Purpose: Use this structure to record decision-relevant cyber risks consistently. The fields can be placed in a spreadsheet, governance platform, or simple document.
Recommended fields
Risk IDStable identifier used across reports and actions.
Risk statementBecause of [cause/event], [service or asset] may experience [consequence].
Business ownerPerson accountable for the affected objective or process.
Inherent assessmentExposure before considering the effect of specific safeguards.
Existing safeguardsControls, contracts, procedures, recovery measures, and supporting evidence.
Residual assessmentRemaining exposure and confidence after safeguards are considered.
Treatment decisionReduce, accept, transfer, avoid, or monitor.
Action and due dateSpecific work, owner, target date, and required resources.
Review triggerScheduled date plus events that require earlier reassessment.
Worked examples
| Example | Context / Rating | Condition / Safeguard | Decision / Result | Owner / Follow-up |
|---|
How to use this page
- Write one scenario per record in plain language.
- Name the business consequence before selecting a rating.
- Attach evidence for safeguards rather than listing controls without support.
- Separate the risk owner from action and control owners where appropriate.
- Record the treatment decision and who approved it.
- Set a review date and event-based triggers.
Cautions
- Do not import every scanner finding as a separate enterprise risk.
- Do not close the record merely because one action finished; reassess residual exposure.
- Avoid permanent risk acceptances with no expiry or monitoring.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.
Frequently asked questions
Can a small organization use this tool?
Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.
Does this replace professional advice?
No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.
How often should it be updated?
Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.