A cyber risk assessment turns vague anxiety about cyber threats into a structured, defensible view that the board can act on. Done well, it is the single most useful artefact a security function produces in a year — it sets the agenda for investment, audit, and reporting. Done badly, it produces a heatmap that nobody trusts. This article sets out what a credible assessment actually covers, in the order practitioners run it.
The short answer
A comprehensive cyber risk assessment comprises six steps: inventory critical information assets, identify and prioritise threats, evaluate current controls, score risks by likelihood and impact, recommend treatment options, and produce a risk register for the audit committee to sign off. It aligns with ISO/IEC 27005 and NIST SP 800-30.
Mature cyber risk assessments increasingly support board reporting, cyber insurance reviews, procurement assurance, regulatory engagement, and investment prioritisation across the organisation.
Start with assets, not threats
Risk assessments that begin with “what could go wrong” quickly become a list of every plausible bad outcome and produce a register that the business cannot act on. Risk assessments that begin with critical information assets — what matters most, where it lives, who depends on it — produce a focused, defensible view. List the assets, map dependencies, and assign ownership before discussing threats.
Risk scoring becomes actionable only when aligned with the organisation’s defined risk appetite and tolerance thresholds.
Model threats against the assets you actually have
Use a structured threat catalogue (MITRE ATT&CK for adversary techniques; ENISA threat landscape for taxonomy; sector-specific advisories, where available). Each asset is mapped to the threats relevant to its context — an internet-facing application has different exposure to a domain controller. Generic threat lists do not survive contact with an actual environment.
Evaluate current controls honestly
For each threat-asset pairing, assess what controls exist, whether they are operating, and whether they are tested. The honest answers usually surprise: documented controls that are not operated; operated controls that have never been tested; tested controls that have not been retested since the environment changed. The output is the control gap analysis that feeds risk scoring.
Score likelihood and impact consistently
A defensible risk register uses a consistent scoring scheme — typically a five-by-five matrix for likelihood and impact, with anchor descriptions for each level. Scoring is done by the working group, not by individuals, and is documented with the reasoning. The point of consistency is not perfect accuracy; it is comparability across the portfolio of risks.
Recommend treatment — accept, transfer, avoid, mitigate
Every risk in the register has a recommended treatment option with the rationale and the residual risk after treatment. Accept where the residual risk is within appetite. Transfer where insurance or contractual terms move the exposure. Avoid areas where the activity that produces the risk is not core. Mitigate where additional controls reduce the likelihood or impact. The board approves the treatment plan; the operations team executes it.
Produce a register, not a heatmap
The deliverable is a working risk register: asset, threat, current control, residual risk, treatment, owner, and due date. Heatmaps are useful for communication but not for management. The register is reviewed quarterly and refreshed annually, with material changes triggered by significant incidents, environmental changes, or new regulatory expectations.
Mature organisations treat risk assessment as a continuous governance process rather than a once-a-year compliance exercise.
Key Takeaways
- Start with critical information assets — assessments that start with threats produce unactionable lists.
- Threat models are framework-grounded (MITRE ATT&CK, ENISA) and tailored to the actual environment.
- Honest control evaluation usually surfaces documented-but-not-operated and tested-but-stale controls.
- Likelihood-impact scoring works because it is consistent, not because it is precisely accurate.
- Each risk has a treatment recommendation (accept, transfer, avoid, mitigate) with rationale and residual risk.
- The deliverable is a working register the audit committee can review quarterly — not a heatmap.
How Cyber Resilience Can Help
Cyber Resilience helps organisations build defensible cyber risk registers through structured asset analysis, threat modelling, control evaluation, and governance-led risk treatment planning.
Speak to our team to arrange a cyber risk assessment scoping discussion.
