---
title: "Cyber Risk is a Myth Resources"
description: "Cyber Risk is a Myth Resources This page contains 43 templates and 24 exercises organized by chapter. Each resource is available in Microsoft Word, Markdown, and Proton Docs formats. Some of these doc..."
url: https://kaynemcgladrey.com/myth/
date: 2026-05-19
modified: 2026-08-14
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/08/cover-image-Cyber-Risk-is-a-Myth.webp
type: page
lang: en
---

# Cyber Risk is a Myth Resources

# Cyber Risk is a Myth Resources

This page contains 43 templates and 24 exercises organized by chapter. Each resource is available in Microsoft Word, Markdown, and Proton Docs formats.

Some of these documents might sound very similar, and that’s because after years of consulting, you start to realize that there’s no “one size fits all” solution, and so you develop alternative approaches and work products. If you don’t like one version of something here, try another one.

It’s also important to note that these exercises, worksheets, and templates are presented *in context* in the book [Cyber Risk is a Myth](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054) by Kayne McGladrey (hey, that’s me!). They *aren’t* presented in context here. I’d suggest picking up a copy at your favorite bookstore or from a local library, although these templates (and associated explainer videos and written explanations) should be able to stand on their own. The difference is that you might not know when to choose one instead of another – but that’s okay, pick the one you like the most for the situation.

I’m also considering [turning the book into a course](https://kaynemcgladrey.com/myth/course/). Let me know what you think.

## Chapter 1: The Myth of “Cyber Risk”

### Cybersecurity Translation Cheat Sheet

Most security communications fail because nobody speaks business, so this table translates technical risks into financial terms that actually drive decisions. Readers quickly convert technical security language into business outcomes that support stakeholder decision-making.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Cybersecurity-Translation-Cheat-Sheet---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Cybersecurity-Translation-Cheat-Sheet---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/88QWZ90JPW#sWpaOV4LuzQf)

### Executive Security Communication Template

A structured format for turning security risks into business decisions that get approved instead of ignored. Helps security leaders deliver board ready updates that connect security status to business priorities and drive actionable decisions.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Executive-Security-Communication-Template---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Executive-Security-Communication-Template---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/E2XRVPVKD0#Y66lqKjtkMrh)

### Risk Integration Maturity Assessment

This matrix helps organizations score how well they connect cybersecurity with business risk, exposing the gap between technical silos and unified governance so leaders can stop guessing and start fixing the disconnect. Gain a structured evaluation of your organization’s cybersecurity business risk integration maturity with identified improvement opportunities.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Risk-Integration-Maturity-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Risk-Integration-Maturity-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/DFJ61ME3EW#wSXLwcpCv633)

### Security Investment Prioritization Matrix

This matrix stops security teams from chasing technical severity scores and forces them to justify every dollar spent based on actual business impact and ROI timelines. Users learn to score and prioritize security investments based on business impact rather than technical severity alone.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Security-Investment-Prioritization-Matrix---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Security-Investment-Prioritization-Matrix---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/2MJTRJRAMC#EwyIuV7Ak52I)

### Security-Business Integration Workshop

This workshop breaks down the walls between security and business teams by forcing them to translate technical threats into financial impact and agree on who actually owns the risk. Participants break down security business silos through structured dialogue and create joint ownership of risk management processes.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Security-Business-Integration-Workshop---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Security-Business-Integration-Workshop---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/WYJNDT8TQR#Ji7qQ9bWoK9J)

### Exercise: “Decoding Security-Speak”

This exercise strips away the technical jargon that confuses executives, showing you how to translate security warnings into plain English that highlights real financial and operational risks. Security professionals learn to translate technical jargon into business relevant statements for clearer cross departmental communication.

Read the [full explanation](https://kaynemcgladrey.com/resources/stop-speaking-gibberish-to-your-board-when-discussing-cyber-risks/) or [watch the video](https://youtu.be/0NTAXLUGKjg) tutorial. If I do [a course](https://kaynemcgladrey.com/myth/course/), it’s going to be along these lines.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Exercise---Decoding-Security-Speak---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Exercise---Decoding-Security-Speak---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/S2BNNTRHP4#2AHtu0B3JfYg)

### Exercise: “Risk Translation”

This exercise demonstrates how to translate technical security flaws into business consequences, forcing engineers to stop speaking in vulnerabilities and start talking about revenue loss, regulatory fines, and operational downtime. Practitioners develop skills converting technical security concerns into business impact language executives can act upon.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Exercise---Risk-Translation---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-1---Exercise---Risk-Translation---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/HHVNX0AHWM#Rcn0Ih5Od7A4)

## Chapter 2: Lost In Translation: Why Technical Vulnerabilities Don’t Resonate

### Business Impact Translation Matrix

A template for translating technical vulnerability details into the financial and operational language executives actually make decisions with. Use a structured matrix to convert technical vulnerability details into financial exposure, compliance implications, and timing considerations for executives.

