Skip to content
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • All guides
  • SRMBOK
  • RMBOK
  • All guides
  • SRMBOK
  • RMBOK

Author: Julian Talbot

How Do I Run a Bow-Tie Workshop That Produces Useful Actions?

End the workshop with owned actions: Agree a precise top event; Test the control logic; Assign actions and reviews.

Twelve specific bow-tie workshop mistakes, from vague focal events to unchallenged barriers, with fixes and a facilitator’s review checklist.

How Do I Keep a Security Risk Assessment Team Working to the Same Process?

Keep the team on the same process: Make the current stage visible; Show the next decision; Revisit earlier assumptions.

A free security risk management wall chart set to keep your project room aligned on what stage the work is at, who leads it, and what happens next.

How Do I Turn Risk Treatments into an Accountable Schedule?

Turn treatments into commitments: A defined action; One accountable owner; A due date and evidence.

A free risk treatment schedule template covering treatment options, cost-benefit, ownership, timeline and the accept/reject decision, in one document.

How Do I Make a Risk Spreadsheet Easier to Use?

Design the spreadsheet for its user: Consistent labels; Meaningful colour; Clear inputs and decisions.

What makes a risk spreadsheet confusing to everyone who opens it, and the colour and layout conventions that fix it, plus a free style guide.

How Can Practitioners Assess Danger While Accounts Are Disputed?

Keep danger, evidence and action visible: Use the specialist framework; Record facts and uncertainty; Follow required response pathways.

How practitioners can organise uncertainty, record safety actions and seek specialist input while disputed accounts remain unresolved. A supplementary risk lens.

How Do I Make a Risk Treatment Plan People Will Keep Updated?

Keep the treatment plan updateable: What will change?; Who acts, and by when?; How will it be checked?.

A simple six-column risk treatment plan template people actually keep updated, replacing the complex schedule everyone quietly stops maintaining.

How Do I Write a Security Plan People Can Implement?

Write a security plan people can implement: Explain the objectives; Specify roles and controls; Set response and review arrangements.

How to write a security plan using an eight-section structure, from statement of purpose through SMART objectives to residual risk and timetable.

How Do I Stop a Security Risk Assessment Growing Beyond Its Scope?

Handle new work through scope control: Compare it with the brief; Record the proposed change; Agree effects on time and outputs.

Five scoping statement clauses that stop security risk assessment scope creep before it starts, with a worked before-and-after example and template.

Which Fields Do I Actually Need in a Risk Register?

Keep the fields that support decisions: Risk and consequence; Controls and assessment; Owner, action and review.

The minimum risk register fields that actually work in practice, why more columns usually make a register worse, and a simple starter set to copy.

Which Essential Eight Maturity Level Should We Aim For?

Choose a maturity target deliberately: Understand exposure; Review current ASD requirements; Plan the evidence and uplift.

An essential eight maturity level comparison for level 1 vs 2 vs 3, so you can pick a realistic target instead of guessing at compliance language.

How Do I Check Whether a Supplier’s Ownership Creates Security Risk?

Look beyond the supplier’s name: Understand ownership; Examine control and influence; Assess access and consequences.

How to screen suppliers for foreign ownership control or influence, and why procurement teams outside defence now need to ask these questions.

How Do I Help a Security Operations Team Apply TLP Consistently?

Make TLP decisions consistent: Mark at the source; Check before onward sharing; Keep the rules at hand.

A free TLP wall chart for your security operations centre, covering markings, label selection and the common mistakes teams make when applying them.

← Previous
Next →
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • About
  • Privacy

All rights reserved