Comprehensive Cyber Risk Assessments

4 Minute read
Qurash Ramlal
Customer Success Manager | Governance & Security Advisory
Comprehensive Cyber Risk Assessments
In this article

Share this article

A cyber risk assessment turns vague anxiety about cyber threats into a structured, defensible view that the board can act on. Done well, it is the single most useful artefact a security function produces in a year — it sets the agenda for investment, audit, and reporting. Done badly, it produces a heatmap that nobody trusts. This article sets out what a credible assessment actually covers, in the order practitioners run it.

The short answer

A comprehensive cyber risk assessment comprises six steps: inventory critical information assets, identify and prioritise threats, evaluate current controls, score risks by likelihood and impact, recommend treatment options, and produce a risk register for the audit committee to sign off. It aligns with ISO/IEC 27005 and NIST SP 800-30.

Mature cyber risk assessments increasingly support board reporting, cyber insurance reviews, procurement assurance, regulatory engagement, and investment prioritisation across the organisation.

Start with assets, not threats

Risk assessments that begin with “what could go wrong” quickly become a list of every plausible bad outcome and produce a register that the business cannot act on. Risk assessments that begin with critical information assets — what matters most, where it lives, who depends on it — produce a focused, defensible view. List the assets, map dependencies, and assign ownership before discussing threats.

Risk scoring becomes actionable only when aligned with the organisation’s defined risk appetite and tolerance thresholds.

Model threats against the assets you actually have

Use a structured threat catalogue (MITRE ATT&CK for adversary techniques; ENISA threat landscape for taxonomy; sector-specific advisories, where available). Each asset is mapped to the threats relevant to its context — an internet-facing application has different exposure to a domain controller. Generic threat lists do not survive contact with an actual environment.

Evaluate current controls honestly

For each threat-asset pairing, assess what controls exist, whether they are operating, and whether they are tested. The honest answers usually surprise: documented controls that are not operated; operated controls that have never been tested; tested controls that have not been retested since the environment changed. The output is the control gap analysis that feeds risk scoring.

Score likelihood and impact consistently

A defensible risk register uses a consistent scoring scheme — typically a five-by-five matrix for likelihood and impact, with anchor descriptions for each level. Scoring is done by the working group, not by individuals, and is documented with the reasoning. The point of consistency is not perfect accuracy; it is comparability across the portfolio of risks.

Recommend treatment — accept, transfer, avoid, mitigate

Every risk in the register has a recommended treatment option with the rationale and the residual risk after treatment. Accept where the residual risk is within appetite. Transfer where insurance or contractual terms move the exposure. Avoid areas where the activity that produces the risk is not core. Mitigate where additional controls reduce the likelihood or impact. The board approves the treatment plan; the operations team executes it.

Produce a register, not a heatmap

The deliverable is a working risk register: asset, threat, current control, residual risk, treatment, owner, and due date. Heatmaps are useful for communication but not for management. The register is reviewed quarterly and refreshed annually, with material changes triggered by significant incidents, environmental changes, or new regulatory expectations.

Mature organisations treat risk assessment as a continuous governance process rather than a once-a-year compliance exercise.

Key Takeaways

  • Start with critical information assets — assessments that start with threats produce unactionable lists.
  • Threat models are framework-grounded (MITRE ATT&CK, ENISA) and tailored to the actual environment.
  • Honest control evaluation usually surfaces documented-but-not-operated and tested-but-stale controls.
  • Likelihood-impact scoring works because it is consistent, not because it is precisely accurate.
  • Each risk has a treatment recommendation (accept, transfer, avoid, mitigate) with rationale and residual risk.
  • The deliverable is a working register the audit committee can review quarterly — not a heatmap.

How Cyber Resilience Can Help

Cyber Resilience helps organisations build defensible cyber risk registers through structured asset analysis, threat modelling, control evaluation, and governance-led risk treatment planning.

Speak to our team to arrange a cyber risk assessment scoping discussion.

Qurash Ramlal

Customer Success Manager | Governance & Security Advisory

Qurash Ramlal works closely with Cyber Resilience clients to support long-term cybersecurity maturity, governance alignment, and operational resilience improvement.

With experience across cybersecurity, telecommunications, and managed services environments, he focuses on helping organisations strengthen governance visibility, improve security awareness, and align operational security initiatives to evolving business risk.

Expertise

ISO 27001 • Managed Security Services • Governance • Client Success • Cybersecurity Advisory

Frequently asked questions

How often should we run a comprehensive cyber risk assessment?

Annually, at a minimum, with quarterly reviews of the existing register. Material environment changes (acquisitions, new product lines, significant tooling changes) and material incidents (any breach, major near-miss, regulator engagement) trigger an out-of-cycle refresh.

Which framework should we align to — ISO 27005 or NIST 800-30?

Either works. ISO 27005 integrates cleanly with an ISO 27001 ISMS and is the more common choice in South Africa. NIST SP 800-30 is widely used where the broader cyber programme aligns with NIST CSF. The methodology is more important than the framework label; consistency year over year matters more than either.

How does this differ from a vulnerability assessment?

A vulnerability assessment is technical — it finds specific weaknesses in systems and applications. A cyber risk assessment is broader — it covers people, process, technology, and supplier exposure, and it expresses risk in business terms. They feed into each other: vulnerabilities found in technical assessment populate the risk register.

Who should own the cyber risk register?

Operationally, the CISO or equivalent. Accountability rests with the executive sponsor or risk committee. The audit committee or board reviews it. Treatment actions are owned by the function delivering the control. Diffuse ownership across these layers is the most common reason registers go stale.

Related Insights

Cyber resilience insights grounded in operational reality.

Practical guidance, operational perspectives, regulatory insights, and forensic-led thinking across cybersecurity, governance, resilience, and digital risk.

Need Clarity on your CURRENT RESILIENCE POSTURE?

Whether you need a focused assessment, operational support, governance maturity, or incident response guid-ance, we will help you understand your current position and build a practical path forward.