Skip to content

Information Security Risk Assessment

Build a defensible view of security risk by connecting assets, threats, vulnerabilities, existing controls and business impact.

A structured risk process

  1. 01

    Asset identification

    Identify the systems, data, services and business processes relevant to the assessment.

  2. 02

    Threat identification

    Identify realistic threat events and threat actors relevant to the environment.

  3. 03

    Vulnerability analysis

    Identify weaknesses in technology, architecture, process or governance.

  4. 04

    Control review

    Evaluate the safeguards already in place and the evidence supporting them.

  5. 05

    Likelihood assessment

    Estimate how plausible or frequent a risk event may be.

  6. 06

    Impact assessment

    Evaluate financial, operational, regulatory, security and reputational impact.

  7. 07

    Risk rating

    Combine likelihood, impact and control effectiveness using the agreed methodology.

  8. 08

    Risk treatment

    Define mitigation, transfer, avoidance or acceptance options.

  9. 09

    Residual risk

    Assess the remaining risk after planned treatment.

  10. 10

    Management reporting

    Provide a risk register and prioritized treatment plan.

Assessments can be aligned with recognized information-security and risk-management frameworks, including ISO/IEC 27001, ISO/IEC 27005, the NIST Cybersecurity Framework and relevant NIST risk-management guidance, depending on the engagement objective.

Frequently asked questions

What do we receive at the end?

A risk register and a prioritized treatment plan, supported by the risk ratings and the reasoning behind them.

Which framework do you use?

The engagement objective decides. Assessments can be aligned with ISO/IEC 27001, ISO/IEC 27005, the NIST Cybersecurity Framework and relevant NIST risk-management guidance.

Do you assess residual risk?

Yes. Residual risk is assessed after planned treatment so management can see what remains once the treatment plan is delivered.

How is risk rated?

Likelihood, impact and control effectiveness are combined using the methodology agreed for the engagement, and the scale is applied consistently across findings.

How much does it cost?

Scope drives effort. Describe the environment, objective and deadline in the assessment request and we will propose the appropriate scope.

Discuss the scope of your assessment

Tell us what you need to assess, your target timeline and the environment involved. We will review the scope and identify the appropriate next step.

Page last reviewed 6 September 2026