<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you communicate risk to leadership? in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49616#M607</link>
    <description>&lt;P&gt;One of the interesting comments I heard at a conference was that turning up to present on risk with masses of information and giving a very technical explanation is definitely not the way to go.&amp;nbsp; Directors will not want to be made to feel stupid for not following an overly complex the explanation and the more complex you make it the more they're likely to see it as a technology problem rather than a business risk.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 09:23:47 GMT</pubDate>
    <dc:creator>Steve-Wilme</dc:creator>
    <dc:date>2022-02-09T09:23:47Z</dc:date>
    <item>
      <title>How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49445#M596</link>
      <description>&lt;P&gt;Curious how you are communicating risk to leadership.&amp;nbsp; Is the conversation focused on vulnerabilities and remediation?&amp;nbsp; Do you find leadership focused on global events?&amp;nbsp; Does your organization have clearly defined goals and risk limits"&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 14:28:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49445#M596</guid>
      <dc:creator>Charlene</dc:creator>
      <dc:date>2022-01-31T14:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49450#M597</link>
      <description>&lt;P&gt;If it's internal leadership, don't be afraid to ask what's important to them when discussing risk. Some people like digging into the details of a risk matrix or register and some don't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the BOD, keep it short and sweet with a PowerPoint slide for each bullet point:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What's the risk?&lt;/LI&gt;&lt;LI&gt;What's the likelihood/probability?&lt;/LI&gt;&lt;LI&gt;What's the cost if it occurs/manifests?&lt;/LI&gt;&lt;LI&gt;What's the cost to fix it?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If they have more questions, hopefully they do, then more detail can be given verbally rather than a death by power point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recommended reading for anyone who manages risk:&amp;nbsp;&lt;A href="https://www.amazon.com/Risk-Users-Guide-Stanley-McChrystal/dp/0593192206" target="_blank"&gt;Risk: A User's Guide: McChrystal, Stanley, Butrico, Anna: 9780593192207: Amazon.com: Books&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 31 Jan 2022 15:46:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49450#M597</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2022-01-31T15:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49469#M598</link>
      <description>&lt;P&gt;Also have a look at the FAIR methodology&amp;nbsp;&lt;A href="https://www.fairinstitute.org/fair-book" target="_blank"&gt;https://www.fairinstitute.org/fair-book&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 08:49:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49469#M598</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2022-02-01T08:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49479#M599</link>
      <description>&lt;P&gt;Consider adding a step to your thought process: Identify the type of risk to WHO or WHAT?&lt;/P&gt;&lt;P&gt;Financial risk, civil liability risk, criminal liability risk, or reputational risk?&lt;/P&gt;&lt;P&gt;Risk to the enterprise (company) or personal risk to the executive leader?&lt;/P&gt;&lt;P&gt;Risk to the individual leader's career?&lt;/P&gt;&lt;P&gt;Risk to the leader's income?&lt;/P&gt;&lt;P&gt;Civil liability risk to the enterprise or to the leader?&lt;/P&gt;&lt;P&gt;Criminal risk to the enterprise or to the leader?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider that decisions even at the top levels are more likely made based on "&lt;STRONG&gt;&lt;EM&gt;what does this to ME"&lt;/EM&gt; &lt;/STRONG&gt;as opposed to "what does this do to the company?"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cynical? Yeah a bit.&lt;/P&gt;&lt;P&gt;Realistic? Yeah. a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 16:08:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49479#M599</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2022-02-01T16:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49482#M600</link>
      <description>&lt;P&gt;Thanks for the feedback.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enjoyed the book.&amp;nbsp; I really liked the opening sequence.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also recently published&amp;nbsp;&lt;A href="https://www.amazon.com/Ensure-Business-Success-Informed-Decisions-ebook/dp/B09Q7R1HY4/ref=sr_1_1?crid=1TRH4YX2VK376&amp;amp;keywords=charlene+deaver-vazquez&amp;amp;qid=1643737878&amp;amp;s=books&amp;amp;sprefix=charlene+deaver-vazquez%2Cstripbooks%2C60&amp;amp;sr=1-1" target="_blank"&gt;Amazon.com: Ensure Your Business Success With Risk Informed Decisions: How to easily quantify risk eBook : Deaver-Vazquez CISA CISSP, Charlene, Austin Ed.D, Sara: Kindle Store&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What tools /methods do you use?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 17:52:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49482#M600</guid>
      <dc:creator>Charlene</dc:creator>
      <dc:date>2022-02-01T17:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49483#M601</link>
      <description>Right - thanks. Yeah, I certified on FAIR.&lt;BR /&gt;Have you implemented that in your organization?</description>
      <pubDate>Tue, 01 Feb 2022 17:53:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49483#M601</guid>
      <dc:creator>Charlene</dc:creator>
      <dc:date>2022-02-01T17:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49484#M602</link>
      <description>I like how you suggested operational, financial and strategic impacts. That's also called out in the NIST guidance. Do you apply NIST guidance in your organization?</description>
      <pubDate>Tue, 01 Feb 2022 17:54:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49484#M602</guid>
      <dc:creator>Charlene</dc:creator>
      <dc:date>2022-02-01T17:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49509#M604</link>
      <description>&lt;P&gt;It might sound cynical, but only when the UK law was changed to make Directors personally accountable for non compliance with legislation on cookie consent, did action get taken to implement the inform and consent model in most organisations.&amp;nbsp; Back when it became part of the Privacy and Electronic Communication Regulations in 2010 not a great deal was done, except in the public sector, as the organisation running a site was liable as the legal entity.&amp;nbsp; So making it personal works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 08:42:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49509#M604</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2022-02-02T08:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49616#M607</link>
      <description>&lt;P&gt;One of the interesting comments I heard at a conference was that turning up to present on risk with masses of information and giving a very technical explanation is definitely not the way to go.&amp;nbsp; Directors will not want to be made to feel stupid for not following an overly complex the explanation and the more complex you make it the more they're likely to see it as a technology problem rather than a business risk.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 09:23:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49616#M607</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2022-02-09T09:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49619#M608</link>
      <description>&lt;P&gt;Steve - you're right.&amp;nbsp; Making it personal is very effective!&amp;nbsp; LOL&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 14:21:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49619#M608</guid>
      <dc:creator>Charlene</dc:creator>
      <dc:date>2022-02-09T14:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do you communicate risk to leadership?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49620#M609</link>
      <description>&lt;P&gt;Steve - I agree.&amp;nbsp; The higher up the chain of command we go the simpler and more clear the message needs to be.&amp;nbsp; And, everything needs to be discussed in terms of risk to the business in business terms, specific to the business goals.&amp;nbsp; Otherwise, as you say, they will see it as a "cyber" problem not a 'business' problem.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 14:24:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/How-do-you-communicate-risk-to-leadership/m-p/49620#M609</guid>
      <dc:creator>Charlene</dc:creator>
      <dc:date>2022-02-09T14:24:31Z</dc:date>
    </item>
  </channel>
</rss>

