Governance, Risk & Compliance

Cyber Risk Management & Assessment

Risk assessment that produces decisions, not a spreadsheet nobody opens.

The situation

Most risk registers are inventories of anxiety.

We run risk assessments to a recognised method — ISO/IEC 27005, EBIOS Risk Manager, CRAMM or the European Commission's ITSRM² where the client is an EU body — and land them where they belong: in an investment decision, a control roadmap and a risk acceptance signed by someone with authority to accept it.

What the client receives

Schedule of deliverables

  1. 01Asset and business-process criticality analysis
  2. 02Threat and scenario modelling grounded in current threat intelligence
  3. 03Risk register with inherent, current and target risk
  4. 04Treatment plan with cost and owner per risk
  5. 05Formal risk acceptance and escalation procedure
  6. 06Board-level risk reporting pack and KRI set

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • ISO/IEC 27005
  • EBIOS RM
  • ITSRM²
  • ISO 31000
  • COSO ERM
  • COBIT

Discuss this engagement

Tell us about the scope of the assessment and the decision it must support and we will set out the scope, the method and the reporting format.

Contact us