# Risk Communication Decision Tree - **PURPOSE:** Guides security professionals in selecting the most effective communication approach based on executive decision-making styles and organizational context. - **WHEN TO USE:**When planning how to present vulnerability findings to different stakeholders, especially those with decision-making authority. ## **START:** Security vulnerability identified ### **1. WHO**needs this information? → Board of Directors → Focus on governance, reputation, and strategic risk → C-Suite → Focus on business impact, resource requirements, and competitive positioning → Business Unit Leaders → Focus on operational impacts and customer implications → Technical Leaders → Include detailed vulnerability information and remediation steps ### **2. WHAT** is their primary decision-making style? → Analytical → Lead with data, ROI calculations, and probability assessments → Intuitive → Lead with scenarios, case studies, and pattern recognition → Consensus-driven → Provide comparison to peer organizations and industry standards → Action-oriented → Lead with clear recommendations and implementation steps ### **3. WHEN** is the optimal timing? → Budget planning cycle → Emphasize financial impacts and resource requirements → After industry breach event → Highlight similarities to recent incidents → Strategic planning session → Connect to long-term business objectives → Regular security review → Place in context of overall security posture ### **4. HOW** should information be presented? → High competing priorities → Limit to one page with clear decision request → Limited technical background → Use analogies and visual explanations → Risk-averse culture → Present multiple options with risk/benefit analysis → Compliance-focused → Emphasize regulatory requirements and potential penalties ### **5. WHAT** decision is needed? → Resource allocation → Provide clear cost/benefit analysis → Risk acceptance → Define residual risk in business terms → Prioritization → Compare against other business risks → Policy exception → Clarify business implications of exception ## **OUTPUT:** Tailored communication approach aligned with decision-maker needs ## IMPLEMENTATION TIPS: - Map the decision-making styles of key executives before using this tool - Review and refine your approach based on feedback from successful (and unsuccessful) security communications - Consider having different versions of your message for different stakeholders *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)