To address this challenge, the authors seek to to improve agency capacity to implement effective cyber risk management through the PRISM decision model that can lead agencies to make intelligent choices about how best to address cyber risk. The model helps agencies begin by prioritizing risk drivers and interdependencies, and linking cybersecurity goals to mission and operational objectives. The model can also assist agencies in communicating return on security investments to mitigate cyber risks. Such communications can foster discussion, assessment, and decisions and actions to tailor approaches for addressing cyber risk management in government.