Steve Reznik

Steve Reznik

New York City Metropolitan Area
857 followers 500+ connections

About

Steve Reznik is an industry leading risk management professional focused on making…

Activity

Join now to see all activity

Education

Volunteer Experience

  • Founder & Chair of Greater New York City Area Chapter

    Founder & Chair of Greater New York City Area Chapter

    FAIR Institute

    - 5 years

    Science and Technology

    The NYC Local Chapter of The Factor Analysis of Information Risk Institute provides the opportunity to meet with your peers across a variety of industries in your geographical area to learn from each other’s expertise and operational practices. Together, you will advance your knowledge of FAIR and expand its range of applications.

  • Marching Band Pit Crew

    Marching Band Pit Crew

    West Orange High School

    - 7 years

    Education

    -Load / unload trucks with the large musical instruments and performance props
    -Quickly set up performance props at the competitions
    -Assist with the West Orange Invitational Marching Band Competition
    -Brag about how marching band was done when I was in high school

  • Author, Reviewer

    Author, Reviewer

    ISACA

    - 10 years

    Science and Technology

    COBIT 5 Risk Scenarios (Reviewer), COBIT 5 for Risk (Task Force), Monitoring Internal Control Systems and IT (Contributor), The Risk IT Framework v1 (Development Team)

Publications

  • What's in Your Risk Assessment?

    RSA Conference, San Franciso, CA

    Not all risk assessments are created equal. And many compliant methods are not useful for running the business. This session will accelerate your approach to the high quality decision data desired by internal stakeholders while making your external stakeholders smile.

    Other authors
    See publication
  • Cyber Risk Panelist - IIB Information Security & Operational Resiliency Conference

    Institute of International Bankers, New York, NY

    Enhancing Your Cyber Risk Management to Meet Increased Expectations: Steve was one of four panelists who discussed regulators’ increased focus on cyber risk management and methods being implemented to identify and mitigate this risk.

    Other authors
    See publication
  • Pen Testing Your Board Pitch: An Interactive Exercise

    FAIRCON 2019, Washington DC

    In one of the most closely listened-to panel discussions of the 2019 FAIR Conference: “Pen-Testing Your Board Pitch,” starring two veteran board members, James Lam (E*TRADE) and Chris Inglis (FedEx), presented attendees with a rare opportunity to hear directly from the source what board directors want to know before bestowing their support – or throwing you out of the room.

    The session began with two skits – one cringe-inducing, one applause-generating. In the first dramatization, two…

    In one of the most closely listened-to panel discussions of the 2019 FAIR Conference: “Pen-Testing Your Board Pitch,” starring two veteran board members, James Lam (E*TRADE) and Chris Inglis (FedEx), presented attendees with a rare opportunity to hear directly from the source what board directors want to know before bestowing their support – or throwing you out of the room.

    The session began with two skits – one cringe-inducing, one applause-generating. In the first dramatization, two self-confident but old-school and still using qualitative reporting infosec executives played by Jeff Welgan of CyberVista and Steve Reznik of ADP brief the board (played by James and Chris) of an imaginary bank on their security posture after a data breach at a competitor bank, complete with a colorful heat map presentation...

    Other authors
    See publication
  • All-in-One Matrix: Regulatory Compliance Risk Assessment Overview for FAIR Practitioners

    FAIR Institute Blog

    Check out this resource for mapping what you are doing now to what the regulators and standards bodies are asking for.

    Other authors
    See publication
  • Three FAIR Use Cases

    FAIR Institute Breakfast at RSA Conference

    This is my short presentation to the FAIR Breakfast during the 2019 RSA Conference on how to:
    -Create a common risk view
    -Make risk-aware business decisions
    -Select better metrics

    See publication
  • What Makes a Good KRI? Using FAIR to Discover Meaningful Metrics

    RSA Conference, San Francisco, CA

    WARNING! Viewer discretion is advised. This presentation contains talking emojis, slides with more numbers than words, and a brief instance of drama. Watching it may change your definition of risk and enable you to make better decisions.

    See publication
  • Key Risk Indicators: A Quantitative Approach

    FAIRCON 2018, Pittsburg, PA

    Marta and I present a case study using sensitivity analysis to tweak risk factors and illustrate the effect on a baseline risk assessment. For instance, a decrease of one percent in vulnerability reduces loss exposure by the same amount as does responding to an incident 10% faster.

    Other authors
    See publication
  • FAIR Practitioner Panelist

    FAIRCON 2016, Charlotte, NC

    FAIR Practitioner Panel: "How to Build a Quantitative Risk Management Program"

    Other authors
    See publication
  • COBIT 5 for Risk (Task Force)

    ISACA

  • IT Risk Management Training Course

    ISACA Training Week, Boston, MA

  • Risk Workshops Based on COBIT 5

    IIA/ISACA GRC Conference, Phoenix, AZ and at the ISACA Information Security and Risk Management (ISRM) Conference, Las Vegas, NV

  • Enterprise Risk Management and IT

    ISRM Conference, Las Vegas, NV

  • Implementation and Operational Issues of The Risk IT Framework

    ISRM Conference, Las Vegas, NV

  • Monitoring Internal Control Systems and IT (Contributor)

    ISACA

  • The Risk IT Framework v1 (Development Team)

    ISACA

    Steve Reznik collaborated with a team of IT leaders from several countries and industries to draft the process model component of the The Risk IT Framework. He also contributed to the Risk IT Practitioner Guide.

    Other authors
  • Make 'MyCOBIT' Your COBIT

    The COBIT Focus Newsletter, Volume 1, January 2008, ISACA

    My thoughts on enterprise risk assessment and using COBIT in a relational database format to create a risk and control matrix. I've continued to develop these approaches with clients and embedded them into The Risk IT Framework.

  • Back to Business with IT Governance

    The Journal of Corporate Accounting and Finance, Volume 18, Number 6, Sep/Oct 2007, Wiley Periodicals, Inc.

    Abstract: "Recent surveys continue to show a serious weakness in how corporate executives and boards are involving themselves with critical IT risks."

    Here I provide advice to CEOs who want to take charge of IT governance and focus on the needs of IT people. I'm proud of the article's behavioral based maturity model and used it while developing the process maturity model for The Risk IT Framework.

    See publication
  • Implementing COBIT—Panel Discussions

    ISACA New Jersey Chapter, Newark, NJ

    Other authors
  • COBIT & Regulatory Compliance

    International COBIT User Conference, Orlando, FL

    Other authors
  • How Pentagon Air Staff Systems Achieved CMM Level II

    Department of Defense Software Technology Conference, Salt Lake City, UT

    Other authors

Recommendations received

  • LinkedIn User

    LinkedIn User

1 person has recommended Steve Join now to view

View Steve’s full profile

  • See who you know in common
  • Get introduced
  • Contact Steve directly
Join to view full profile

Other similar profiles

Explore collaborative articles

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Explore More

Others named Steve Reznik in United States