I wish all security pros practiced a scenario-first mindset. Explanations based on risk scenarios before jumping to best practices, gaps, controls, compliance etc. I wrote an essay to coach on this: "Writing a risk scenario"
https://medium.com/starting-up-security/writing-a-risk-scenario-bdbe6e20bfcb