Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Information Security Risk Register

Holds the assessed risk population with scoring, ownership, treatment status and appetite breach flagging.

Available soon

Format
Excel
Size
110 KB
Length
11 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Register
  • Appetite
  • Summary
  • Heat Map
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30, the example quarter end; replace it with today's date, or type =TODAY() to keep it current. The review flag, trigger flag and acceptance check use this date.
2On the Appetite sheet, list your risk categories and choose each one's appetite level from your approved Cyber Risk Appetite Statement Template (Averse: appetite up to Low, tolerance up to Medium; Cautious: appetite up to Medium, tolerance up to High; Open: appetite up to High, tolerance up to High). The register reads the appetite and tolerance from there.
3Add one row per risk (RM-11). Give it a Risk ID (R-01, R-02 …) that never changes. Write the Risk scenario as a threat, the weakness it uses, the service or asset affected and the consequence (RM-01); use the Cyber Risk Scenario Library as a starting point. Choose the Category and name one Risk owner: the executive accountable for the service it would hurt, not the security team (RM-02).
4Score it as the Risk Assessment Methodology & Scoring Model sets out (RM-03): Inherent impact and likelihood (1–4) as if the existing controls were not there, then Existing controls in plain words, then Residual impact and likelihood with those controls working as they do today. Impact is judged on the worst consequence; likelihood over the next 12 months. Scores and bands calculate (Low 1–3, Medium 4–6, High 8–9, Critical 12–16).
5Read the Position against appetite (RM-05). A risk outside appetite needs a treatment decision within 30 calendar days of first being assessed outside appetite; later reviews do not restart the window (RM-06): choose Reduce, Avoid, Transfer or Accept. For Reduce, Avoid or Transfer, enter the action IDs from the Risk Treatment Plan in Linked actions (RM-07).
6For Accept, record the acceptance on the Risk Acceptance Form & Approval Record, enter its reference and review date here, and check that the right person signed: Who may accept shows the band's approvers; outside appetite, executive management signs as well; outside tolerance, the band's approvers can only recommend and only the board or its equivalent may accept (RM-08).
7Every quarter, each owner reviews each of their risks and the date goes in Last owner review (RM-09). Before you update the scores for the new quarter, copy each Residual score into Last quarter's residual score, so Movement shows Better, Same or Worse.
8When a trigger happens (a major incident, a major change, a new threat, an audit or test finding, or a change in law or contract), record it and its date on every risk it touches. Reassess those risks within 10 working days (RM-10) and enter the Reassessed on date; Trigger flag shows the deadline and when it has passed.
9Clear every Record check that does not say OK. Once a year, reassess the whole register (RM-09). Take the Summary figures into the quarterly report to [[e.g. Executive Committee]] (RM-12).
10Delete the EXAMPLE rows on the Register and Appetite sheets before the register is approved. Do not type over the white calculated columns.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: 10 to 20 risks are enough to start; one person may assess them all, but each still needs an owner outside the security role (RM-02). A quarterly review can be one meeting with the owners.

Tailoring — regulated entity (NIS2, DORA): keep a copy of the register at each quarter end (with the As-at date fixed) as the record of risk assessment. Under DORA, reassess on each major change and review the risk scenarios at least once a year (Art 8(2), 8(3)); the scoring and acceptance rules must match your ICT risk management policy (Delegated Regulation (EU) 2024/1774 Art 3). Add a column for the critical or important function a risk affects. Where personal data is involved, the residual score is part of showing security appropriate to the risk (GDPR Art 32(1)).

Tailoring — IT run by a service provider: risks in the provider's service belong in this register, owned by your executive for the service it supports. The provider can supply evidence for the existing controls; transferring part of the impact by contract does not transfer the ownership.

The scales, bands, appetite levels, treatments, acceptance authority and triggers are on the Lists sheet. If your Risk Assessment Methodology & Scoring Model sets different ones, change them there and nowhere else. The reassessment deadline (10 working days) is set on the Summary sheet.

EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30 (Q3 2026). Its 12 top risks are those in the quarterly board report: 2 outside appetite (R-01, R-02), both within tolerance; R-04 moved from 9 to 4 this quarter, after TA-04 separated the last warehouse site from the office network, and is back within appetite.