Read the [full explanation](https://kaynemcgladrey.com/resources/stop-wasting-money-on-reports-nobody-reads-the-business-impact-translation-matrix/) or [watch the video](https://youtu.be/v0wAexMIHqQ) tutorial.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Business-Impact-Translation-Matrix---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Business-Impact-Translation-Matrix---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/2JQDR9TKF0#XJn6Cx9I3dkX)

### Business-Focused Vulnerability Translator

Stop sending technical vulnerability reports to your executives and use this worksheet to translate them into the financial language they actually speak. Walk through a full worksheet and executive briefing format that translates a technical vulnerability into business language with quantified impacts and ranked response options.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Business-Focused-Vulnerability-Translator---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Business-Focused-Vulnerability-Translator---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/16M80XDEZM#1XbqZfKRb9v4)

### Risk Communication Decision Tree

A decision tree that maps who needs the information, how they make decisions, and what you need from them, because the right finding delivered the wrong way is still a failed communication. Build a decision tree to select the most effective communication approach for presenting vulnerabilities based on audience, decision style, timing, and context.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Risk-Communication-Decision-Tree---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Risk-Communication-Decision-Tree---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/ACP3PJJJ50#I8kCurb3LjcH)

### Risk-to-Value Mapping Framework

This framework forces executives to stop treating security as an abstract IT problem by mapping specific vulnerabilities directly to the business value drivers they actually care about, such as revenue, uptime, and customer trust. Learn to map security vulnerabilities directly to business value drivers so executives see what is at stake and which fixes matter most.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Risk-to-Value-Mapping-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Risk-to-Value-Mapping-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/TYZF7GZ2R8#Fx0TYZnsNVwr)

### Exercise – Cognitive Bias Identification

A structured exercise for spotting the cognitive biases that make executives ignore your security recommendations, with specific countermeasures so you can stop wondering why nobody acts on perfectly good risk data. Identify and counteract cognitive biases such as availability, optimism, status quo, and framing effects that distort how security risks are perceived and acted upon.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Exercise---Cognitive-Bias-Identification---Cyber-Risk-is-a-Myth) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Exercise---Cognitive-Bias-Identification---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/6D29Y0K4WR#Q5pHY1lyTQT0)

### Exercise – Risk Perception Assessment

This self-assessment helps you identify the cognitive biases that cause organizations to chase vivid threats while ignoring the risks that actually matter. Assess your organization for common risk perception biases by reflecting on recent security incidents and communication patterns.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Exercise---Risk-Perception-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Exercise---Risk-Perception-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/ACCHRG3AB4#8xfQrdIJgjGw)

### Exercise – Vulnerability Translation Practice

This exercise teaches you to convert raw technical vulnerability reports into clear business impact statements covering financial loss, operational downtime, compliance risks, and reputation damage, so executives finally understand why they should care. Practice translating a real technical vulnerability report into business terms that increase the likelihood of executive action.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Exercise---Vulnerability-Translation-Practice---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-2---Exercise---Vulnerability-Translation-Practice---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/40CHWXS57M#HY3FjqdzcOaf)

## Chapter 3: Business Impact Analysis: The Essential Translation Tool

### Business Impact Analysis Maturity Assessment Checklist

A 30-item checklist that forces security teams to prove they can translate technical risks into business language, scored across five maturity levels with space to identify priority fixes.

Read the [full explanation](https://kaynemcgladrey.com/resources/using-the-business-impact-analysis-maturity-assessment-checklist/) or [watch the video](https://www.youtube.com/watch?v=DOn90ZX6pX0) tutorial. This is related to an in-person workshop that I’ve developed, related to the idea of a [training course](https://kaynemcgladrey.com/myth/course/).

