How Do I Set the Scope of a Security Risk Assessment?

Set the security risk assessment scope properly, with boundaries, dates and assumptions fixed up front, plus a free scoping statement template.
How Do I Turn a Risk Register into Better Decisions?

What is RMBOK? A practitioner’s introduction to writing risk statements, running bow-tie analysis and testing controls that actually work.
How Do I Carry Out a Security Risk Assessment?

Work through a security risk assessment: agree scope, identify scenarios, assess controls and risk, choose treatments and review. Includes a practical flowchart.
How Do I Use Bow-Tie Analysis to Understand a Security Risk?

Bow-tie analysis explained simply: focal events, causes, consequences and controls, with a worked example, in about the time it takes to read this.
How Do I Apply ISO 31000 Without Adding Unnecessary Paperwork?

ISO 31000 explained in plain language: the principles, framework and full process, from setting the context through to risk treatment and review.
How Do I Run a Bow-Tie Workshop That Produces Useful Actions?

Twelve specific bow-tie workshop mistakes, from vague focal events to unchallenged barriers, with fixes and a facilitator’s review checklist.
How Do I Keep a Security Risk Assessment Team Working to the Same Process?

A free security risk management wall chart set to keep your project room aligned on what stage the work is at, who leads it, and what happens next.
How Can Practitioners Assess Danger While Accounts Are Disputed?

How practitioners can organise uncertainty, record safety actions and seek specialist input while disputed accounts remain unresolved. A supplementary risk lens.
How Do I Stop a Security Risk Assessment Growing Beyond Its Scope?

Five scoping statement clauses that stop security risk assessment scope creep before it starts, with a worked before-and-after example and template.
How Do I Explain Risk Management to Colleagues Who See Only Paperwork?

Risk management is not paperwork: how to explain that to sceptical colleagues using clear risk statements and bow-tie thinking instead of forms.
