Governance, Risk & Compliance

Security Risk Assessment

Comprehensive cybersecurity risk assessment and professional risk register aligned with your strategic decisions

We identify and assess cybersecurity risks in your organization following ISO 27005 and NIST methodology, building a structured risk register that enables management to make informed decisions about risk acceptance or treatment.

What's included

  • Inventory and classify information assets by confidentiality, integrity and availability and map them to critical processes
  • Identify threats and vulnerabilities per asset and build risk scenarios
  • Measure inherent risk through likelihood and impact on an agreed rating scale
  • Identify existing controls and calculate residual risk after treatment
  • Assign a treatment option to each risk (mitigate, accept, transfer, avoid) and a named risk owner
  • Define risk appetite and tolerance at management level and align them with business objectives

Methodology & standards

01

Risk framing: agree the methodology, likelihood and impact scales and acceptance criteria

02

Identification and analysis: inventory assets, threats and vulnerabilities and build risk scenarios

03

Evaluation and ranking: calculate inherent and residual risk and plot them on a risk matrix

04

Treatment plan: set the treatment option, controls, owner and timeline for each risk

05

Governance and monitoring: establish a periodic review cycle and a dashboard to track how risks evolve

Deliverables

  • A professional risk register capturing asset, threat, likelihood, impact and inherent and residual risk
  • A documented risk assessment and treatment methodology with risk acceptance criteria
  • A risk heat map and a top-risk concentration view
  • A risk treatment plan with controls, owners and timelines
  • A risk appetite statement approved by senior management
  • An executive report to the board on top strategic risks with decision recommendations

Regulatory controls it satisfies

ISO/IEC 27005
The information security risk management methodology applied across identification, analysis, evaluation and treatment
NIST SP 800-30 and 800-39
Guidance for conducting risk assessment and risk management at the organization and system tiers
ISO/IEC 27001:2022 (clauses 6.1, 8.2, 8.3)
Feed the ISMS with risk assessment and treatment and link them to the Statement of Applicability
SAMA CSF and NCA ECC-2:2024
Satisfy the risk management domain requirements with a register presentable to the auditor and the regulator

Typical timeline

The risk assessment and register are usually completed in three to six weeks depending on the number of assets and processes in scope.

Common questions

How often should the risk register be updated?

It is reviewed at least annually and after any material change such as a new system launch, a security incident or an organizational change, so it stays a live reflection of the real posture.

What is the difference between inherent and residual risk?

Inherent risk is the level before any control; residual risk is what remains after controls are applied. Acceptance and treatment decisions are based on residual risk measured against the risk appetite.