Register

One row per assessed risk (RM-11). Yellow columns are inputs; white columns calculate. Every colour sits beside a word.

ExampleRisk IDCategoryAppetite levelRisk scenarioRisk ownerInherent impact (1–4)Inherent likelihood (1–4)Inherent scoreInherent bandExisting controlsResidual impact (1–4)Residual likelihood (1–4)Residual scoreResidual bandLast quarter's residual scoreMovementPosition against appetiteTreatmentLinked actionsWho may acceptAcceptance refAcceptance review dateLast owner reviewReviewed this quarterTrigger since last assessmentTrigger dateReassessed onTrigger flagRecord checkNotes
EXAMPLER-01Service availabilityCautiousRansomware takes online ordering offline for more than 2 daysChief Operating Officer4312CriticalNightly backups of the ordering platform; endpoint detection on servers; recovery of the whole platform not yet proven within 2 days428High8SameOutside appetite, within toleranceReduceTA-01Accountable executive and Head of Information Security, and executive management as well10 Sep 2026YesOKTreatment action TA-01 (€180,000) is the decision put to the board; see the Risk Treatment Plan
EXAMPLER-02Financial fraudCautiousPayment fraud through a compromised supplier email accountChief Financial Officer3412CriticalTwo-person approval of payments; accounts payable staff trained to spot changed bank details339High9SameOutside appetite, within toleranceReduceTA-02Accountable executive and Head of Information Security, and executive management as well8 Sep 2026YesOK
EXAMPLER-03Customer and personal dataCautiousCustomer data exposed through the ordering serviceChief Operating Officer428HighWeb application firewall; yearly penetration test of the ordering service; customer data encrypted at rest414Medium4SameWithin appetiteReduceRisk owner and Head of Information Security22 Jul 2026YesOK
EXAMPLER-04Service availabilityCautiousRansomware spreads from warehouse office PCs to warehouse systemsHead of Logistics339HighWarehouse networks separated from the office network at all three sites (last site 2026-09-09, tested 2026-09-11); endpoint protection on office PCs224Medium9BetterWithin appetiteReduceTA-04Risk owner and Head of Information Security30 Sep 2026YesA major incident, or a near miss that shows a risk was underrated12 Aug 202620 Aug 2026ReassessedOKReassessed on 2026-08-20 after the 12 Aug 2026 ransomware incident and kept at 9: two sites were still on the office network. The last site was separated on 2026-09-09 and tested on 2026-09-11 (TA-04); the quarter-end review scored it 4
EXAMPLER-05Service availabilityCautiousCritical weaknesses on internet-facing systems exploited before they are fixedHead of IT339HighMonthly vulnerability scanning; patching deadlines by severity; internet-facing systems behind a web application firewall326Medium6SameWithin appetiteReduceTA-03Risk owner and Head of Information Security15 Sep 2026YesOK
EXAMPLER-06Third-party dependencyCautiousManaged IT provider fails or is compromisedHead of IT326MediumContract with security and service-level clauses; provider's yearly assurance report; insurance covering provider failure313Low3SameWithin appetiteTransferRisk owner14 Jul 2026YesOKTransferred in part by contract and insurance; the Head of IT still owns the risk
EXAMPLER-07People and insiderCautiousAdministrator misuses privileged accessHead of IT326MediumSeparate administrator accounts with multi-factor authentication; administrator activity logged313Low3SameWithin appetiteReduceRisk owner14 Jul 2026YesOK
EXAMPLER-08Regulatory complianceAverseSignificant incident not reported to the authority on time (NIS2)Head of Information Security224MediumIncident response procedure with the notification steps and deadlines; on-call rota212Low2SameWithin appetiteReduceRisk owner5 Aug 2026YesOK
EXAMPLER-09People and insiderCautiousStaff account taken over through phishingHR Director248HighMulti-factor authentication on email; phishing report button; awareness training every quarter236Medium6SameWithin appetiteReduceRisk owner and Head of Information Security27 Aug 2026YesOK
EXAMPLER-10Service availabilityCautiousBackups cannot restore a critical systemHead of IT428HighDaily backups with an offline copy; one critical system restored in a test each quarter414Medium4SameWithin appetiteReduceRisk owner and Head of Information Security14 Jul 2026YesOK
EXAMPLER-11Customer and personal dataCautiousCloud storage misconfigured and customer files exposedHead of IT326MediumCloud configuration baseline; monthly configuration scan313Low3SameWithin appetiteReduceRisk owner14 Jul 2026YesOK
EXAMPLER-12Customer and personal dataCautiousCustomer data on an unencrypted laptop at the smaller warehouse site is lost or stolenHead of Logistics224MediumAcceptance conditions: Laptops stay on site, are locked away overnight and are not used for customer data exports.224Medium4SameWithin appetiteAcceptRisk owner and Head of Information SecurityRA-0115 Jun 20271 Sep 2026YesOKAccepted on 2026-06-15 by the Head of Logistics (risk owner) and Head of Information Security until the March 2027 laptop refresh (see RA-01)

