Cyber Risk Assessment
Identification and evaluation of cyber risks to your critical services, with a treatment plan management can approve and track.
- NIST CSF 2.0 functions
- Govern Identify
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
Management decides on budgets and priorities in terms of risk, not vulnerabilities. Without a structured risk assessment, security teams struggle to explain why one investment matters more than another.
We run cyber risk assessments that link threats to business impact and give management a clear basis for decisions.
What you get
- Cyber risks described in business terms management understands
- Risks ranked by likelihood and impact on critical services
- A treatment plan with owners, costs and deadlines
- A risk register that can be maintained after the project
What we cover
- Critical asset and service identification
- Threat and vulnerability analysis
- Likelihood and impact rating
- Risk treatment planning
- Risk methodology and register design
How we work
-
Set context
We agree scope, risk criteria and the methodology, aligned with ISO/IEC 27005 and NIST SP 800-30.
-
Identify
We identify critical assets, threats and existing controls through workshops and reviews.
-
Analyze
We rate likelihood and impact for each risk with the people who own the assets.
-
Evaluate
We rank risks against your appetite and agree which need treatment.
-
Plan treatment
We recommend treatment options and build the plan with owners and deadlines.
Deliverables
- Risk methodology and criteria
- Asset and threat inventory
- Risk register
- Risk assessment report
- Risk treatment plan
Not sure where to start? Our online self-assessment gives you a first view of where you stand.
Questions buyers ask
How is this different from a security assessment?
A security assessment checks controls. A risk assessment asks which events could harm the business, how likely they are and what to do about them.
Can the results feed ISO/IEC 27001?
Yes. The methodology and register are designed to support an ISO/IEC 27001 information security management system.
Related offerings
-
Security Assessment
An evidence-based review of your security controls, processes and technology against recognized frameworks, with a prioritized improvement roadmap.
NIST CSF function: Govern NIST CSF function: Identify -
Governance, Risk and Compliance
Security policies, risk management and compliance processes that meet regulator expectations and work in daily operations.
NIST CSF function: Govern -
Security Strategy and Program
A security strategy and multi-year roadmap tied to your business goals, risks and budget, with a program structure to deliver it.
NIST CSF function: Govern