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Business-Impact-Analysis-Maturity-Assessment-Checklist---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Business-Impact-Analysis-Maturity-Assessment-Checklist---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/1P9BDW0BQ0#fAGBx9Vr6Nb2)

### Business Impact Quantification Calculator

This calculator translates abstract security scares into hard dollar figures, giving you the financial basis to stop executives from treating cyber risk as something to ignore. Helps with estimating direct and indirect business costs of security incidents including incident response, legal, disruption, reputational, and long term impacts with ROI analysis.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Business-Impact-Quantification-Calculator---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Business-Impact-Quantification-Calculator---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/G6QRHQNSV8#GmUmzUrzb7G2)

### Cross-Functional Risk Translation Workshop

This workshop template brings security teams and business leaders into the same room to translate technical vulnerabilities into dollar amounts, because nobody approves budgets for things they cannot measure.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Cross-Functional-Risk-Translation-Workshop---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Cross-Functional-Risk-Translation-Workshop---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/RYJETSPZ7C#IQkKQk4kkAji)

### Risk Register Template

This simplified risk register template forces security teams to translate technical vulnerabilities into business impacts, ensuring executives finally understand what they are paying to protect. Used for documenting and communicating security risks in business terms with fields for financial, operational, regulatory, and reputational impact.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Risk-Register-Template---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Risk-Register-Template---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/RSW1Y023H4#zJrBHAEZDcy5)

### Vulnerability-to-Business Impact Mapping Framework

This template helps security teams to stop hiding behind CVSS scores and translate technical flaws into the dollar amounts and the operational headaches that make executives move. Five step framework connecting technical vulnerabilities to specific business impacts including financial, operational, reputational, and regulatory consequences with a risk rating calculation. I’ve taught this in-person as part of determining if I should make [a course](https://kaynemcgladrey.com/myth/course/) out of the book.

Read the [full explanation](https://kaynemcgladrey.com/resources/turning-vulnerability-scans-into-budget-approvals/) or [watch the video](https://www.youtube.com/watch?v=HL-rxg-oF7k) tutorial.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Vulnerability-to-Business-Impact-Mapping-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-3---Vulnerability-to-Business-Impact-Mapping-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/AZHVRYKYDM#sRaZojgFakum)

## Chapter 4: Integrating Security Into Enterprise Risk Management

### Cross-Functional Risk Assessment Workshop

A structured three-to-four hour workshop that forces security and business teams into the same room to identify and assess risks using business language instead of technical jargon, because risk discussions that only happen inside the security team are risk discussions that go nowhere. Collaborative workshop for breaking down silos between security and business teams through structured threat scenario development and risk analysis.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-4---Cross-Functional-Risk-Assessment-Workshop---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-4---Cross-Functional-Risk-Assessment-Workshop---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/JYSJ6T61TM#Wd5cEAgVUPhh)

### Risk Acceptance Decision Framework

This template helps you to stop guessing and start documenting exactly who owns a security risk, what it costs, and how long leadership is willing to wait before fixing it. Useful for evaluating, documenting, and approving risk acceptance decisions with tiered authorization levels based on risk severity and acceptance duration.

Read the [full explanation](https://kaynemcgladrey.com/resources/the-risk-acceptance-decision-framework-stop-guessing-and-start-owning-your-exposure/) or [watch the video](https://youtu.be/H2u63xe8ofY) tutorial.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-4---Risk-Acceptance-Decision-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-4---Risk-Acceptance-Decision-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/C5HQWP69FR#EOhJnLI5tyJG)

### Security-ERM Integration Maturity Assessment Framework

A six-dimension scoring framework that benchmarks where your security and enterprise risk programs actually align and where they don’t, so you can fix the gaps instead of debating whether they exist.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-4---Security-ERM-Integration-Maturity-Assessment-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-4---Security-ERM-Integration-Maturity-Assessment-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/JB1CN9C038#WUwt8aC6w1CL)

## Chapter 5: Building The Business Case For Security Investments

### Executive Objection Response Toolkit

This toolkit arms security leaders with brief, data-backed rebuttals for the four most common executive excuses that can prevent cyber investment. Data driven responses to common executive objections about security investment proposals.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Executive-Objection-Response-Toolkit---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Executive-Objection-Response-Toolkit---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/JE1HGPA0VR#Sy3iMt8FiCmn)

