Cybersecurity Risk Assessment Template
Purpose
Use this template to identify and prioritize cybersecurity risks that could affect the company.
The objective is not to identify every possible cyber threat, but rather to focus on realistic scenarios that could cause meaningful operational, financial, legal, customer, or reputational impact.
Risk Identification
Risk ID: ____________________
Date identified: ____________________
Risk owner: ____________________
Business area: ____________________
Affected system, data, vendor, or process: ____________________
Risk Scenario
Describe what could happen:
Examples:
- An employee mailbox is compromised through phishing.
- Ransomware disrupts file storage and business operations.
- A vendor account is compromised.
- Critical data cannot be restored from backup.
- A public-facing server is exploited.
- Customer information is accidentally shared publicly.
- A fraudulent bank-detail change causes payment diversion.
- A former employee retains access.
- A privileged account is misused.
Threat or Cause
What could cause the risk?
Examples:
- Phishing
- Stolen credentials
- Malware
- Insider misuse
- Human error
- Unpatched vulnerability
- Misconfiguration
- Vendor compromise
- Lost device
- Weak business process
Existing Controls
What controls already reduce this risk?
Examples:
- MFA
- Endpoint protection
- Backups
- Email filtering
- Approval procedures
- Access restrictions
- Logging
- Employee training
- Vendor controls
Control Gaps
What is missing, weak, untested, or uncertain?
Likelihood
Select one:
- Low
- Medium
- High
Consider how realistic the scenario is given the company’s systems, exposure, users, previous incidents, and current threat environment.
Likelihood: ____________________
Impact
Select one:
- Low
- Medium
- High
Consider potential impact on:
- Business operations
- Revenue
- Customers
- Sensitive data
- Legal or regulatory obligations
- Reputation
- Employees
- Recovery costs
- Impact: ____________________
Overall Risk Priority
Use professional judgment rather than relying only on arithmetic.
Select:
- Low
- Medium
- High
- Critical
- Risk priority: ____________________
Treatment Decision
Select one:
-
Reduce — implement additional controls.
-
Avoid — stop or change the risky activity.
-
Transfer — use insurance, contractual arrangements, or another risk-sharing mechanism.
-
Accept — formally accept the remaining risk.
Treatment: ____________________
Improvement Actions
Action required:
Owner: ____________________
Priority: ____________________
Target date: ____________________
Required evidence: ____________________
Verification method: ____________________
Residual Risk
After planned controls are completed, what risk will remain?
Residual risk rating:
- Low
- Medium
- High
- Critical
Approval
Risk owner: ____________________
Leadership approval required: Yes / No
Approver: ____________________
Approval date: ____________________
Review
Next review date: ____________________
Review sooner if:
- The threat changes significantly.
- The affected system changes.
- A related incident occurs.
- A major vendor changes.
- A control fails.
- The business accepts additional exposure.
Example
Risk scenario:
- “A finance employee mailbox is compromised and used to redirect a supplier payment.”
Likelihood:
- Medium
Impact:
- High
Current controls:
- MFA, email filtering, payment approval procedure.
Gap:
- Bank-detail changes can currently be approved based only on email confirmation.
Treatment:
- Reduce.
Action:
- Require independent callback verification using a previously known contact for all supplier bank-detail changes.
Owner:
- Finance Manager
Evidence:
- Updated payment verification procedure and staff briefing.
Residual risk:
- Low to Medium
Practical Rule
A useful risk assessment should answer:
- What could happen?
- What would it affect?
- How serious would it be?
- What protects us today?
- What is missing?
- What are we going to do about it?
- Who owns the action?