Information security organizations and leaders have seen a meteoric rise in significance and prominence as IT ecosystems change at a more rapid pace than ever before. In the past few years, there have been a spate of high-profile breaches and attacks that have cost businesses billions of dollars in revenue and inestimable injury to growth and productivity. This puts tremendous pressure on InfoSec organizations and leaders to demonstrate that they are taking concrete measures to protect the enterprise. With its emphasis on structure, transparency, extensiveness, certainty and adaptability, Risk Management is an ideal model for cybersecurity programs. Core risk management principles of creating value, being an integral part of organizational and decision-making process, being systematic, processing accurate and extensive information, and continuously monitoring and improving are directly applicable to InfoSec programs. Risk-centric management of cybersecurity programs can transform how InfoSec organizations operate, communicate and contribute to business growth. In this session we: Identify the key goals for cyber security risk management Explore a real-world use case for risk-centric cybersecurity management Create the blue-print for a risk-centric cybersecurity management program