### Security Investment Financial Analysis Toolkit

This toolkit helps security teams to stop guessing and start calculating, translating controls into the hard financial metrics that actually convince boards to sign the checks for those controls. Provides a comprehensive framework for quantifying security investment value using standardized business financial metrics.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Investment-Financial-Analysis-Toolkit---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Investment-Financial-Analysis-Toolkit---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/MNZQ4S7ZEC#MR6MTHhiS2ub)

### Security Investment Prioritization Matrix

A weighted scoring template that helps you to compare security investments against actual business criteria instead of arguing about gut feelings in a conference room. Enables objective comparison of security investments using weighted criteria aligned with business priorities.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Investment-Prioritization-Matrix---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Investment-Prioritization-Matrix---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/TG4F8KHTE4#z4tERr0ln3vF)

### Security Value Dashboard for Executives

This dashboard shifts the conversation from abstract threats to concrete business wins by tracking how security drives revenue, accelerates product releases, and proves its worth to executives who care about the bottom line. Demonstrates security value beyond vague “risk reduction” through business focused metrics across multiple categories.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Value-Dashboard-for-Executives---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Value-Dashboard-for-Executives---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/QHKZK8PNM8#CDIePZHzfW00)

### Security-Business Alignment Matrix

This matrix helps security teams to stop talking about abstract “threats” and start speaking the language of revenue, deadlines, and strategic goals by mapping every dollar spent to a concrete business outcome. Maps security initiatives to business objectives and creates tailored proposals for different stakeholder groups.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Business-Alignment-Matrix---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Security-Business-Alignment-Matrix---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/8PM9Q9T2HC#3KCOt2eGbKYr)

### Exercise – Opportunity Cost Analysis

This exercise helps you to calculate the real cost of security spending by comparing it against the financial return of doing nothing or investing elsewhere, proving that ignoring risk is often the most expensive option.

Read the [full explanation](https://kaynemcgladrey.com/resources/opportunity-cost-analysis-the-security-tool-your-cfo-actually-wants-to-see/) or [watch the video](https://youtu.be/J3fFi2nSirQ) tutorial.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Exercise---Opportunity-Cost-Analysis---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Exercise---Opportunity-Cost-Analysis---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/ESAN3NF5GM#g5cKUHoAsMbP)

### Exercise – ROI Calculator Template

This spreadsheet template helps security teams to translate risk reduction into dollars, because executives stop listening when you start talking about threats instead of the return on investment. Guides creation of comprehensive security investment ROI analyses accounting for risk reduction and business enablement benefits.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Exercise---ROI-Calculator-Template---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-5---Exercise---ROI-Calculator-Template---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/JVW17QFYPG#HtxCAf92fT23)

## Chapter 6: Metrics That Matter: Measuring Security In Business Terms

### Business-Aligned Security Metrics Selection Framework

This framework guides security leaders in translating technical controls into financial language that executives actually understand, ensuring security investments are justified by business outcomes rather than fear. Uses a five step framework for mapping business objectives to security dependencies and defining business relevant metrics with stakeholder specific views.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Business-Aligned-Security-Metrics-Selection-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Business-Aligned-Security-Metrics-Selection-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/QTXC6H4C10#DiEoNWUUwt01)

### Security Communication Playbook

This playbook provides structured communication templates to translate security risks into business terms executives will actually read and act on. Comprehensive playbook with audience analysis, message templates, checklists, and storytelling frameworks for translating security into business language.

Read the [full explanation](https://kaynemcgladrey.com/resources/security-communication-playbook-making-security-reports-that-people-actually-read/) or [watch the video](https://www.youtube.com/watch?v=1BnKJSs4SIE) tutorial.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Security-Communication-Playbook---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Security-Communication-Playbook---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/PGMT3AK7B0#VRgGSVuz7bNn)

### Security Investment ROI Calculator

This spreadsheet template helps security teams to stop talking about threats and start speaking the main language executives understand: money. A five part calculator that quantifies security investments in financial terms spanning risk reduction, business enablement, and operational efficiency.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Security-Investment-ROI-Calculator---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Security-Investment-ROI-Calculator---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/5FHEZ79HMM#BqOw0E6NO1MB)

### Security-Business Value Mapping Workshop

This workshop template guides security and business leaders through a structured session to map security activities to revenue streams, quantify protection value, and build metrics that prove security drives growth rather than just blocking progress.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Security-Business-Value-Mapping-Workshop---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Security-Business-Value-Mapping-Workshop---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/CE44AEBA8G#kcOXJ5cN8i68)

