Skip to content
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • All guides
  • SRMBOK
  • RMBOK
  • All guides
  • SRMBOK
  • RMBOK

Author: Julian Talbot

How Do I Record Security Risks So Someone Can Act on Them?

Write risk records that prompt action: A clear risk statement; Controls with evidence; An owner and next review.

A free security risk register template with the fields that matter most: risk ID, consequence, likelihood, control evaluation and prioritisation.

Do We Need OSCAL for Our Security Compliance Work?

Decide whether structured compliance helps: Repeated information; Consistent control records; Reusable assessment data.

What is OSCAL? A plain-English explanation of the NIST control documentation standard and how to decide if your organisation needs it yet.

How Do I Decide Which Information Needs the Most Protection?

Protect information according to impact: Loss of confidentiality; Loss of integrity; Loss of availability.

See a fully worked information classification example across five systems and four labels, with the written reasoning behind every rating explained.

How Do I Prepare a Safety Plan for a Business Trip?

Plan the trip before departure: Assess the destination and trip; Agree contacts and contingencies; Review after returning.

A free business travel safety plan template and the method behind it: risk tiers, emergency contacts, digital footprint and no-internet backups explained.

How Do I Use Bow-Tie Analysis to Understand a Security Risk?

Trace the path from cause to harm: Threats; Top event; Consequences.

Bow-tie analysis explained simply: focal events, causes, consequences and controls, with a worked example, in about the time it takes to read this.

How Can I Use AI to Help Draft Security Risk Work?

Use AI for a draft, then apply judgement: Set the task and context; Use approved information; Check every material claim.

Thirty ChatGPT prompts for risk practitioners, plus clear rules for what to paste into a prompt and what to always keep out.

How Do I Help Staff Recognise a Targeted Phishing Email?

A convincing email still needs checking: Notice an unusual request; Verify through a known channel; Report the suspicious message.

Spearphishing vs phishing: the practical differences staff need to recognise, since the generic red flags in most training don’t catch a targeted attack.

How Do I Learn the Bow-Tie Method and Apply It at Work?

Practise bow-tie thinking on one event: Stolen credentials; Unauthorised entry; Service disruption.

This free risk bow-tie method course covers threats, top events, consequences and controls, plus a companion free eBook.

How Do I Apply ISO 31000 Without Adding Unnecessary Paperwork?

Make the risk process support decisions: Clarify context and criteria; Assess and treat risk; Monitor, review and communicate.

ISO 31000 explained in plain language: the principles, framework and full process, from setting the context through to risk treatment and review.

How Do I Compare Risk Before and After a Treatment?

Separate today’s risk from the target: Record current controls; Assess current exposure; Test the proposed treatment.

Recording pre and post mitigation risk as separate, dated fields lets you verify whether a treatment actually worked, not just claim it did.

What Cybersecurity Questions Should I Ask at a Board Meeting?

Ask for evidence behind reassurance: What matters most?; What has been tested?; What decision is needed?.

Five cybersecurity questions for boards to ask management, moving past ‘are we secure’ to ones with evidence-based answers behind them.

How Do I Explain Network Segmentation to Our Board?

Control movement between security zones: Public-facing services; Controlled access; Critical systems.

A method for explaining segmentation to a board using an enclave model, a reach matrix and gates, instead of a technical topology diagram.

← Previous
Next →
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • About
  • Privacy

All rights reserved