Compyl
Sponsored by:
The Conversation Starts in....
Days
Hours
Minutes
Seconds

Your Risk Register Is Not a Business Case

Who’s on this one

Kayne McGladrey — Cybersecurity Risk Advisor, CISSP and Senior IEEE Member, and author of Cyber Risk is a Myth (Routledge). A former CISO who spent years as a virtual CISO for SMBs and mid-market firms, sitting in the board meetings where security gets filed under cost rather than investment. He has released 43 templates and 24 exercises from the book free at kaynemcgladrey.com/myth.

Sid Roper — VP of Customer Solutions, Compyl. 24 years in cybersecurity and GRC, spent replacing manual chaos with automated trust and scalable compliance.

Daniel Tangney — Host, GRC Radio.

Who should be in the room

  • GRC and compliance managers — you maintain the register. This is about what to do with it when someone asks what it is worth.
  • CISOs and security leaders — the budget conversation, and the objections finance raises before you reach the second slide.
  • Anyone who has presented a risk and been told to come back next quarter.

Run of show

Forty-five minutes, no slides. A real conversation, then your questions.

  • Why treating cyber risk as its own category costs you money — Kayne’s core argument, in about a minute.
  • Business impact analysis: what actually generates revenue, and the dependencies nobody documented.
  • Putting a number on a vulnerability that survives contact with a CFO.
  • The objections finance always raises — and what answers them.
  • Metrics an executive acts on, versus the ones that get ignored.
  • Live Q&A — bring a risk you have been trying to get funded.
When
October 8, 2026
Time
3:00 pm –
3:45 pm

We will cover:

  • Why a risk register is a list of problems, and a budget request is a business case
  • Finding what actually generates revenue — and the undocumented dependencies underneath it
  • Putting a defensible number on a vulnerability without inventing false precision
  • The objections finance raises before you reach the second slide, and what answers them
  • Metrics an executive will act on, versus the ones filed under someone else’s problem
  • What deferred governance actually costs, where the regulatory fine is the smallest line item

"(Required)" indicates required fields

Name(Required)
Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies