# Organizational Silo Mapping Exercise - **PURPOSE:** Identifies communication barriers, knowledge gaps, and process disconnects between different functions involved in risk management to enable targeted improvements. - **WHEN TO USE:**When planning cross-functional risk governance structures, addressing communication breakdowns, or preparing for security integration initiatives. ## Step 1: Stakeholder Identification List all functions/teams involved in managing security and risk in your organization: | Function/Department | Primary Risk Responsibilities | Key Stakeholders (Names/Roles) | | --- | --- | --- | | Executive Leadership | | | | Information Security | | | | IT Operations | | | | Legal/Compliance | | | | Business Unit Leaders | | | | Risk Management | | | | Finance | | | | Human Resources | | | | [Add other relevant functions] | | | Table 1: Stakeholder Identification ## Step 2: Information Flow Mapping For each primary risk management process, map current information flows between functions: | Risk Process | Originating Function | Receiving Function(s) | Information Shared | Formal/Informal | Effectiveness (1-5) | | --- | --- | --- | --- | --- | --- | | Risk Assessment | | | | | | | Security Incident Response | | | | | | | Vulnerability Management | | | | | | | Compliance Reporting | | | | | | | Risk Acceptance | | | | | | | [Other key processes] | | | | | | Table 2: Information Flow Mapping ## Step 3: Silo Analysis Identify specific barriers between functions using this matrix. For each pair of functions, rate the current state of: - Communication (1=Poor, 5=Excellent) - Shared Understanding (1=Minimal, 5=Comprehensive) - Process Integration (1=Siloed, 5=Seamless) - Common Language (1=Different terminologies, 5=Shared vocabulary) | Function | Information Security | IT Operations | Legal/Compliance | Business Units | Risk Management | Finance | HR | | --- | --- | --- | --- | --- | --- | --- | --- | | Executive Leadership | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | | Information Security | — | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | | IT Operations | | — | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | | Legal/Compliance | | | — | C: U: P: L: | C: U: P: L: | C: U: P: L: | C: U: P: L: | | Business Units | | | | — | C: U: P: L: | C: U: P: L: | C: U: P: L: | | Risk Management | | | | | — | C: U: P: L: | C: U: P: L: | | Finance | | | | | | — | C: U: P: L: | | HR | | | | | | | — | Table 3: Silo Analysis ## Step 4: Bridge Building Plan Based on the analysis, identify the most significant silos and develop specific actions to address them: | Priority Silos (Function Pairs) | Key Issues Identified | Bridge-Building Actions | Owner | Timeline | | --- | --- | --- | --- | --- | | 1. | | | | | | 2. | | | | | | 3. | | | | | | 4. | | | | | | 5. | | | | | Table 4: Bridge Building Plan ## IMPLEMENTATION TIPS: - Conduct this exercise with representatives from multiple functions to ensure diverse perspectives - Look for patterns where multiple groups identify the same communication barriers - Focus on process improvements rather than placing blame for existing silos *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)