C-Risk invites you to their event

3.2 - Build, buy, or hybrid? Designing your DDRM capability

About this event

"Build or buy" is the wrong question — because it isn't one decision, it's three.


In mature DDRM programmes, over 90% of organisations buy their platform rather than build it — a choice that avoids 12 to 18 months of delay with no offsetting differentiation. On methodology, the split flips: roughly 70% rests on open standards (FAIR, FAIR-CAM, ISO 31000, NIST CSF), with the remaining 30% organisation-specific and partner co-built. On the team, the only durable answer is in-house — but it's built over 18 months, with partner support in year one. Conflating these three decisions, or trying to do everything internally, is the structural cause of failure across the programmes we've observed.

In this webinar, we break down the decision matrix component by component — platform, methodology, team — and why "buy everything" and "build everything" each fail for different reasons.

Case in point: a global retail group (>$1.2Bn) that cut its programme cost by roughly 30% versus the pure-build alternative it had originally costed, with its first quantified risk report delivered to the Board in 4 months.

15 September, 3pm CET · 30 minutes + 10 minutes of live Q&A. The replay will be available to all registrants.

C-Risk

Quantifying Information Risk

C-Risk provides solutions to quantify cyber risk in financial terms, improve information security governance and optimise control investments.