Cyber Risk Strategy and Decision Science

Helping leaders make better decisions about cyber, AI, and technology risk.

Freund Advisory Group helps organizations understand complex technology risks, improve how those risks are measured and managed, and make defensible decisions under uncertainty. Our work spans cyber risk quantification, risk methodology, third party risk, AI and emerging risk, GRC transformation, insurance and materiality, and executive risk decision support.

We work with organizations facing problems where conventional assessments, compliance exercises, and simple scoring methods provide an incomplete answer.

When the Risk Matters, the Methodology Matters

Cyber risk programs produce enormous amounts of information. The harder problem is determining what that information means, how much confidence to place in it, and what decision should follow. Freund Advisory Group works with leaders confronting questions such as:

How much cyber risk do we actually have?

Quantify material cyber scenarios and express uncertainty in terms executives can use.

Can we trust our risk model?

Design, validate, and challenge risk models, scoring methodologies, assumptions, and data.

Which third parties create the greatest exposure?

Move beyond questionnaires toward risk based segmentation, continuous signals, concentration analysis, and financial exposure.

What decision should we make?

Translate risk information into decisions involving investment, prioritization, acceptance, mitigation, transfer, and escalation.

How do we create a credible enterprise view of cyber risk?

Improve taxonomies, assessment methods, aggregation, risk appetite, governance, and reporting.

How should we manage AI and other emerging risks?

Build practical approaches for risks characterized by uncertainty, limited historical data, and rapidly changing technology.

Experience Across the Cyber Risk Profession

Freund Advisory Group is led by Dr. Jack Freund, a cyber risk executive, researcher, author, and advisor with more than two decades of experience in technology and cyber risk management.

Jack is coauthor of Measuring and Managing Information Risk: A FAIR Approach, the foundational book on FAIR based cyber risk quantification, and has held senior risk and methodology roles at organizations including Acrisure, Kovrr, BitSight, RiskLens, Nationwide, and TIAA. His work has included enterprise technology risk leadership, quantitative model development, model validation, cyber insurance, third party risk, AI governance, GRC, and board and executive advisory. 

His research and professional work have been recognized by ISACA, ISC2, ISSA, IAPP, and the FAIR Institute, and he has spoken internationally at venues including the Cyber Future Foundation, RSA Conference, Gartner Evanta, ISACA, ISC2, and ISSA.