Appetite

Your risk categories and each one's appetite level, from the approved Cyber Risk Appetite Statement Template. The register reads its Appetite level from here.

ExampleCategory IDCategoryAppetite levelAppetite: highest band acceptedTolerance: highest band tolerated while treatedApproved in the risk appetite statement (date)
EXAMPLERC-01Service availabilityCautiousMediumHigh[[YYYY-MM-DD]]
EXAMPLERC-02Customer and personal dataCautiousMediumHigh[[YYYY-MM-DD]]
EXAMPLERC-03Financial fraudCautiousMediumHigh[[YYYY-MM-DD]]
EXAMPLERC-04Regulatory complianceAverseLowMedium[[YYYY-MM-DD]]
EXAMPLERC-05Third-party dependencyCautiousMediumHigh[[YYYY-MM-DD]]
EXAMPLERC-06People and insiderCautiousMediumHigh[[YYYY-MM-DD]]

Appetite levels

LevelAppetiteToleranceWhat it means
AverseLowMediumWe avoid this risk and act on anything above Low.
CautiousMediumHighWe accept some risk for a clear business benefit, with controls.
OpenHighHighWe accept higher risk to pursue opportunity; Critical is never within tolerance.
Appetite is the highest residual band accepted without escalation; tolerance is the highest band tolerated while a plan brings the risk back. Critical is never within tolerance.

Summary

Register summary

Every figure is calculated from the Register as at the date shown. Use them for the quarterly report to executive management (RM-12); RMM-02 comes from the Risk Treatment Plan.

As-at date30 Sep 2026EXAMPLE date (the example quarter end). Replace it with today's date, or type =TODAY().
Reassessment deadline after a trigger (working days, RM-10)10Your procedure's deadline; the rule's default is shown.

Risks by band

Band (score)Now (residual)Before controls (inherent)Last quarter (residual)
Low (1–3)404
Medium (4–6)655
High (8–9)253
Critical (12–16)020
All risks121212

Position against appetite

PositionRisksWith a treatment decisionWorse than last quarter
Within appetite10——
Outside appetite, within tolerance220
Outside tolerance000
Overall position (the board measure)Outside appetite, within toleranceOutside tolerance if any risk is past its tolerance; otherwise outside appetite, within tolerance if any risk is above appetite; otherwise within appetite.

Headline measures

MeasureResultTargetStatusWhat it means
RMM-01 Risks outside appetite2Each with a treatment decisionOn targetTop risks whose residual band is above their category's appetite; and of those, above its tolerance. RMM-01 target: zero past tolerance; outside appetite each with a treatment decision.
RMM-01 Of those, past tolerance00On targetA risk past tolerance goes to the board; only the board or its equivalent may accept it (RM-08).
RMM-03 Acceptances past review00On targetAccepted risks whose acceptance review date has passed. Review each on the Risk Acceptance Form & Approval Record.
RMM-04 Risks not reviewed this quarter00On targetRegister entries with no owner review in the last quarter (RM-09). Counted as no owner review in the 3 months up to the as-at date.
RMM-02 Treatment actions overdue—Zero older than 30 days—From the Risk Treatment Plan.

