Governance, Risk & Compliance
Cyber Risk Management & Assessment
Risk assessment that produces decisions, not a spreadsheet nobody opens.
The situation
What the client receives
Schedule of deliverables
- Asset and business-process criticality analysis
- Threat and scenario modelling grounded in current threat intelligence
- Risk register with inherent, current and target risk
- Treatment plan with cost and owner per risk
- Formal risk acceptance and escalation procedure
- Board-level risk reporting pack and KRI set
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- ISO/IEC 27005
- EBIOS RM
- ITSRM²
- ISO 31000
- COSO ERM
- COBIT
Related services
Discuss this engagement
Tell us about the scope of the assessment and the decision it must support and we will set out the scope, the method and the reporting format.