CyberRisk

CyberRisk IT Audit | Cybersecurity | Digital Risk | Tech Strategy for Professionals & Businesses

This page is educational content only.

Opinions are personal and do not represent any employer or organization. The Tech Strategist is a professional knowledge platform focused on:

✔ Cybersecurity & Information Security
✔ IT Audit & Risk Management
✔ Digital Banking & FinTech Technology
✔ Career Guidance for IT, Audit & Cyber Professionals
✔ Practical Tools, Frameworks & Real-World Insights

🎯 Mission: Turrning technology into strategic advantage.

🔐 আপনার ফোন কি নিরাপদ?ফোন ধীর হয়ে গেছে? ব্যাটারি দ্রুত শেষ হচ্ছে? অজান্তেই বেশি ডেটা খরচ হচ্ছে? এগুলো কখনও কখনও নিরাপত্...
26/07/2026

🔐 আপনার ফোন কি নিরাপদ?

ফোন ধীর হয়ে গেছে? ব্যাটারি দ্রুত শেষ হচ্ছে? অজান্তেই বেশি ডেটা খরচ হচ্ছে? এগুলো কখনও কখনও নিরাপত্তা ঝুঁকির ইঙ্গিত হতে পারে।

📌 সচেতন থাকুন। নিরাপদ থাকুন।

🌐 Beyond the Surface: Understanding the Surface Web, Deep Web, and Dark WebThe internet is often compared to an iceberg—...
20/07/2026

🌐 Beyond the Surface: Understanding the Surface Web, Deep Web, and Dark Web

The internet is often compared to an iceberg—what we access every day is only a small fraction of what actually exists.

🔹 Surface Web
The publicly accessible part of the internet indexed by search engines like Google. It includes websites, social media platforms, blogs, e-commerce sites, and online news.

🔹 Deep Web
Content that is not indexed by search engines but is completely legitimate. Examples include online banking portals, medical records, academic research databases, corporate intranets, and private forums. This layer exists primarily to protect privacy and sensitive information.

🔹 Dark Web
A small segment of the Deep Web that requires specialized software, such as Tor, to access. While it has legitimate uses—such as protecting privacy and enabling anonymous communication—it is also known for hosting illegal marketplaces and cybercriminal activities. It’s important to distinguish the Dark Web from the much larger and mostly legitimate Deep Web.

As cybersecurity professionals, understanding these distinctions is essential for effective threat intelligence, digital forensics, cyber defense, and risk management. Knowledge—not fear—is the foundation of cybersecurity.

What are your thoughts on the role of the Deep Web and Dark Web in today’s cybersecurity landscape?

15/07/2026

Cybersecurity Tips..

15/07/2026

🔒 আপনার ফোন কি নিরাপদ?

আপনার ফোন কি অস্বাভাবিক গরম হচ্ছে? ব্যাটারি কি দ্রুত শেষ হয়ে যাচ্ছে? অথবা এমন কোনো অ্যাপ দেখতে পাচ্ছেন যা আপনি কখনো ইনস্টল করেননি?

এই ভিডিওতে আমি এমন ৫টি সম্ভাব্য লক্ষণ নিয়ে আলোচনা করেছি, যেগুলো দেখলে আপনার স্মার্টফোনের নিরাপত্তা পরীক্ষা করা উচিত। তবে মনে রাখবেন, এসব লক্ষণ থাকলেই ফোন হ্যাক হয়েছে—এমনটি নিশ্চিত নয়। অনেক সময় সফটওয়্যার সমস্যা, ব্যাটারির অবস্থা বা অন্যান্য বৈধ কারণেও একই ধরনের আচরণ দেখা যেতে পারে।

📌 এই ভিডিওতে যা জানতে পারবেন:
✅ ফোন অস্বাভাবিক গরম হওয়ার সম্ভাব্য কারণ
✅ ব্যাটারি দ্রুত শেষ হওয়ার কারণ
✅ অচেনা বা সন্দেহজনক অ্যাপ কীভাবে শনাক্ত করবেন
✅ Mobile Data Usage কীভাবে পরীক্ষা করবেন
✅ App Permissions কেন নিয়মিত পর্যালোচনা করা জরুরি

🛡️ নিজেকে নিরাপদ রাখতে যা করবেন:
✔️ ফোনের অপারেটিং সিস্টেম নিয়মিত আপডেট করুন
✔️ অপ্রয়োজনীয় ও সন্দেহজনক অ্যাপ আনইনস্টল করুন
✔️ App Permissions নিয়মিত পরীক্ষা করুন
✔️ Google Play Protect (Android) অথবা iPhone-এর বিল্ট-ইন নিরাপত্তা ফিচার ব্যবহার করুন
✔️ শক্তিশালী পাসওয়ার্ড ও Two-Factor Authentication (2FA) ব্যবহার করুন

🎯 এই ভিডিওটি শিক্ষামূলক ও সচেতনতামূলক উদ্দেশ্যে তৈরি করা হয়েছে, যাতে সবাই নিরাপদ ডিজিটাল অভ্যাস গড়ে তুলতে পারেন।

আপনি যদি Cyber Security, Ethical Hacking, IT Audit, Banking Security, Online Safety এবং Digital Privacy সম্পর্কে নিয়মিত বাংলা কনটেন্ট দেখতে চান, তাহলে চ্যানেলটি Subscribe করুন, ভিডিওটি Like করুন এবং আপনার বন্ধু ও পরিবারের সঙ্গে Share করুন।

🔔 নিরাপদ থাকুন, সচেতন থাকুন।

🔐 Security Governance: The Foundation of Every Mature Cybersecurity ProgramA strong cybersecurity strategy is built on m...
11/07/2026

🔐 Security Governance: The Foundation of Every Mature Cybersecurity Program

A strong cybersecurity strategy is built on more than just firewalls and SIEMs—it starts with effective security governance.