### Exercise – Audit Your Current Metrics

This worksheet helps you to list every security metric you report to executives, classify them by activity versus impact, and find the gaps between your vanity metrics and actual business value.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Audit-Your-Current-Metrics---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Audit-Your-Current-Metrics---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/3YHH16RAHG#LIIbtCvI6Rvi)

### Exercise – Dashboard Design Workshop

This worksheet guides security teams through building executive dashboards that replace vague risk scores with the specific metrics and alert thresholds needed to trigger real business decisions. Used for designing executive security dashboards with templates for metric selection, layout, and evaluation.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Dashboard-Design-Workshop---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Dashboard-Design-Workshop---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/BE9NM9J0Q0#irQtMtatK3dp)

### Exercise – Designing Your Metrics Framework

This worksheet guides you through mapping security activities to business outcomes so you can stop reporting vanity numbers and start proving financial value. Design a security metrics framework from scratch, including metric definition templates and example metrics across four categories.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Designing-Your-Metrics-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Designing-Your-Metrics-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/C14N8RNTGC#VHnXCFk2Cxmw)

### Exercise – Developing Stakeholder-Specific Reports

A worksheet for mapping what each audience actually needs from security reporting, building tailored report templates for boards and executives, and collecting feedback so reports stay useful instead of becoming shelf decorations.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Developing-Stakeholder-Specific-Reports---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-6---Exercise---Developing-Stakeholder-Specific-Reports---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/F6CMNEZZP4#LrCsNoiyb4An)

## Chapter 7: Governance Models For Integrated Security And Risk

### Decision Authority Matrix for Security Risks

This matrix cuts through the confusion of security governance by helping assign clear accountability for strategic, operational, and incident response decisions, ensuring that risk acceptance and exception approvals happen at the right level without paralyzing the business. Walk away with a customizable RACI based decision authority matrix mapping security decisions across board, executives, and operational roles, plus tiered escalation thresholds and an exception approval workflow.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Decision-Authority-Matrix-for-Security-Risks---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Decision-Authority-Matrix-for-Security-Risks---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/8SFHZPGYE4#r5dokbygBrwS)

### Risk Appetite Statement Development Framework

This framework turns vague security fears into concrete, board-ready statements by defining exactly what risks the business will accept and what it will not, so you can stop guessing and start governing. A six step framework for developing actionable, business aligned security risk appetite statements across multiple risk categories with qualitative descriptions, quantitative boundaries, and governance implications.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Risk-Appetite-Statement-Development-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Risk-Appetite-Statement-Development-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/ECEMN2QAQW#LVC7NUxKGlnJ)

### Security Governance Maturity Assessment

A four level maturity scoring instrument across 24 governance criteria in four domains, plus a prioritized improvement planning methodology targeting the lowest scoring areas.

Read the [full explanation](https://kaynemcgladrey.com/resources/security-governance-maturity-assessment-without-the-guesswork/) or [watch the video](https://www.youtube.com/watch?v=Vh-uXHltFro) tutorial.

[Word](http://Chapter-7---Security-Governance-Maturity-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Security-Governance-Maturity-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/Q7CJNVSP04#3iexVAk5qq9c)

### Exercise – Decision Rights Mapping

This exercise walks teams through mapping security decisions to specific roles so you stop guessing who owns the approval and start fixing the gaps that cause real operational headaches. Map security decision types to responsible roles using RACI, define escalation triggers, and validate the resulting matrix for gaps and conflicts before implementation.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Decision-Rights-Mapping---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Decision-Rights-Mapping---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/6NK665234C#fi8KUDfQ9Flp)

### Exercise – Governance Implementation Planning

This exercise outlines a six-step process to move governance from theory to reality by assessing maturity, defining targets, and mapping out a phased roadmap that accounts for human resistance.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Governance-Implementation-Planning---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Governance-Implementation-Planning---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/58AVPB68B4#x6kulkZBjMR2)

### Exercise – Governance Structure Assessment

This exercise walks you through documenting governance bodies, mapping information flows, and spotting the gaps and redundancies that let security decisions stall while business stakeholders wonder why nothing moves.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Governance-Structure-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Governance-Structure-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/GJTSN4SB80#aeFQcbPOUo3k)

### Exercise – Resistance Mapping and Mitigation

A practical framework for mapping resistance to governance changes and developing communication strategies that prevent pushback from undermining your risk management initiatives.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Resistance-Mapping-and-Mitigation---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-7---Exercise---Resistance-Mapping-and-Mitigation---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/6WJRWMYH4R#VqtpWnGAU8vb)

