Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Information Security Risk Management Pack — Guide

Information Security Risk Management Pack

Most risk registers are a list of vague worries such as “cyber attack”, owned by IT and scored once in a workshop. Nothing is decided, so nothing changes before the next audit. This pack helps you run a process that produces decisions: who owns each risk, whether it is acceptable, and what happens next.

Is this for you?

This pack is for you if:

  • you have a risk register, but nobody outside security reads it;
  • you cannot say which of your risks the business has agreed to carry;
  • an auditor asked how you treat risk, and you had only a spreadsheet.

How the method works

Every risk is scored before and after existing controls:

StepWhat it means
Impact, 1 to 4Minor to Severe, on the worst consequence: money, service, data, legal or reputation.
Likelihood, 1 to 4Unlikely to Almost certain, over the next 12 months.
Score and bandImpact × likelihood: Low 1–3, Medium 4–6, High 8–9, Critical 12–16. The band after controls sets who may accept.
AppetiteThe highest band you accept without escalating.
ToleranceThe highest band you will carry while a plan brings it back. Never Critical.

A risk above appetite needs a decision; only the board may accept one above tolerance. The exceptions pack uses the same scale: an exception is a risk accepted for a fixed time.

Where small programmes go wrong

  • Risks owned by IT. The owner is the executive whose service would be hurt (RM-02).
  • Vague risks. Write each as a scenario: threat, weakness, what it affects, consequence (RM-01).
  • No appetite. Nobody can say whether a High risk is acceptable (RM-05).
  • Scores nobody can defend. Use the defined scales and record why (RM-03).
  • Acceptance by default. Decide each risk outside appetite within 30 days; record acceptances at the right level (RM-06, RM-08).
  • No review. Owners review quarterly; a major incident or change forces reassessment within 10 working days (RM-09, RM-10).

Start with these three

  1. Risk Assessment Methodology & Scoring Model — the scales and the twelve rules every other document follows.
  2. Cyber Risk Appetite Statement Template — appetite and tolerance for each risk category.
  3. Information Security Risk Register — the single record of every assessed risk.

Your first month

WhenWhat to doYou’re done when
Week 1Set the Methodology’s money thresholds and name who accepts each band.Management has approved it.
Week 2Set an appetite level for each risk category.The board or management body has approved the statement.
Week 3Score your top risks with their owners, using the scenario library.Each owner agrees their scores.
Week 4Enter them in the register; decide each risk outside appetite.Each has a decision: reduce, avoid, transfer or accept.

Four numbers to report

Report these to executive management quarterly.

NumberTarget
Risks outside appetite, and of those, past toleranceZero past tolerance; each outside appetite with a treatment decision
Treatment actions overdueNone older than 30 days
Acceptances past their review dateZero
Risks not reviewed by their owner this quarterZero

The first is the same figure a board report opens with, so register and board paper agree.

Everything in the pack

DocumentWhat it doesFormat
Risk Assessment Methodology & Scoring ModelThe rules management approvesWord
Risk Identification & Assessment Operating ProcedureHow risks are found, assessed and reviewedWord
Cyber Risk Appetite Statement TemplateHow much risk you accept, by categoryWord
Information Security Risk RegisterEvery risk, its owner, score and positionExcel
Risk Assessment WorkbookOne assessment, from scenario to scoreExcel
Risk Treatment PlanWho does what, by when, at what costExcel
Risk Acceptance Form & Approval RecordWho accepted which risk, why, and until whenWord
Cyber Risk Scenario LibraryReady-written scenarios to start fromExcel
Risk Reporting DashboardThe four numbers, quarter by quarterExcel

Adapting it

  • Small organisation: start with a dozen top risks. One person may run every assessment, but executives still own the risks.
  • Regulated entity (NIS2, DORA): NIS2 Article 21(1) expects proportionate measures, and 21(2)(a) a risk analysis policy. DORA Article 6(1) requires a documented framework; Article 8, yearly scenario reviews and an assessment on each major change. Delegated Regulation (EU) 2024/1774, Article 3, adds an approved tolerance, a methodology, and a list of accepted residual risks reviewed at least yearly. For personal data, GDPR Article 32 asks for security appropriate to the risk to the people concerned, so score that harm too.
  • IT run by an outside provider: the provider can assess risks and deliver actions, but ownership and acceptance stay with your executives. Its own failure belongs in your register.

Where it maps

  • ISO/IEC 27001:2022 — Clauses 6.1.1, 6.1.2 and 6.1.3.
  • NIST CSF 2.0 — GV.RM-01, GV.RM-02 and ID.RA-05.
  • NIS2 — Article 21(1) and 21(2)(a).
  • DORA — Articles 6(1) and 8; Delegated Regulation (EU) 2024/1774, Article 3.
  • GDPR — Article 32.