Understanding the relationship between Frameworks, Policies, Standards, Guidelines, and Procedures helps organizations transform strategic objectives into consistent operational security.

📌 Security Governance Hierarchy

🔷 Framework → Defines the overall security strategy and best practices (ISO/IEC 27001, NIST CSF, CIS Controls, MITRE ATT&CK)

📘 Policy → Specifies what the organization must do to protect information assets.

⚙️ Standard → Defines how security requirements must be implemented consistently.

💡 Guideline → Recommends best practices while allowing operational flexibility.

📋 Procedure → Provides step-by-step instructions for executing security tasks effectively.

Together, these five layers establish a governance model that strengthens compliance, improves operational efficiency, and reduces cyber risk.

In today’s threat landscape, organizations should also understand key regulatory and compliance frameworks such as:

✅ ISO/IEC 27001:2022 – Information Security Management System (ISMS)

✅ GDPR – Protecting personal data and privacy rights

✅ HIPAA – Safeguarding healthcare and patient information

For Security Operations Centers (SOCs), governance directly supports:
✔️ Detection Engineering
✔️ SIEM Standardization
✔️ Incident Response
✔️ Threat Hunting
✔️ Regulatory Compliance

Cybersecurity is not just about deploying technology—it’s about building governance that enables people, processes, and technology to work together securely.

Author: Bappy Sharma, CISA, FMVA

📊 IFRS 9 Expected Credit Loss (ECL) ModelIFRS 9 applies a forward-looking approach to credit risk measurement using:ECL ...
25/06/2026

📊 IFRS 9 Expected Credit Loss (ECL) Model

IFRS 9 applies a forward-looking approach to credit risk measurement using:

ECL = PD × LGD × EAD

🔹 PD: Probability of Default
🔹 LGD: Loss Given Default
🔹 EAD: Exposure at Default

Key elements:
✅ Stage 1: 12-month ECL
✅ Stage 2 & 3: Lifetime ECL
✅ Forward-looking macroeconomic adjustments
✅ Recovery and collateral assessment

IFRS 9 ECL is more than an accounting model — it is a powerful credit risk analytics framework for better decision-making and financial stability.

21/06/2026

🛡️ TOP CYBERSECURITY CAREERS

1.👨‍💻 SOC ANALYST

Skills: SIEM tools, log analysis, incident triage
Certs: Security+, CySA+
Avg. Salary: $65K–$95K

2.🎯 PE*******ON TESTER

Skills: Exploitation tools, scripting, network protocols
Certs: OSCP, CEH
Avg. Salary: $85K–$130K

3.⚙️ SECURITY ENGINEER

Skills: Network architecture, IDS/IPS, cloud security
Certs: CISSP, CCSP
Avg. Salary: $95K–$140K

4.🚨 INCIDENT RESPONDER

Skills: Forensics, malware analysis, crisis communication
Certs: GCIH, GCFA
Avg. Salary: $90K–$135K

5.🏗️ SECURITY ARCHITECT

Skills: Risk modeling, zero-trust design, enterprise systems
Certs: CISSP, SABSA
Avg. Salary: $120K–$165K

6.🔍 DIGITAL FORENSICS INVESTIGATOR

Skills: Evidence handling, disk/memory forensics
Certs: GCFE, CHFI
Avg. Salary: $80K–$120K

7.☁️ CLOUD SECURITY SPECIALIST

Skills: IAM policies, container security, cloud-native tools
Certs: CCSP, AWS Security Specialty
Avg. Salary: $100K–$150K

8.📊 CYBERSECURITY CONSULTANT

Skills: Risk assessment, client communication, cross-domain knowledge
Certs: CISSP, CISM
Avg. Salary: $90K–$140K

9.🌐 NETWORK SECURITY ENGINEER

Skills: Firewall config, VPNs, network protocols
Certs: CCNA Security, Network+
Avg. Salary: $85K–$125K

10.🤖 AI SECURITY SPECIALIST

Skills: ML model security, adversarial testing, AI governance
Certs: CISSP + AI/ML Specialization
Avg. Salary: $110K–$160K

11.⚖️ GRC ANALYST

Skills: Risk frameworks (NIST, ISO 27001), audits, policy writing
Certs: CRISC, CISA
Avg. Salary: $80K–$120K

12.💼 CISO

Skills: Leadership, business strategy, risk communication
Certs: CISSP, CISM
Avg. Salary: $160K–$250K+

🔐 Cybersecurity is not just about technology.One of the biggest challenges in cybersecurity today is not the lack of too...
06/06/2026

🔐 Cybersecurity is not just about technology.

One of the biggest challenges in cybersecurity today is not the lack of tools—it’s the persistence of misconceptions.

Many organizations still believe that:
❌ Cybersecurity is only IT’s responsibility
❌ Antivirus alone is enough
❌ Compliance equals security
❌ Small businesses are not targets
❌ Technology can solve every security problem

The reality is that effective cybersecurity requires a combination of:

👥 People
⚙️ Processes
🖥️ Technology
🏛️ Governance
📊 Risk Management

Organizations that focus on building a security-aware culture, strengthening governance, and continuously managing risks are far more resilient against today’s evolving threat landscape.

Cybersecurity ≠ Technology Only
Cybersecurity = People + Process + Technology + Governance + Continuous Improvement

What other cybersecurity misconceptions have you encountered in your organization?

.

Address

Motijil
Dhaka
4000

Alerts

Be the first to know and let us send you an email when CyberRisk posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share