Consultant and director reviewing a scored risk assessment
Cyber Risk Assessments

A clear, defensible picture of your cyber risk.

We run a point-in-time assessment that scores your actual risks against your appetite, then hand you a prioritised treatment plan — not a stack of theoretical findings nobody has time to work through.

Typical duration
2-4
Risks scored
20-40
Report format
1
Illustrative figures
The challenge

Most risk registers are lists. Few are actually risk-assessed.

A lot of organisations already have something called a risk register, but when you look closely it's a spreadsheet of concerns collected during a workshop years ago, scored inconsistently, and never revisited. Nobody can say with confidence which three or four risks actually matter most, or what would change if a given risk materialised tomorrow.

Boards and audit committees are increasingly asked to demonstrate that cyber risk is being managed, not just discussed. That means being able to explain the method behind a risk score, not just quote a number. A red, amber or green rating with no explanation of how it was reached tends to fall apart the moment someone asks a follow-up question.

Technical teams, meanwhile, often see risk through a narrow lens — vulnerabilities, patch levels, firewall rules — while the risks that actually cause the organisation harm are frequently about process and dependency: a single administrator holding institutional knowledge, a legacy system nobody wants to touch, a data flow to a partner that was never formally reviewed.

Without a structured assessment, investment decisions end up driven by whichever risk was discussed most recently, or by whoever shouts loudest in a budget meeting, rather than by a considered view of likelihood and impact. That's an uncomfortable way to justify spend to a finance director, and an even less comfortable position to be in after an incident.

Insurers and larger clients are also asking harder questions at renewal and during due diligence. A generic statement that 'cyber risk is managed' doesn't hold up against a request for evidence of how risks are identified, scored and treated.

  • Risk registers that were built once and never revisited
  • Scores nobody can explain the reasoning behind
  • Technical risk and business risk assessed in isolation
  • No clear owner or deadline attached to the risks that matter most
Our approach

Workshops, evidence, then a scored plan you can defend.

We start with structured workshops involving both technical and operational stakeholders, because a realistic view of risk needs input from people who understand the business as well as people who understand the systems. These sessions surface risks that pure technical scanning would never find — over-reliance on a single supplier, manual processes with no fallback, or access arrangements left over from a departed employee.

Every risk identified is scored against a likelihood and impact matrix calibrated to your organisation, using thresholds your finance director would recognise rather than an abstract five-point scale borrowed from a template. We test the scoring with you in the room, so the final figures reflect a judgement your leadership team actually agrees with.

We then set each score against your stated or implied risk appetite, which tells you not just how big a risk is but whether it sits inside or outside the level of exposure you're prepared to accept. That distinction is what turns a list of concerns into an actual decision-making tool.

Every risk above your appetite threshold gets a proposed treatment — accept, reduce, transfer or avoid — along with a realistic owner and target date. We're deliberately conservative about timelines; a treatment plan full of dates nobody will hit is worse than an honest one with fewer, achievable commitments.

The assessment closes with a written report and a readout session pitched at board or senior management level, followed by a working session with technical owners to make sure the detail behind each score is understood and actionable.

  • Workshops with both technical and business stakeholders
  • Likelihood and impact thresholds calibrated to your organisation
  • Risks scored against your stated risk appetite, not a generic scale
  • Every priority risk given an owner, a treatment and a target date
What's included

Everything in the engagement, set out up front.

A fixed-scope engagement from initial workshop through to a scored register and treatment plan.

Scoping and kick-off

A short session to agree which business areas, systems and locations fall within the assessment.

Risk identification workshops

Structured sessions with technical and operational stakeholders to surface real, organisation-specific risks.

Likelihood and impact scoring

A calibrated scoring model applied consistently across every identified risk.

Risk appetite alignment

Each score set against your organisation's tolerance for financial, operational and reputational exposure.

Treatment plan development

Proposed accept, reduce, transfer or avoid decisions with named owners and realistic dates.

Board-level readout

A plain-language presentation to directors or the audit committee, with time for challenge.

Deliverables

What you receive.

  • Scored and prioritised risk assessment
  • Documented scoring methodology and appetite thresholds
  • Treatment plan with owners and target dates
  • Written assessment report
  • Board or audit committee readout pack
  • Workshop notes and evidence log
  • Summary of quick-win versus longer-term treatments
  • Recommendation for review cadence
Who it suits

Built for organisations that need the work done properly.

