# Exercise: Stakeholder Mapping for Cultural Change Effective cultural change requires understanding and engaging key stakeholders. This stakeholder mapping exercise helps identify who needs to be involved in your transformation journey: 1.Identify stakeholders across the organization who influence or are affected by security risk decisions. Include representatives from: - Executive leadership - Business unit leaders - IT and security teams - Legal and compliance - Human resources - Operations and product teams 2.Assess each stakeholder's: - Current understanding of security as a business risk (high/medium/low) - Influence over organizational culture (high/medium/low) - Potential resistance factors (e.g., competing priorities, knowledge gaps) - Potential benefits from improved risk integration 3.Develop targeted engagement strategies for different stakeholder groups: - For high-influence supporters: Empower them as change champions - For high-influence resistors: Address concerns and demonstrate business value - For low-influence supporters: Provide tools to elevate their voice - For low-influence resistors: Focus on education and awareness 4.Create a communication plan customized to each stakeholder group's needs, knowledge level, and concerns. This mapping provides a foundation for a targeted change management approach that addresses the specific needs and concerns of different stakeholders throughout your organization. *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)