Security Risk Templates · by SRMBOK
All security risk guides
Browse the latest articles or search for the problem in front of you. Each guide connects practical advice to a relevant SRMBOK tool.
New to the role? Start with the foundational guides.
-

How Do I Record Security Risks So Someone Can Act on Them?
A free security risk register template with the fields that matter most: risk ID, consequence, likelihood, control evaluation and prioritisation.
-

Do We Need OSCAL for Our Security Compliance Work?
What is OSCAL? A plain-English explanation of the NIST control documentation standard and how to decide if your organisation needs it yet.
-

How Do I Decide Which Information Needs the Most Protection?
See a fully worked information classification example across five systems and four labels, with the written reasoning behind every rating explained.
-

How Do I Prepare a Safety Plan for a Business Trip?
A free business travel safety plan template and the method behind it: risk tiers, emergency contacts, digital footprint and no-internet backups explained.
-

How Do I Use Bow-Tie Analysis to Understand a Security Risk?
Bow-tie analysis explained simply: focal events, causes, consequences and controls, with a worked example, in about the time it takes to read this.
-

How Can I Use AI to Help Draft Security Risk Work?
Thirty ChatGPT prompts for risk practitioners, plus clear rules for what to paste into a prompt and what to always keep out.
-

How Do I Help Staff Recognise a Targeted Phishing Email?
Spearphishing vs phishing: the practical differences staff need to recognise, since the generic red flags in most training don’t catch a targeted attack.
-

How Do I Learn the Bow-Tie Method and Apply It at Work?
This free risk bow-tie method course covers threats, top events, consequences and controls, plus a companion free eBook.
-

How Do I Apply ISO 31000 Without Adding Unnecessary Paperwork?
ISO 31000 explained in plain language: the principles, framework and full process, from setting the context through to risk treatment and review.
-

How Do I Compare Risk Before and After a Treatment?
Recording pre and post mitigation risk as separate, dated fields lets you verify whether a treatment actually worked, not just claim it did.
-

What Cybersecurity Questions Should I Ask at a Board Meeting?
Five cybersecurity questions for boards to ask management, moving past ‘are we secure’ to ones with evidence-based answers behind them.
-

How Do I Explain Network Segmentation to Our Board?
A method for explaining segmentation to a board using an enclave model, a reach matrix and gates, instead of a technical topology diagram.
