A cybersecurity risk assessment is a structured list of what your organisation holds, what could go wrong with it, and how much damage that would cause. You can produce a credible first version in-house in two or three focused days.
The first pass changes the conversation later. You arrive at any paid engagement with your own asset list and your own ranked concerns.
Start with what you hold, not what you fear
List systems and data before you list threats. Every place customer records live, every finance system, every laptop, cloud tenant, and shared mailbox.
Add three columns: who owns it, who can reach it, and what happens if it stops for a week. That last column does most of the work later.
Include shadow systems. The marketing spreadsheet in someone’s personal cloud drive belongs on the list as much as the finance platform.
Write threat scenarios in plain language
Skip the CVE numbers. A risk assessment is not a scan, and confusing the two is why so many of these documents go unread.
Write sentences a non-technical director understands. “The finance mailbox is compromised and a supplier invoice gets redirected.” “Ransomware encrypts the file server and the backup turns out to be untested.”
Three to six scenarios per significant asset is plenty. A scenario that maps to nothing on your inventory is a headline, not your exposure.
Score likelihood and impact without faking precision
Use a five-by-five matrix. Likelihood one to five, impact one to five, multiply them.
Resist decimals. Nobody in a small organisation can say a breach is 4.7 percent likely, and inventing that figure costs you credibility with whoever approves the budget.
Score each risk as it stands today, using the controls actually running rather than the ones in a policy document. That gap is usually the most useful thing you find.
Build the register that carries the decisions
The register is the deliverable, not the report. Six columns cover it: risk, asset, current score, named owner, decision, and review date.
A named owner is non-negotiable. Risks assigned to “IT” or “the business” never move, and an auditor spots that pattern in seconds.
Sort by score and draw a line. Everything above it gets funded this year. Everything below it gets reviewed on the date you wrote down.
Decide treat, tolerate, transfer, or terminate
Every scored risk gets one of four decisions. Treat means adding a control, which is where our shortlist of the security solutions most businesses actually need becomes useful.
Tolerate means you accept it and say so in writing. Transfer usually means insurance or a contract clause. Terminate means you stop doing the risky thing, the cheapest option and the one people forget.
Technical risks need an ongoing cycle rather than a single decision. The five phases of the vulnerability management lifecycle describe how that repeating work is structured.
Where the do-it-yourself version stops
Three situations need an outside firm: a certification body that requires an independent assessor, a technical test that needs someone who breaks things for a living, and a dispute between your IT provider and your board.
By then the spend is easy to justify, because you know what you are buying. Our breakdown of what a cybersecurity consulting engagement delivers shows how firms scope and price it.
How long does a first cybersecurity risk assessment take?
Two or three focused days covers inventory, scenarios, and scoring for a small organisation. Chasing owners for answers takes longer than the analysis.
Do I need a framework like ISO 27001 to start?
No. A framework helps you structure and later certify the work, but a rough register built from real assets beats an empty template. Map it to a standard afterwards.
How often should the assessment be reviewed?
Review it at least annually, and immediately after any significant change: a new supplier with data access, a migration, an acquisition, or an incident.