## Chapter 8: Creating A Culture Of Integrated Risk Management

### Organizational Silo Mapping Exercise

This worksheet helps you map communication breakdowns between security, IT, legal, and business teams so you can stop blaming departments and start fixing the actual process gaps that let risk slip through the cracks.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Organizational-Silo-Mapping-Exercise---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Organizational-Silo-Mapping-Exercise---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/S7GNYA4FVM#2sjCpudc7mz2)

### Risk Culture Maturity Assessment

A scored evaluation framework to measure your organization’s risk culture maturity across five dimensions and turn those honest ratings into prioritized action items through structured gap analysis.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Risk-Culture-Maturity-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Risk-Culture-Maturity-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/M3YCSGPA40#sUiuGN4NMMgO)

### Risk Translation Framework – From Technical to Business Impact

This framework shows security teams how to stop speaking in CVSS scores and start talking about revenue loss, regulatory fines, and strategic delays so executives understand why they need to fund the fix.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Risk-Translation-Framework---From-Technical-to-Business-Impact---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Risk-Translation-Framework---From-Technical-to-Business-Impact---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/FPERKMPRKG#5LqivmIUWc0E)

### Role-Based Risk Awareness Program Template

A fill-in-the-blank template for building security awareness programs that actually speak to specific business functions instead of subjecting everyone to the same generic slide deck. Includes learning objectives, delivery plans, and measurement frameworks.

Read the [full explanation](https://kaynemcgladrey.com/resources/the-role-based-risk-awareness-program-template/) or watch the [video tutorial](https://www.youtube.com/watch?v=yluqwz28iYM).

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Role-Based-Risk-Awareness-Program-Template---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Role-Based-Risk-Awareness-Program-Template---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/SB22N5R6MM#f4BrTbNf1Eao)

### Security Incentive Design Framework

This template guides organizations through six phases of designing reward systems that actually change security behavior, helping leaders spot the unintended consequences that turn good intentions into bad outcomes.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Security-Incentive-Design-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Security-Incentive-Design-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/RK950SBDB4#na6IGK03zzeD)

### Exercise – Designing Risk Incentives

This four-step framework audits your current risk incentives, designs aligned alternatives, implements them systematically, and measures whether behavior actually changes.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Exercise---Designing-Risk-Incentives---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Exercise---Designing-Risk-Incentives---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/MP2ZF17FSR#sIwL1qzASDOW)

### Exercise – Stakeholder Mapping for Cultural Change

This worksheet guides you through identifying the people who hold power over security decisions, assessing their resistance, and building a communication plan that stops pretending everyone is on the same page.

[Word](http://Chapter-8---Exercise---Stakeholder-Mapping-for-Cultural-Change---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-8---Exercise---Stakeholder-Mapping-for-Cultural-Change---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/4SV8V2VEFR#QqxVMwBKCHMe)

## Chapter 9: From Risk Reduction To Business Enablement

### Executive Security Value Communication Toolkit

A communication toolkit providing audience analysis checklists, message reframing templates, briefing structures, and value dashboards for articulating security’s business impact to executives.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Executive-Security-Value-Communication-Toolkit---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Executive-Security-Value-Communication-Toolkit---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/73WHF479GR#T8T5sWB8Y7ac)

### Security Business Enablement Matrix

A matrix worksheet that helps security leaders map security capabilities to business objectives across operational enablement, trust, compliance, and innovation dimensions with quantifiable metrics.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Business-Enablement-Matrix---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Business-Enablement-Matrix---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/Y695TFJ2DW#nMrjTZzQwB8P)

### Security Competitive Differentiation Framework

This worksheet helps you move past generic security claims by forcing a direct comparison against competitors and mapping specific capabilities to actual customer value, so you can finally stop selling fear and start selling a measurable advantage.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Competitive-Differentiation-Framework---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Competitive-Differentiation-Framework---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/92Y8MMPQX8#GPQxB80uqBn6)

### Security Investment Business Case Template

A structured business case template that positions security investments as business enablers with revenue, cost optimization, and risk mitigation value frameworks alongside ROI calculations.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Investment-Business-Case-Template---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Investment-Business-Case-Template---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/3JW95B6EB8#29o4fLTgUe4j)

### Security-Enabled Business Opportunity Assessment

A structured template for building security budget requests that speak in business outcomes instead of fear, because nobody in the C-suite ever approved a project because “the risk is really scary.”

