
A risk register people actually use and keep current.
We build the structure, scoring method, ownership and review cadence for a working risk register — one that stays current because it's linked to your controls and reported upward, not filed away after the first workshop.
Registers built once tend to die quietly.
Almost every organisation we work with already has a risk register in some form. Almost none of them are being kept up to date. The usual pattern is a spreadsheet built during a workshop, populated with enthusiasm, and then left untouched until an auditor or an insurer asks to see it again, at which point half the risks are stale and nobody remembers who owns what.
Ownership is the most common failure point. Risks get assigned to 'IT' as a department rather than a named individual with the authority to act, which means nothing actually happens when a risk needs treating. Other registers have owners listed who left the organisation eighteen months ago.
Scoring drifts too. Without a documented method, each review ends up re-litigating what 'high' or 'medium' means, and scores creep up or down depending on who's in the room that day rather than any consistent measure. That inconsistency undermines confidence the moment a board member compares this quarter's register to the last one.
Perhaps the biggest gap is the missing link between risks and controls. A register that lists 'ransomware' as a risk scored high, with no reference to backups, endpoint protection or the incident response plan that actually mitigates it, tells a director nothing about whether the exposure is real or already substantially managed.
And reporting upward is often an afterthought — a raw spreadsheet forwarded to the audit committee with no narrative, leaving directors to interpret technical risk language themselves or, more often, to nod along without genuinely understanding what they're approving.
- Risks assigned to departments rather than named individuals
- Scoring that shifts depending on who's in the review
- No documented link between risks and the controls that treat them
- Reporting upward that's a raw export rather than a narrative
We build the structure so the register survives past the first review.
We start by agreeing the register's structure and scoring method with you — the categories of risk you'll track, the likelihood and impact scale, and how it aligns with any existing risk appetite statement. Getting this right at the outset avoids the constant re-litigation that kills most registers within a year.
Ownership is assigned deliberately, not by default. We work through each risk with you to identify who has the authority and resource to actually treat it, and we push back where ownership has been assigned purely because someone raised the risk or understands it technically rather than because they can act on it.
Every risk is then mapped to the specific controls intended to reduce it, so the register shows not just a score but the evidence behind it — what's actually mitigating the exposure today, and where a control is assumed but not verified. This is what turns the register from a list of worries into a genuine management tool.
We set a review cadence matched to your governance calendar — typically quarterly for the full register, with individual risks revisited on trigger events such as an incident, a control failure, or a material change like a new system or acquisition. We build the reminders and the reporting template into the process so reviews happen because they're straightforward, not because someone remembers.
Finally, we set up reporting that translates the register into something a board or audit committee can use directly: a short narrative alongside the data, movement since the last review, and a clear view of which treatments are on track and which are slipping.
- Structure and scoring method agreed and documented up front
- Ownership assigned to individuals with the authority to act
- Every risk mapped to the controls that mitigate it
- Review cadence and reporting template built into the process
Everything in the engagement, set out up front.
A fixed-scope engagement to design, populate and hand over a working register, with an optional platform build.
Structure and scoring workshop
Agreeing categories, scoring scale and how the register aligns with your risk appetite.
Risk population
Working through existing assessments, incidents and stakeholder input to populate the register accurately.
Ownership assignment
Naming individual owners with the authority to treat each risk, not departments or job titles.
Control mapping
Linking every risk to the specific controls intended to reduce it, and flagging where evidence is missing.
Review cadence design
Setting a realistic review schedule matched to your board or audit committee reporting calendar.
Reporting template
A board-ready summary format that presents movement, treatment status and priority risks in plain language.
What you receive.
- Documented register structure and scoring methodology
- Populated risk register with owners and scores
- Risk-to-control mapping
- Review cadence and escalation triggers
- Board or audit committee reporting template
- Register handover session with named owners
- Optional build-out in Secure Chain Horizon
- Guidance note on maintaining the register in-house
Built for organisations that need the work done properly.
Organisations with a stale register
Businesses whose existing register hasn't been meaningfully updated since it was first built.
Boards wanting clearer reporting
Audit committees receiving raw spreadsheets and asking for a structured, narrative view instead.
Teams scaling their risk function
Organisations moving from ad-hoc risk discussions to a formal, ownership-driven process as they grow.
Businesses moving off spreadsheets
Organisations ready to move register management into a proper platform with tracking built in.
