Create your first TRM analysis
The goal is to compare any action you might take in a business on the same terms. That takes a cost-benefit analysis, with time, risk and money as the measures so the comparison stays consistent.
Steps 1 and 2: who gains, who loses
A cost-benefit analysis starts with who stands to gain and who stands to lose. Working that out also tells you what value is created and what value is lost. See Identify customers and patrons.
Step 3: put numbers on it
Give every value, created and lost, a number. Use one unit per value: for example, all time in hours per year, all money in US dollars per month, all risk in “risk impact”.
T-shirt sizes can work too. The more specific you are, the better the comparison.
Step 4: decide what matters most
Ideally, leadership has said which part of TRM is the priority right now, or how to weigh each one. Keep the business’s needs in mind when you decide.
In 2023 my employer put the bottom line first. My direction to my department was:
- Resolve any critical or high-severity security risk immediately.
- Focus planning on saving money.
- Consider time only when the value created is large and the cost is low.
Later in 2023 we had done well on cutting costs, and concern about ransomware was growing. So the direction changed slightly: the first priority now included medium-severity risks too. One simple message, and teams changed how they worked straight away.
Try it
How comfortable are you doing this on your own? What didn’t I answer? I’d love to work through it with your specifics. Get in touch.