Position by category

CategoryAppetite levelRisksWithin appetiteOutside appetite, within toleranceOutside toleranceCategory position
Service availabilityCautious4310Outside appetite, within tolerance
Customer and personal dataCautious3300Within appetite
Financial fraudCautious1010Outside appetite, within tolerance
Regulatory complianceAverse1100Within appetite
Third-party dependencyCautious1100Within appetite
People and insiderCautious2200Within appetite

Movement, treatment and triggers

ItemRisks
Better than last quarter1
Same as last quarter11
Worse than last quarter0
New this quarter0
Treatment: Reduce10
Treatment: Avoid0
Treatment: Transfer1
Treatment: Accept1
No treatment recorded0
Awaiting reassessment after a trigger (RM-10)0
of which past the deadline0
Rows with a record check to resolve0

Quarterly review record

ItemEntry
Reviewed by (name, role) and date[[Name, role, YYYY-MM-DD]]
Risks whose score changed, and why[[e.g. R-04 from 9 to 4: warehouse network separated from the office network]]
New risks, and closed risks[[e.g. none]]
Decisions needed from executive management[[e.g. R-01: funding for TA-01 goes to the board]]

Heat Map

Heat map

Where the risks sit on the 4 × 4 scale. Each cell shows its band in words and the number of risks in it. The colour only repeats the band.

Now — residual (after existing controls)Before controls — inherent
Impact ↓ Likelihood →1 Unlikely2 Possible3 Likely4 Almost certainImpact ↓ Likelihood →1 Unlikely2 Possible3 Likely4 Almost certain
4 SevereMedium (4) — 2High (8) — 1Critical (12) — 0Critical (16) — 04 SevereMedium (4) — 0High (8) — 2Critical (12) — 1Critical (16) — 0
3 MajorLow (3) — 3Medium (6) — 1High (9) — 1Critical (12) — 03 MajorLow (3) — 0Medium (6) — 3High (9) — 2Critical (12) — 1
2 ModerateLow (2) — 1Medium (4) — 2Medium (6) — 1High (8) — 02 ModerateLow (2) — 0Medium (4) — 2Medium (6) — 0High (8) — 1
1 MinorLow (1) — 0Low (2) — 0Low (3) — 0Medium (4) — 01 MinorLow (1) — 0Low (2) — 0Low (3) — 0Medium (4) — 0

Each cell: band (score) — number of risks. Bands: Low 1–3; Medium 4–6; High 8–9; Critical 12–16. The score is impact × likelihood (RM-03).

Where a risk sits against appetite depends on its category as well as its band: read the Position against appetite column, not the colour.

Lists

LevelBandBandMinScoreAcceptApproverAcceptReviewMonthsAppetiteLevelLevelAppetiteLevelToleranceTreatmentTriggerPosition
1Low1Risk owner12AverseLowMediumReduceA major incident, or a near miss that shows a risk was underratedWithin appetite
2Medium4Risk owner and Head of Information Security12CautiousMediumHighAvoidA major change to systems, processes, suppliers or the organisationOutside appetite, within tolerance
3High8Accountable executive and Head of Information Security6OpenHighHighTransferA new or changed threat relevant to our services (threat intelligence)Outside tolerance
4Critical12The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management3AcceptAn audit, test or assessment finding

