Resources

The reference library for modern risk teams.

Guides, explainers, a working glossary and practical tools — the frameworks, regulations and ideas shaping enterprise risk, security and compliance, written for practitioners.

The GeneSecure resources hub is a free, practical library for risk, compliance, operational-risk and security professionals. It covers the regulations and frameworks that define modern risk work — from FRTB and IFRS 17 to CPS 230, SR 11-7, CECL and AI governance — through plain-English explainers, a cross-linked glossary, and tools that help you quantify the value of running risk on one governed platform.

Guides & explainers

Read up on the rules of the game.

Substantive, jargon-free breakdowns of the regulations and methods that define risk and compliance work. Filter by topic to find what matters to your team.

Cyber Defense

CISOs don't need more alerts. They need risk context.

Adding another detection tool rarely makes a security team safer — it makes them busier. The scarce resource is context: which of today's alerts sits on a critical asset, reaches sensitive data, and could actually cause a material loss.

July 5, 20268 min read
Cyber Defense

Black-box security ratings vs transparent cyber scoring

A single letter grade from an outside-in rating is easy to consume and impossible to act on. Transparent scoring shows the evidence, the weighting and the path from finding to number — so a disputed score becomes a fixable one.

July 3, 20269 min read
Cyber Defense

How to report cyber risk to the board without drowning them in CVEs

Boards do not want a vulnerability scan. They want to know whether the organisation is exposed beyond its appetite, whether the trend is improving, and whether the money is going to the right places. Here is a structure that answers those questions.

July 1, 20269 min read
Cyber Defense

FAIR cyber risk quantification: turning CVEs into board dollars

FAIR (Factor Analysis of Information Risk) is the open standard for expressing cyber risk in financial terms — translating technical exposure into an annualised loss expectancy the board can actually prioritise against.

June 30, 20269 min read
Compliance

From SOC 2 audit to live trust center

A SOC 2 report is a point-in-time PDF that starts ageing the day it is signed. A live trust center turns the same controls, evidence and policies into a continuously current, self-service view of your security posture that shortens every deal.

June 28, 20268 min read
Cyber Defense

How to build an affordable cyber risk program with Wazuh and GeneSecure

You don't need a six-figure EDR and SIEM to run a credible cyber risk program. Open-source telemetry from Wazuh, plus open scanners, feeding a neutral risk and GRC layer, gets a lean team enterprise-grade correlation, evidence and reporting.

June 26, 20269 min read
Cyber Defense

What is a vendor-neutral security platform (and why it beats rip-and-replace)?

A vendor-neutral security platform sits on top of the EDR, SIEM, cloud and scanning tools you already own — normalising their data into one model and adding detection, response, exposure and risk on top, instead of replacing them.

June 24, 20268 min read
AI Governance

AI governance for regulated enterprises: a practical framework

AI governance is the set of policies, controls and oversight that keep AI systems safe, fair, explainable and compliant. For regulated enterprises it builds on model risk discipline and frameworks like the NIST AI RMF and EU AI Act.

June 4, 20269 min read
Credit Risk

CECL for credit unions: the Current Expected Credit Loss model explained

CECL replaced the incurred-loss method with a forward-looking expected-loss model for the allowance for credit losses. Credit unions and other institutions adopted it for fiscal years beginning after 15 December 2022.

May 7, 20268 min read
Model Risk

Model risk under SR 11-7: a guide to model risk management

SR 11-7 is the US supervisory guidance that defines model risk management for banks. It frames model risk as the potential for adverse consequences from model errors or misuse, and demands validation, governance and an inventory.

April 9, 20269 min read
Market Risk

What is FRTB? The Fundamental Review of the Trading Book explained

FRTB overhauls how banks measure and capitalise market risk in the trading book — replacing Value at Risk with an Expected Shortfall measure and a stricter boundary between the trading and banking books.

March 12, 20269 min read
Insurance

IFRS 17 explained: the insurance contracts accounting standard

IFRS 17 is the global accounting standard for insurance contracts. It replaced IFRS 4 with a single, transparent model that measures insurance liabilities at current value and releases profit as service is provided.

February 26, 202610 min read
Operational Resilience

APRA CPS 230 guide: operational risk management for regulated entities

CPS 230 is APRA's prudential standard for operational risk management, business continuity and service-provider management. It applies to banks, insurers and superannuation trustees in Australia from 1 July 2025.

January 29, 20268 min read
The glossary

Every risk term, plainly defined.

A cross-linked, A-to-Z reference of 48 risk, security and compliance terms — from Value at Risk to the EU AI Act. Each entry links to related terms and the modules that put them to work.

AI GovernanceAI governance is the framework of policies, controls and oversight that keeps AI systems safe, fair, explainable and compliant. For regulated enterprises it extends model risk management to cover AI-specific risks — drift, bias, hallucination, autonomy — guided by frameworks like the NIST AI RMF, ISO/IEC 42001 and the EU AI Act.Annualised Loss Expectancy (ALE)ALE is the expected financial loss from a risk over a one-year period. In quantitative cyber risk it is read from a FAIR loss distribution as the average annual loss, usually reported alongside tail percentiles — such as a 95th-percentile 'bad year' — that often matter more for capital and cyber-insurance decisions.Attack PathAn attack path is the chain of steps — across assets, identities, permissions and network connections — by which an attacker could move from an initial entry point to a high-value target. Analysing attack paths lets defenders find and cut the few links that would block many routes to their crown-jewel systems, which is far more efficient than patching vulnerabilities in isolation.Basel IIIBasel III is the international regulatory framework from the Basel Committee on Banking Supervision that strengthens bank capital, leverage and liquidity requirements after the 2008 crisis. It raises the quantity and quality of capital banks must hold, introduces liquidity ratios (LCR and NSFR), and includes the 'Basel III endgame' reforms that refine credit, operational and market-risk capital.Business ContinuityBusiness continuity is an organisation's capability to keep delivering critical operations during and after a disruption. A business continuity plan documents the people, processes, technology and recovery objectives needed to stay within acceptable downtime and data-loss tolerances through severe events.CECLCurrent Expected Credit Losses is the US GAAP credit-loss model (ASC 326) that requires institutions to reserve for expected losses over the full life of a financial asset from day one, using forward-looking forecasts. It replaced the incurred-loss method, which only recognised losses once they became probable.Contractual Service Margin (CSM)The Contractual Service Margin is the unearned profit embedded in a group of insurance contracts under IFRS 17. It sits on the balance sheet at inception and is released to the income statement as the insurer provides coverage, ensuring profit is recognised over time rather than up front.ControlA control is a process, policy or technical measure that reduces the likelihood or impact of a risk. Controls are classified as preventive, detective or corrective, and their design and operating effectiveness are tested during audits and compliance assessments such as SOC 2.
Tools

Unified-risk ROI calculator

Model the time, cost and audit-effort savings of moving from fragmented point tools to one governed risk platform — in a couple of minutes.

From reading about risk to running it.

Book a 30-minute walkthrough and we'll map GeneSecure to the frameworks and domains you just read about — with your data in view.

Risk Management Resources — GRC Guides & RegTech Whitepapers | GeneSecure