Cybersecurity Risk Assessment Template

Purpose

Use this template to identify and prioritize cybersecurity risks that could affect the company.

The objective is not to identify every possible cyber threat, but rather to focus on realistic scenarios that could cause meaningful operational, financial, legal, customer, or reputational impact.

Risk Identification

Risk ID: ____________________

Date identified: ____________________

Risk owner: ____________________

Business area: ____________________

Affected system, data, vendor, or process: ____________________

Risk Scenario

Describe what could happen:


Examples:

  • An employee mailbox is compromised through phishing.
  • Ransomware disrupts file storage and business operations.
  • A vendor account is compromised.
  • Critical data cannot be restored from backup.
  • A public-facing server is exploited.
  • Customer information is accidentally shared publicly.
  • A fraudulent bank-detail change causes payment diversion.
  • A former employee retains access.
  • A privileged account is misused.

Threat or Cause

What could cause the risk?


Examples:

  • Phishing
  • Stolen credentials
  • Malware
  • Insider misuse
  • Human error
  • Unpatched vulnerability
  • Misconfiguration
  • Vendor compromise
  • Lost device
  • Weak business process

Existing Controls

What controls already reduce this risk?


Examples:

  • MFA
  • Endpoint protection
  • Backups
  • Email filtering
  • Approval procedures
  • Access restrictions
  • Logging
  • Employee training
  • Vendor controls

Control Gaps

What is missing, weak, untested, or uncertain?


Likelihood

Select one:

  • Low
  • Medium
  • High

Consider how realistic the scenario is given the company’s systems, exposure, users, previous incidents, and current threat environment.

Likelihood: ____________________

Impact

Select one:

  • Low
  • Medium
  • High

Consider potential impact on:

  • Business operations
  • Revenue
  • Customers
  • Sensitive data
  • Legal or regulatory obligations
  • Reputation
  • Employees
  • Recovery costs
  • Impact: ____________________

Overall Risk Priority

Use professional judgment rather than relying only on arithmetic.

Select:

  • Low
  • Medium
  • High
  • Critical
  • Risk priority: ____________________

Treatment Decision

Select one:

  • Reduce — implement additional controls.

  • Avoid — stop or change the risky activity.

  • Transfer — use insurance, contractual arrangements, or another risk-sharing mechanism.

  • Accept — formally accept the remaining risk.

Treatment: ____________________

Improvement Actions

Action required:


Owner: ____________________

Priority: ____________________

Target date: ____________________

Required evidence: ____________________

Verification method: ____________________

Residual Risk

After planned controls are completed, what risk will remain?


Residual risk rating:

  • Low
  • Medium
  • High
  • Critical

Approval

Risk owner: ____________________

Leadership approval required: Yes / No

Approver: ____________________

Approval date: ____________________

Review

Next review date: ____________________

Review sooner if:

  • The threat changes significantly.
  • The affected system changes.
  • A related incident occurs.
  • A major vendor changes.
  • A control fails.
  • The business accepts additional exposure.

Example

Risk scenario:

  • “A finance employee mailbox is compromised and used to redirect a supplier payment.”

Likelihood:

  • Medium

Impact:

  • High

Current controls:

  • MFA, email filtering, payment approval procedure.

Gap:

  • Bank-detail changes can currently be approved based only on email confirmation.

Treatment:

  • Reduce.

Action:

  • Require independent callback verification using a previously known contact for all supplier bank-detail changes.

Owner:

  • Finance Manager

Evidence:

  • Updated payment verification procedure and staff briefing.

Residual risk:

  • Low to Medium

Practical Rule

A useful risk assessment should answer:

  • What could happen?
  • What would it affect?
  • How serious would it be?
  • What protects us today?
  • What is missing?
  • What are we going to do about it?
  • Who owns the action?