Last year I was at a security symposium in
Sydney where I bumped into a friend working for a large security vendor. We
discussed the latest industry rumours, trends and shared a few interesting
stories on breaches - this is when I asked if his firm performs risks
assessments for Business Process Compromise (BPC) to which he replied -
"No". I was now thinking how on earth do they perform security
assessments when they only look at one half of the big picture? Surely the
other big half is equally as important? Don't believe me? - what about the big
cyber-heist of Bangladesh's