Join ISSA Rainier on Thursday, August 27, 2026, at the Washington State History Museum in Tacoma for an interactive cybersecurity session with author and practitioner Kayne McGladrey ,CISSP.
Most security teams know how to prioritize vulnerabilities by technical severity. But CVSS scores do not always tell you what matters most to the business.
A “critical” vulnerability on a low-value dev system may get urgent attention, while a “medium” flaw affecting a revenue-generating system quietly creates real business risk.
In this interactive session, participants will complete a hands-on vulnerability-to-business impact mapping exercise using a framework from the book, applying it in real time to a vulnerability from their own environment.
Fair warning: you'll be asked to estimate financial impacts, revenue loss, and operational costs. You won't know the exact numbers, and that's the point. The discomfort you feel is the gap between where security professionals sit and where business decisions actually get made. The session closes with participants sharing what they discovered and what they plan to do about it, followed by an open Q&A about the book and the process of writing it.
What you'll learn:
-Why technical severity scores like CVSS don't reflect business risk, and what to use instead
-How to map a specific vulnerability to the business functions and revenue streams it threatens
-A practical framework for estimating financial, operational, reputational, and regulatory impacts, even when you don't have perfect data
-How to translate your findings into language that drives executive action rather than executive confusion
-Why your next career move should involve walking across the building to meet your business leaders
What you'll do:
-Work through a vulnerability-to-business impact mapping framework on paper, using a real vulnerability from your own organization
-Estimate business impacts across four dimensions (financial, operational, reputational, regulatory) using ranges and best guesses
-Calculate a business risk rating that combines likelihood and business impact
-Determine a recommended risk response and proposed solution
Share your key takeaway and planned next step with the room
This session is designed for cybersecurity practitioners, risk leaders, students, job seekers, veterans, and anyone working to make security more relevant to business decision-making.
ISSA Rainier events are community-powered, sponsor-supported, free, and open to the public.
Special thank you to our Platinum annual sponsor, Fortinet
Back to All Events