Boards needing assurance

Directors who need to demonstrate cyber risk is understood and managed, with evidence beyond a verbal reassurance.

Organisations facing insurance renewal

Firms whose broker or insurer is asking pointed questions about how risk is identified and treated.

Businesses after growth or acquisition

Organisations whose risk profile has changed through headcount, systems or acquired entities and needs re-baselining.

Teams inheriting a stale register

Organisations with an existing register that has drifted out of date and needs an independent, structured refresh.

Outcomes & benefits

What changes once the work is done.

What changes once the assessment is complete.

A defensible set of scores

Risk ratings the board can explain and stand behind, rather than numbers nobody can justify under questioning.

Clear investment priorities

Spend directed at the risks that matter most, rather than whichever was discussed most recently.

Named ownership

Every priority risk has a person accountable for treating it and a date to be held to.

Evidence for insurers and clients

A structured assessment that supports renewal conversations and due diligence requests without a scramble.

A baseline for future reviews

A methodology and starting point that makes the next assessment faster and more consistent.

Better-informed board discussion

Directors spend less time debating what a risk means and more time deciding what to do about it.

A point-in-time view, done properly, still has lasting value.

It's worth being direct about what this engagement is and isn't. This is a point-in-time assessment — it gives you an accurate, well-evidenced picture of your risk as it stands today, scored consistently and set against your appetite. It is not a live, continuously updated register, and we don't pretend otherwise. Organisations that want an ongoing register with ownership, review cadence and control linkage built in should look at our risk register development work, which picks up from exactly this point.

The value of doing the assessment properly, rather than quickly, is that the scores hold up. We've sat in enough board meetings to know that a risk rating gets challenged the moment someone asks how it was reached, and a scoring model that can't answer that question undermines the whole exercise. Calibrating impact thresholds to your organisation, rather than importing a generic scale, is what makes the difference.

We deliver this work with senior consultants across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, and the same pattern holds across sectors: the risks that actually cause damage are rarely the ones getting the most attention beforehand. A structured assessment corrects that, even when the answer is uncomfortable.

Where useful, findings from this assessment feed directly into Secure Chain Horizon, our risk register and control tracking platform, so the scored output isn't left in a static document but can be tracked, updated and reported on as treatments progress.

Frequently asked questions

Questions we are asked most often.

What exactly is a cyber risk assessment?

A structured, point-in-time review of the threats and vulnerabilities that could affect your organisation, scored for likelihood and impact and set against a risk appetite the board can defend. It ends with a prioritised list of risks and a treatment plan, not a generic report full of theoretical vulnerabilities.

How is this different from a penetration test?

A penetration test probes specific systems for exploitable technical weaknesses. A risk assessment is broader — it covers people, process, technology and third parties, and translates findings into business risk that a non-technical director can weigh up. Many organisations use both, with the assessment setting priorities the testing then validates.

How long does an assessment take?

A typical assessment for a mid-sized organisation runs two to four weeks from kick-off workshop to final report, depending on how many business areas and systems are in scope. Larger or more complex estates with multiple sites or subsidiaries usually need four to six weeks to do the workshops properly.

Who needs to be involved from our side?

IT or the technical owner is essential, but the assessment only works if operational leads and at least one director are also in the room for the workshop stage. Risk decisions get made by people who understand the business impact, not just the technical detail, so their input shapes the scoring directly.

What scoring method do you use?

We use a likelihood and impact matrix calibrated to your organisation rather than a generic five-by-five template copied from a textbook. Impact bands are set against real financial, operational and reputational thresholds that your board recognises, so the resulting scores are ones people will actually stand behind in a meeting.

Do you assess third-party and supplier risk as part of this?

This engagement focuses on risk within your own organisation. Where suppliers introduce material risk we'll flag it and recommend it as a separate line of work, since third-party and supplier security reviews need a different process and are usually best run as their own exercise.

What do we get at the end?

A scored and prioritised risk register, a written report explaining the methodology and findings in plain language, and a treatment plan with named owners and target dates for each significant risk. We also run a short readout session so the board or senior team can ask questions before signing off.

Can this feed into cyber insurance renewal?

Yes. Insurers and brokers increasingly ask for evidence of a structured risk assessment process, and a scored register with a treatment plan is exactly the kind of document that supports a renewal conversation and can help avoid unwelcome surprises in the proposal form.

Want an honest view of where your cyber risk actually sits?

Talk to a senior consultant about scoping an assessment. No obligation, and no pressure to buy anything else.

Talk to a consultant