This canvas is a thinking tool to help frame the decisions needed to make progress with a proposal. By working through a proposal in this way, the arguments that need to be made, the politics and the obstacles will become clearer.
Situation
Our problem will often be a technical problem. However, it must be described in business terms. It will be competing for funds, people’s time and other resources with proposals that have clear and simple business impacts.
For example, unpatched on-premise servers may be presented as exposing sensitive customer data. The business impact could relate to potential ransoms, regulatory fines, loss of reputation and trust and loss of confidence in the markets. The urgency may be driven by the importance of the data at risk and the growing number of cyber attacks that have been recorded.
Target
When the technical issue has been resolved, what is success in business terms? We should have business measures of success. We may need additional technical measures to ensure that the problem is controlled. Given the urgency of the problem, what needs to be resolved when? There will be components of the problem that are more urgent than others.
For example, success may be defined as providing data security appropriate to the sensitivity of the data. Customer data and other data critical to the operation and survival of the organisation may be deemed to the highest priority. Success could be defined as certification by an independent security consultant that the high priority data is secure. The timeframe for these initial security measures might be set as 3 months with interim milestones that incrementally reduce risk.
Proposal
Expectations of the solution need to be clear. We need to be clear what aspects of the problem we will solve and what we will not address. The solution needs to be outlined in a way that gives confidence to stakeholders. We should be honest about risks so that they can be managed effectively.
For example, our scope will only be the critical data, other data will remain at risk after this initiative. We explain that the best plan is to migrate the critical data to an existing highly secure cloud environment. The on-premise equipment will be decommissioned. We are aiming for cost neutrality. The is a risk that it may not be possible to migrate all critical data, some equipment may be shared and cannot be decommissioned. A detailed risk and impact assessment will be carried out. and appropriate mitigations put in place.
Decision
The decisions that need to be made to deliver the proposal should be clearly laid out with any constraints. The decision makers should identified with their authority stated.
For example, several actions are required. The first action is to immediately commission an independent security consultancy to carry out a detailed baseline assessment of the security risks for critical data. In parallel, carry out a cloud migration risk assessment. Based on these assessments, a remediation plan will be prepared with a request for funds and resources to deliver it. Given the urgency, the decision to proceed should be made by the CISO alone. This will be the top priority for all impacted managers and their teams. They will pause inflight work if requested by the CISO.

Leave a Reply