What changes once the work is done.
What changes once the register is built and embedded.
A register that stays current
Ownership and cadence built in from the start, so updates happen as routine rather than as a rescue exercise.
Consistent scoring over time
A documented method that means this quarter's scores are genuinely comparable to last quarter's.
Visible control coverage
A clear view of which risks are backed by real, evidenced controls and which are assumed but unverified.
Accountability that holds
Named owners who know what they're responsible for and when it's next being reviewed.
Board reporting that lands
A reporting format directors can engage with directly, without needing it translated by IT first.
A foundation for wider governance
A register that supports ISO 27001, insurance renewal and client due diligence without separate rebuilding.
Building the register is the easy part. Keeping it alive is the point.
The technical work of building a register — agreeing categories, scoring risks, mapping controls — is genuinely not difficult, and most organisations could do it themselves given a free afternoon and a spreadsheet template. What consistently goes wrong is what happens in month four, when the person who built it has moved on to other priorities and nobody owns keeping it current. We spend as much effort on the operating rhythm — cadence, ownership, reporting — as we do on the register's initial content.
If you haven't already had a structured cyber risk assessment, that's usually the right starting point, since it gives you a scored, evidenced set of risks to populate the register with rather than a list assembled from memory in a workshop. Where an assessment has already been done — by us or by another provider — we use it directly and move straight into structure and ownership.
We deliver this work with senior consultants across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, and the same lesson applies everywhere: a register only earns its keep once it's genuinely used in a meeting, not just produced for one. That means building it in a format your board will actually open.
Where it makes sense, we set the register up directly in Secure Chain Horizon, our risk register and control tracking platform, which handles ownership, review reminders, control linkage and executive reporting in one place. We're equally happy to build the same structure into a tool you already run, if that's the better fit for your organisation.
Questions we are asked most often.
What is a cyber risk register, exactly?
A structured, living document that lists your organisation's cyber risks, each scored for likelihood and impact, assigned an owner, linked to the controls that mitigate it, and reviewed on a set cadence. Unlike a one-off assessment report, it's designed to be updated as risks, controls and the business change.
We already have a risk assessment — why do we need a register too?
An assessment gives you a scored snapshot at a point in time; a register is the ongoing mechanism that keeps that snapshot current. Without a register, an assessment's findings age quickly as new systems, suppliers and staff changes alter the picture, and nobody notices until the next review, which is often too late.
How often should the register be reviewed?
Most organisations settle on a quarterly review of the full register, with individual risks revisited sooner if a related incident, control failure or significant change occurs. We help set a cadence that matches your board and audit committee reporting cycle, so the register stays useful rather than becoming another item people rush before a meeting.
Who should own individual risks on the register?
Ownership should sit with whoever has the authority and budget to act on a risk, not necessarily whoever raised it or knows the most about it technically. We work through this deliberately during setup, because vague or purely technical ownership is one of the most common reasons registers stall.
How does the register link to our controls?
Each risk is mapped to the specific controls intended to reduce it, so you can see at a glance whether a risk is genuinely being treated or whether the mitigation exists only on paper. This linkage is also what lets you report meaningfully upward — a risk score without its supporting controls tells a director very little.
Can you build the register in a platform rather than a spreadsheet?
Yes. Many clients start in a spreadsheet and outgrow it quickly once ownership, review dates and control links are added. We can set the register up in Secure Chain Horizon, our own risk register and control tracking platform, or work within a tool you already use if that's a better fit.
Does this cover supplier and third-party risk?
The register can include supplier-related risks at a summary level, but detailed third-party risk assessment and supplier security review is a distinct discipline with its own process, which we treat as separate work. We're happy to align the two so supplier risks feed into the same reporting structure.
What does the finished register look like in practice?
A working document — either in Horizon or a structured spreadsheet — listing each risk, its score, owner, linked controls, treatment status and next review date, alongside a reporting template your board or audit committee can use without needing it translated by IT first.
Cyber risk assessments
A structured, scored assessment to populate a new or existing register with real, evidenced risks.
ISO 27001 gap analysis
See how your risk register and treatment approach measure against ISMS requirements.
Vulnerability management as a service
Ongoing technical evidence that keeps the controls linked to your register genuinely current.
Want a register that's still being used a year from now?
Speak to a senior consultant about setting up the structure, ownership and review cadence properly from the start. No obligation.
Speak to a consultant