Recommended Free Tools
Former CISA Director Chris Krebs’s February 2021 CPX 360 keynote made a practical case for treating cyber risk as more than a question of who might attack. Organizations also need to assess what is exposed, what an incident could disrupt, and how likely the scenario is—and then use intelligence and cooperation to choose defenses.
What Krebs meant by a cyber risk formula
In a virtual keynote at Check Point’s CPX 360 conference, Krebs described risk as threat multiplied by vulnerability multiplied by consequence, with likelihood also considered. Kelly Sheridan’s February 23, 2021 Dark Reading report explains the point: an organization’s assessment should include the software, services, and systems it depends on, as well as the potential effects if an attack succeeds.
That framing widens the question beyond “Who is the attacker?” A useful assessment asks what an adversary could exploit, which business or public services depend on the exposed systems, and what disruption would follow. Likelihood helps distinguish plausible scenarios from merely imaginable ones; consequence helps explain why a less frequent event can still merit attention.
Why attacker behavior matters—but is not the whole risk picture
The report contrasted opportunistic scanning for unpatched systems and VPNs with more patient, strategic intrusions, including the supply-chain campaign associated with SolarWinds. These examples appeared in a 2021 account and should be read in that historical context, not as a description of today’s threat landscape.
#1 Best Overall
| Behavior described in the report | What it means for risk decisions |
|---|---|
| Opportunistic scanning for exposed or unpatched systems | Basic exposure and patching can matter even when an organization is not singled out. |
| Patient, strategic intrusion, including a supply-chain campaign | Assessment should consider dependencies and pathways through software or service providers, not only an organization’s own perimeter. |
| Visible criminal or ransomware disruption | Operational consequences may be immediate and apparent, making continuity and response planning important. |
Krebs’s point was not that one kind of attacker makes another irrelevant. A sophisticated actor may remain unnoticed, while criminal activity can create conspicuous disruption. Defenders need to consider both the chance of compromise and what a successful incident would mean for the systems and services that matter.
How CISA used threat modeling for election security
As reported by Sheridan, Krebs said CISA and its partners considered scenarios in which a capable, determined attacker could disrupt election operations. They engaged stakeholders early to help secure election systems and reduce the prospect that ransomware or other malware would interrupt them. The scenario work informed defensive strategies, state and local officials’ investment decisions, and Congress’s understanding of potential resource needs.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Krebs said CISA had spent three-and-a-half years thinking through election-disruption scenarios before the 2020 election. That duration is his statement as reported by Dark Reading, not an independently verified measurement. The example shows how threat modeling can turn a hypothetical attack into preparation and investment before an incident occurs.
How the pandemic changed healthcare cyber risk
Krebs also described healthcare risk changing rapidly during COVID-19. As facilities altered operations, the vulnerability and consequence sides of the assessment shifted too. The report says CISA worked with healthcare partners, including the healthcare ISAC, to share ransomware-defense practices and respond to changing conditions.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
He said healthcare had been a prime ransomware target for at least three years before the pandemic; this figure, too, is attributed to his remarks in the 2021 report rather than presented as an independently validated statistic. The broader lesson was to keep reassessing internal and external conditions instead of treating a risk assessment as a one-time exercise.
Why sharing indicators is not enough
Indicators of compromise (IOCs) can help identify malicious activity, but Krebs argued that complex campaigns call for more operational context. Organizations benefit from understanding how and where adversaries are operating, which networks and targets they are pursuing, and how important software and service providers connect across the economy. The report also cited international operational work ahead of the 2020 election as information that could support cooperation with election officials.
Rank #4
This is a coordination problem as much as a technical one: no single organization sees the entire threat picture. Sharing context and coordinating defensive operations can help participants make decisions that isolated indicator exchange cannot support on its own.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Applying the ideas in an organization today
Krebs’s remarks were made in 2021. For a current organizational frame, CISA’s Cross-Sector Cybersecurity Performance Goals organize cybersecurity work across Govern, Identify, Protect, Detect, Respond, and Recover. This is separate, current CISA guidance—not a framework Krebs cited in the keynote.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
CISA’s Shields Up guidance for corporate leaders advises including CISOs in company-risk decisions and exercising incident-response plans with senior business leaders and board members. In practice, those actions connect cyber risk to business priorities: decide which services must keep operating, understand dependencies and exposures, and ensure leaders know how decisions and response responsibilities fit together.
CISA’s archived Strategic Intent announcement describes the agency’s mission to protect critical infrastructure from physical and cyber threats and confirms Krebs’s former role as CISA Director. His keynote, as reported by Dark Reading, is best understood as a historical argument for linking threat intelligence to exposure, consequences, investment, and cooperation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




