# Security-Business Value Mapping Workshop - **PURPOSE:** Facilitates structured collaboration between security and business leaders to identify and document how security activities create business value. - **WHEN TO USE:**During strategic planning, when building business cases for security investments, or when seeking to improve security's strategic positioning. ## Workshop Preparation: Duration: 2-3 hours Participants: CISO, security team leaders, business unit representatives, finance Materials: Workshop templates (below), whiteboard/digital collaboration tool ## PART A: Value Stream Identification ### Step 1: Have business leaders identify their most important value streams: | Business Value Stream | Key Activities | Success Measures | Value to Organization | | --- | --- | --- | --- | | [Example: Customer onboarding] | [List key activities] | [How success is measured] | [Revenue/strategic value] | | | | | | Table 1: Value Stream Identification ### Step 2: Identify where security interacts with each value stream: | Value Stream | Security Touchpoints | Current Impact (Positive/Negative) | Opportunity | | --- | --- | --- | --- | | [From Step 1] | [Where security is involved] | [How security helps/hinders] | [Improvement potential] | | | | | | Table 2: Security Touchpoints ## PART B: Value Contribution Analysis ### Step 3: For each value stream, assess what security protects: | Value Stream | Assets Protected | Threats Mitigated | Business Impact if Compromised | Protection Value | | --- | --- | --- | --- | --- | | [From Step 1] | [Critical assets] | [Relevant threats] | [Business consequence] | [Estimated value] | | | | | | | Table 3: Risk Protection Value ### Step 4: Identify how security enables business innovation and growth: | Business Initiative | Security Enablement | Without Security | With Security | Value Contribution | | --- | --- | --- | --- | --- | | [Example: Cloud migration] | [Security capabilities] | [Slower, riskier] | [Faster, safer] | [Time/cost savings] | | | | | | | Table 4: Business Enablement Value ### Step 5: Assess regulatory and contractual requirements: | Regulation/Requirement | Business Activities Affected | Consequences of Non-Compliance | Security's Role | Value Provided | | --- | --- | --- | --- | --- | | [Example: GDPR] | [Affected processes] | [Penalties/business impact] | [Controls provided] | [Risk avoided] | | | | | | | Table 5: Compliance Value ## PART C: Metrics Development ### Step 6: For each value area, develop metrics that demonstrate security's contribution: | Value Area | Business Outcome | Security Contribution | Proposed Metric | Data Sources | | --- | --- | --- | --- | --- | | [From previous steps] | [Business result] | [Security's role] | [How to measure] | [Where to get data] | | | | | | | Table 6: Metric Identification ### Step 7: Prioritize metrics and plan implementation: | Metric | Value Demonstration | Implementation Difficulty | Timeline | Owner | Resources Needed | | --- | --- | --- | --- | --- | --- | | [From Step 6] | [Business value shown] | [Low/Medium/High] | [Target date] | [Responsible person] | [What's required] | | | | | | | | Table 7: Implementation Planning ## Workshop Output: - Documented security-business value connections - Prioritized list of business-aligned security metrics - Implementation roadmap for new measurement approaches - Shared understanding between security and business teams ## IMPLEMENTATION TIPS: - Include representatives from across the business to ensure comprehensive value identification - Focus on business outcomes rather than security activities throughout the exercise - Document and share results with executive leadership to build support for security initiatives *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)