A change in law, regulation or a key contract

Definitions

Definitions

TermMeaning in this workbook
RiskThe chance that a threat uses a weakness to harm a service or asset we depend on, with a consequence we can describe (RM-01).
Risk IDYour unique reference for the risk, such as R-04. It stays the same while the risk is on the register.
CategoryThe kind of harm, which sets the appetite that applies. Your categories and their appetite levels are on the Appetite sheet.
Risk ownerEvery risk has one named owner: the executive accountable for the service or asset it would hurt, not the security team. [[the accountable executive for the service or asset]]
Impact1 Minor: affects one system of Standard criticality or non-sensitive data; no customer or regulatory effect. 2 Moderate: affects a High criticality system or internal confidential data; limited, recoverable disruption. 3 Major: affects a Critical system, personal or customer data, or a regulated service; notifiable if it went wrong. 4 Severe: could stop a core business service, expose sensitive data at scale, or breach a legal obligation. Judged on the worst consequence; the Risk Assessment Methodology & Scoring Model gives the money and service thresholds.
Likelihood1 Unlikely: less than [[20]]% in the next 12 months. Not seen at organisations like ours in recent years, or only with rare skill or access. 2 Possible: [[20]]% to [[50]]% in the next 12 months. Happens regularly to organisations like ours; our controls make it harder but not rare. 3 Likely: [[50]]% to [[90]]% in the next 12 months. Happening now to organisations like ours, or has happened to us, and the gap is still open. 4 Almost certain: more than [[90]]% in the next 12 months, or already happening. Being attempted against us now, with little in the way.
Inherent scoreImpact × likelihood as if the existing controls were not there, 1 to 16.
Residual scoreImpact × likelihood with the existing controls working as they do today, 1 to 16. The residual band decides who must know and who may accept (RM-04).
BandLow: score 1–3; Medium: score 4–6; High: score 8–9; Critical: score 12–16.
Who must knowBy residual band (RM-04): Low: risk owner; recorded in the register. Medium: risk owner and Head of Information Security. High: accountable executive and Head of Information Security; named to executive management in the quarterly report. Critical: executive management at once; the board chair out of cycle, within [[5]] working days (Critical is always outside tolerance).
Appetite levelAverse: we avoid this risk and act on anything above Low. Cautious: we accept some risk for a clear business benefit, with controls. Open: we accept higher risk to pursue opportunity; Critical is never within tolerance.
Position against appetiteWithin appetite: the residual band is at or below the category's appetite. Outside appetite, within tolerance: above appetite but at or below tolerance, with a plan to bring it back. Outside tolerance: above the tolerance limit, where the board must act (RM-05).
MovementBetter, Same or Worse: this quarter's residual score against last quarter's. New: no score last quarter.
TreatmentReduce: change the likelihood or the impact with controls. Avoid: stop the activity that creates the risk. Transfer: share the impact with a third party, for example by insurance or contract; the risk owner still owns the risk. Accept: keep the residual risk knowingly, recorded and approved at the right level (Risk Acceptance Form).
Linked actionsThe IDs of the treatment actions in the Risk Treatment Plan, such as TA-01 (RM-07).
Who may acceptLow: risk owner; Medium: risk owner and Head of Information Security; High: accountable executive and Head of Information Security; Critical: the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management. Outside appetite, the band's approvers sign and executive management signs as well. Outside tolerance, the band's approvers can only recommend: only the board or its equivalent may accept (RM-08).
Acceptance ref, review dateThe reference on the Risk Acceptance Form & Approval Record and the date the acceptance must be reviewed by: Low 12 months, Medium 12 months, High 6 months, Critical 3 months after approval.
Reviewed this quarterYes when the owner's last review is within the 3 months up to the as-at date (RM-09, RMM-04).
TriggerAn event that forces reassessment before the scheduled one (RM-10): a major incident, or a near miss that shows a risk was underrated; a major change to systems, processes, suppliers or the organisation; a new or changed threat relevant to our services (threat intelligence); an audit, test or assessment finding; a change in law, regulation or a key contract.
Trigger flagReassess by a date: reassess by then, 10 working days (Monday to Friday) after the trigger. Reassessment overdue: that date has passed. Reassessed: done on or after the trigger date.
Record checkA calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding.
As-at dateThe date the review flag, trigger flag and acceptance check are measured against. Set on the Summary sheet.
EXAMPLE rowA worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. Delete before approval.
RM-nn, RMM-nnRule and measure numbers in the Risk Assessment Methodology & Scoring Model.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 6.1.2 — Information security risk assessmentThe register as a whole: risks identified with owners, analysed and evaluated against criteria on the same scale every time
ISO/IEC 27001:2022Clause 8.2 — Information security risk assessmentLast owner review, trigger and reassessment columns: assessments repeated each quarter and on change, and kept as records
NIST CSF 2.0ID.RA-05 — “Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization”Inherent and residual impact, likelihood, score and band; position against appetite used to prioritise treatment
NIST CSF 2.0GV.RM-06 — “A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated”One scoring method for every risk: the scales, bands and position rule on the Lists and Appetite sheets
DORA — Delegated Regulation (EU) 2024/1774Article 3(b) — a procedure and methodology for ICT risk assessment, with indicators to measure impact and likelihoodImpact and likelihood scales, scores and bands: the indicators used to assess ICT risk
DORA — Regulation (EU) 2022/2554Article 8(2) — identify all sources of ICT risk on a continuous basis and review the risk scenarios at least yearlyTrigger columns and the quarterly and yearly reassessment: risk sources identified continuously and scenarios reviewed at least yearly

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)