We identify and assess cybersecurity risks in your organization following ISO 27005 and NIST methodology, building a structured risk register that enables management to make informed decisions about risk acceptance or treatment.
What's included
- Inventory and classify information assets by confidentiality, integrity and availability and map them to critical processes
- Identify threats and vulnerabilities per asset and build risk scenarios
- Measure inherent risk through likelihood and impact on an agreed rating scale
- Identify existing controls and calculate residual risk after treatment
- Assign a treatment option to each risk (mitigate, accept, transfer, avoid) and a named risk owner
- Define risk appetite and tolerance at management level and align them with business objectives
Methodology & standards
Risk framing: agree the methodology, likelihood and impact scales and acceptance criteria
Identification and analysis: inventory assets, threats and vulnerabilities and build risk scenarios
Evaluation and ranking: calculate inherent and residual risk and plot them on a risk matrix
Treatment plan: set the treatment option, controls, owner and timeline for each risk
Governance and monitoring: establish a periodic review cycle and a dashboard to track how risks evolve
Deliverables
- A professional risk register capturing asset, threat, likelihood, impact and inherent and residual risk
- A documented risk assessment and treatment methodology with risk acceptance criteria
- A risk heat map and a top-risk concentration view
- A risk treatment plan with controls, owners and timelines
- A risk appetite statement approved by senior management
- An executive report to the board on top strategic risks with decision recommendations
Regulatory controls it satisfies
Typical timeline
The risk assessment and register are usually completed in three to six weeks depending on the number of assets and processes in scope.
Common questions
How often should the risk register be updated?
It is reviewed at least annually and after any material change such as a new system launch, a security incident or an organizational change, so it stays a live reflection of the real posture.
What is the difference between inherent and residual risk?
Inherent risk is the level before any control; residual risk is what remains after controls are applied. Acceptance and treatment decisions are based on residual risk measured against the risk appetite.
From the same practice