## Purpose

Use this template to identify and prioritize cybersecurity risks that could affect the company.

The objective is not to identify every possible cyber threat, but rather to focus on realistic scenarios that could cause meaningful operational, financial, legal, customer, or reputational impact.

## Risk Identification

Risk ID: ____________________

Date identified: ____________________

Risk owner: ____________________

Business area: ____________________

Affected system, data, vendor, or process: ____________________

## Risk Scenario

Describe what could happen:

---

**Examples:**

- An employee mailbox is compromised through phishing.
- Ransomware disrupts file storage and business operations.
- A vendor account is compromised.
- Critical data cannot be restored from backup.
- A public-facing server is exploited.
- Customer information is accidentally shared publicly.
- A fraudulent bank-detail change causes payment diversion.
- A former employee retains access.
- A privileged account is misused.

## Threat or Cause

What could cause the risk?

---

**Examples:**

- Phishing
- Stolen credentials
- Malware
- Insider misuse
- Human error
- Unpatched vulnerability
- Misconfiguration
- Vendor compromise
- Lost device
- Weak business process

## Existing Controls

What controls already reduce this risk?

---

**Examples:**

- MFA
- Endpoint protection
- Backups
- Email filtering
- Approval procedures
- Access restrictions
- Logging
- Employee training
- Vendor controls

## Control Gaps

What is missing, weak, untested, or uncertain?

---

## Likelihood

Select one:

- Low
- Medium
- High

Consider how realistic the scenario is given the company’s systems, exposure, users, previous incidents, and current threat environment.

Likelihood: ____________________

## Impact

Select one:

- Low
- Medium
- High

Consider potential impact on:

- Business operations
- Revenue
- Customers
- Sensitive data
- Legal or regulatory obligations
- Reputation
- Employees
- Recovery costs
- Impact: ____________________

## Overall Risk Priority

Use professional judgment rather than relying only on arithmetic.

**Select:**

- Low
- Medium
- High
- Critical
- Risk priority: ____________________

## Treatment Decision

**Select one:**

- Reduce — implement additional controls.

- Avoid — stop or change the risky activity.

- Transfer — use insurance, contractual arrangements, or another risk-sharing mechanism.

- Accept — formally accept the remaining risk.

Treatment: ____________________

## Improvement Actions

Action required:

---

Owner: ____________________

Priority: ____________________

Target date: ____________________

Required evidence: ____________________

Verification method: ____________________

## Residual Risk

After planned controls are completed, what risk will remain?

---

**Residual risk rating:**

- Low
- Medium
- High
- Critical

## Approval

Risk owner: ____________________

Leadership approval required: Yes / No

Approver: ____________________

Approval date: ____________________

## Review

Next review date: ____________________

**Review sooner if:**

- The threat changes significantly.
- The affected system changes.
- A related incident occurs.
- A major vendor changes.
- A control fails.
- The business accepts additional exposure.

## Example

**Risk scenario:**

- “A finance employee mailbox is compromised and used to redirect a supplier payment.”

**Likelihood:**

- Medium

**Impact:**

- High

**Current controls:**

- MFA, email filtering, payment approval procedure.

**Gap:**

- Bank-detail changes can currently be approved based only on email confirmation.

**Treatment:**

- Reduce.

**Action:**

- Require independent callback verification using a previously known contact for all supplier bank-detail changes.

**Owner:**

- Finance Manager

**Evidence:**

- Updated payment verification procedure and staff briefing.

**Residual risk:**

- Low to Medium

## Practical Rule

**A useful risk assessment should answer:**

- What could happen?
- What would it affect?
- How serious would it be?
- What protects us today?
- What is missing?
- What are we going to do about it?
- Who owns the action?
