Low probability but a devestating impact
I’ve been too busy to blog this week and haven’t had any ideas for any new topics. Tomorrow (Wednesday and Thursday) I’ll be attending my company’s internal security “conference” to discuss the issues and projects IT Security faces. I’m interning at this company, so I’ll be all ears for the next two days and just learning as much as I can before my start date on May 30th. One of the more interesting talks I look forward to seeing is on “Next Generation Threat Analysis,” which will attempt to identify those areas of risk with low probability but devastating impacts. I’ve been trying to think of some on my own and come up dry (of course my definition of high probability is someone’s low and vice-versa).
Anyone care to share their stories or opinions? Post a comment, I definitely will be following up this post tomorrow night after attending the session.

low probability but devastating effects…
natural disaster? Katrina is a poster-child for low probability events and risk management
concerted cyber terrorist attack against the company?
bomb threat or disgruntled worker going postal? (I really bet the post office loves that verb)
stolen/lost backup tapes?
I hope they define ‘threats’ up front… :)
(Of note, I don’t think lost laptops, outside worms and hack attempts, or insider theft are low probability…really)