# Cross-Functional Risk Assessment Workshop - **PURPOSE:** Provides a structured method for breaking down silos between security and business teams by collaboratively identifying and assessing security risks in business terms. - **WHEN TO USE:**When initiating security risk assessments for critical business processes, evaluating risks in new initiatives, or improving collaboration between security and business units. ## PREPARATION ### Identify Participants: - Business process owner(s) - Security representative(s) - IT/system representative(s) - Legal/compliance representative (if applicable) - Finance representative (if applicable) ### Pre-Workshop Materials: - Business process documentation - System architecture diagrams - Previous assessment results (if available) - Asset inventory for the process - Recent incident data (if relevant) ## WORKSHOP AGENDA (3-4 hours) ### 1. Business Context Setting (30 minutes) - Business owner presents process overview - Clarify business objectives and key metrics - Identify critical dependencies and constraints - Define scope of assessment ### 2. Asset and Value Identification (45 minutes) Brainstorm key assets involved in the process For each asset, determine: - Business value/criticality - Confidentiality requirements - Integrity requirements - Availability requirements - Rank assets by business importance ### 3. Threat Scenario Development (60 minutes) For top 3-5 assets, brainstorm threat scenarios using this format: "What if [threat source] exploited [vulnerability/condition] to [action] our [asset], resulting in [consequence]?" - Security team provides input on likely threats - Business team provides input on potential impacts - Document scenarios in risk register format ### 4. Risk Analysis (60 minutes) For each scenario, assess: - Likelihood: How probable is this scenario? - Business impact: What would be the consequences? - Existing controls: What protections are already in place? - Control effectiveness: How well do current controls work? - Determine residual risk level - Identify gaps in current controls ### 5. Next Steps and Ownership (45 minutes) - Assign risk owners for each identified risk - Agree on risk treatment approach - Determine additional control requirements - Establish monitoring and review process - Document decisions in risk register ## FACILITATION GUIDE Tips for the Facilitator: - Establish ground rules emphasizing collaboration and respect - Ensure balanced participation from security and business representatives - Use business language, avoiding technical jargon when possible - Focus discussions on business impact rather than technical vulnerabilities - Document all identified risks for later prioritization - Address disagreements by focusing on data and organizational objectives Common Challenges and Solutions: - Technical focus: Redirect conversation to business implications - Scope creep: Keep discussion focused on the defined process - Blame culture: Emphasize improvement rather than fault-finding - Overconfidence: Use data and examples to challenge assumptions - Disagreement on impacts: Document different perspectives for further analysis ## IMPLEMENTATION TIPS: - Schedule follow-up sessions to review progress on identified risks - Document all findings in the organization's risk register - Consider running workshops quarterly for critical business processes *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)