How Do I Record Security Risks So Someone Can Act on Them?

A free security risk register template with the fields that matter most: risk ID, consequence, likelihood, control evaluation and prioritisation.
Do We Need OSCAL for Our Security Compliance Work?

What is OSCAL? A plain-English explanation of the NIST control documentation standard and how to decide if your organisation needs it yet.
How Do I Decide Which Information Needs the Most Protection?

See a fully worked information classification example across five systems and four labels, with the written reasoning behind every rating explained.
How Do I Prepare a Safety Plan for a Business Trip?

A free business travel safety plan template and the method behind it: risk tiers, emergency contacts, digital footprint and no-internet backups explained.
How Do I Use Bow-Tie Analysis to Understand a Security Risk?

Bow-tie analysis explained simply: focal events, causes, consequences and controls, with a worked example, in about the time it takes to read this.
How Can I Use AI to Help Draft Security Risk Work?

Thirty ChatGPT prompts for risk practitioners, plus clear rules for what to paste into a prompt and what to always keep out.
How Do I Help Staff Recognise a Targeted Phishing Email?

Spearphishing vs phishing: the practical differences staff need to recognise, since the generic red flags in most training don’t catch a targeted attack.
How Do I Learn the Bow-Tie Method and Apply It at Work?

This free risk bow-tie method course covers threats, top events, consequences and controls, plus a companion free eBook.
How Do I Apply ISO 31000 Without Adding Unnecessary Paperwork?

ISO 31000 explained in plain language: the principles, framework and full process, from setting the context through to risk treatment and review.
How Do I Compare Risk Before and After a Treatment?

Recording pre and post mitigation risk as separate, dated fields lets you verify whether a treatment actually worked, not just claim it did.
What Cybersecurity Questions Should I Ask at a Board Meeting?

Five cybersecurity questions for boards to ask management, moving past ‘are we secure’ to ones with evidence-based answers behind them.
How Do I Explain Network Segmentation to Our Board?

A method for explaining segmentation to a board using an enclave model, a reach matrix and gates, instead of a technical topology diagram.
