# Exercise: Risk Perception Assessment To identify risk perception biases in yourself and your organization, consider the following assessment: - Recall the last three security issues that received significant attention in your organization. Were they the most important risks, or simply the most vivid or recent? - When security issues are raised, does your organization typically respond with "we're different from those who experienced breaches"? This may indicate optimism bias. - Has your organization delayed security improvements despite acknowledging their importance? Status quo bias may be a factor. - Do security communications typically emphasize prevention of loss or creation of value? The framing may be affecting response. - By recognizing these patterns, you can begin to adjust security communications to account for and counteract common biases. *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)