Skip to content
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • All guides
  • SRMBOK
  • RMBOK
  • All guides
  • SRMBOK
  • RMBOK

Author: Julian Talbot

How Do I Review Our Insider Threat Program as a Senior Manager?

Review the program as a system: Governance and accountability; People and access controls; Evidence, response and learning.

A free insider threat self-assessment checklist for senior managers who need to know whether their organisation’s real controls actually still work.

How Do I Shorten a Risk Policy Without Losing What Matters?

Keep the policy short and useful: Keep intent and authority; Name responsibility; Move detail into procedures.

Why a one page risk policy gets read and used, while a twenty-page version usually sits unread on a shared drive somewhere nobody opens it.

How Do I Explain Risk Management to Colleagues Who See Only Paperwork?

Explain risk through a real decision: What could happen?; What changes the likelihood or harm?; What should we do next?.

Risk management is not paperwork: how to explain that to sceptical colleagues using clear risk statements and bow-tie thinking instead of forms.

How Do I Remove Sensitive Details from an AI Prompt Without Losing Its Meaning?

Remove identifying detail without losing logic: Keep necessary relationships; Generalise sensitive specifics; Check re-identification and output.

Remove or generalise identifying details in an AI prompt while retaining useful structure. Check re-identification risk, service approval and the resulting output.

← Previous
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • About
  • Privacy

All rights reserved