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Enabled-Business-Opportunity-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-9---Security-Enabled-Business-Opportunity-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/BYX89ASCRM#ZOU7KRRXlf8x)

## Chapter 10: Putting It All Together: Integrated Risk Management In Action

### Integration Progress Dashboard

Populate a ready made dashboard template tracking process, outcome, and perception metrics alongside success stories and challenge mitigations for regular stakeholder reporting.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Integration-Progress-Dashboard---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Integration-Progress-Dashboard---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/RV88R56MDG#NsQxCsMkmknj)

### Security Integration Challenge Resolution Toolkit

This toolkit helps you identify the specific cultural and technical barriers stopping security from becoming a business enabler rather than just another compliance hurdle. Diagnose integration challenges across four categories, analyze root causes for your top three, and build detailed resolution strategies using the provided framework and common strategy library.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Security-Integration-Challenge-Resolution-Toolkit---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Security-Integration-Challenge-Resolution-Toolkit---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/WGTCQGBKXG#rE7ODRZUwhIS)

### Security-Business Integration Maturity Assessment

This toolkit gives security and business leaders a straightforward way to diagnose resistance, map root causes, and build resolution strategies that stop treating security as a barrier and start treating it as a business enabler. Complete a 24 dimension maturity assessment scored 1 – 4 across five categories to pinpoint integration strengths and gaps and guide next steps.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Security-Business-Integration-Maturity-Assessment---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Security-Business-Integration-Maturity-Assessment---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/YK3D73NH48#tpWaBQkDjZ8W)

### Exercise – Benchmark Your Organization

This self-assessment helps you score your organization’s security integration across governance, reporting, and risk frameworks so you can stop guessing where your program stands and start fixing the gaps. Rate your organization’s security business integration across governance, reporting, and risk frameworks on a 1 5 scale to establish a baseline maturity score.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Benchmark-Your-Organization---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Benchmark-Your-Organization---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/KGMPWEE998#k0tGNGFT5nd7)

### Exercise – Build Your Custom Implementation Plan

A fill-in-the-blanks template for building a phased security integration plan, complete with prioritized initiatives, resource requirements, and a prioritization matrix for sequencing security integration efforts, because good intentions without a plan are just expensive surprises waiting to happen.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Build-Your-Custom-Implementation-Plan---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Build-Your-Custom-Implementation-Plan---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/KMF0E0Y2FC#xcm6OBa2LFv8)

### Exercise – Design Your Progress Measurement System

How you’ll measure progress and report it to who cares, because a plan that doesn’t report results to stakeholders is a vanity project.

Read the [full explanation](https://kaynemcgladrey.com/resources/design-your-progress-measurement-system) or watch the [video tutorial](https://youtu.be/N9AxMST3wMM).

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Design-Your-Progress-Measurement-System---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Design-Your-Progress-Measurement-System---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/67SNP39SFW#8ran8IIGAczi)

### Exercise – Develop Your Challenge Mitigation Strategy

Catalog organizational, resource, and technical challenges, then prioritize them on an impact likelihood matrix and develop mitigation strategies with assigned owners and timelines.

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Develop-Your-Challenge-Mitigation-Strategy---Cyber-Risk-is-a-Myth.docx) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Develop-Your-Challenge-Mitigation-Strategy---Cyber-Risk-is-a-Myth.md) | [Proton Docs](https://drive.proton.me/urls/HVD85SHJBW#N2FiaIGzzMVc)

### Exercise – Identify Your Organization’s Transformation Opportunities

This worksheet helps you to pinpoint where security and business goals clash, then map out the specific leaders, metrics, and resources needed to turn those conflicts into quick wins. I’ve taught this as an in-person workshop to see if this could be a part of [a course](https://kaynemcgladrey.com/myth/course/).

[Word](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Identify-Your-Organization) | [Markdown](https://kaynemcgladrey.com/cyberriskisamyth/Chapter-10---Exercise---Identify-Your-Organization) | [Proton Docs](https://drive.proton.me/urls/Z6NHYDPYMC#WRAhpMI63lp4)

### Want this to be a course?

I’m considering turning the whole book and all the resources into a course for executives, managers, and future leaders. [Learn more](https://kaynemcgladrey.com/myth/course/).
