Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Risk Assessment Workbook

Guides an assessor through a structured assessment of a system, process or supplier and outputs register-ready entries.

Available soon

Format
Excel
Size
93 KB
Length
14 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Scope & Context
  • Threat Checklist
  • Existing Controls
  • Scenario Assessment
  • Results
  • Register-Ready Output
  • Scales & Appetite
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Scope & Context: answer each item in the Answer column for the one system, process or supplier you are assessing. Name the business service it supports and its executive: that person is usually the risk owner (RM-02). Record the reason for the assessment — scheduled (RM-09), new, or one of the triggers that force a reassessment within [[10]] working days (RM-10).
2Threat Checklist: for each threat type, decide whether it could harm this subject. The list is the Cyber Risk Scenario Library's threat list, and column E names the library scenarios to consider for each. Answer: scenario raised (name its A-nn), covered by an existing register entry (name its R-nn), not relevant or not material (give the reason), or not yet assessed.
3Existing Controls: list the controls in place today that affect these threats, with the evidence you saw and how effective they are. Count a control only if you have seen evidence that it works; 'Not tested' controls should not lower a residual score.
4Scenario Assessment: one row per risk scenario raised. Write it in the four RM-01 parts — threat, weakness, asset or service, consequence — starting from the library entry where one fits (put its SC-nn in Library ID). Choose the category.
5Score the inherent impact on each of the 5 areas (Financial, Service, Data, Legal and regulatory, Reputation) from 1 to 4 using the anchors on the Scales & Appetite sheet. The inherent impact is the worst of them — no area is weighted (RM-03). Where personal data is involved, score the Data area on the worse of the harm to the organisation and the harm to the people whose data it is (GDPR Article 32). Then score the inherent likelihood: the chance over the next 12 months without your controls.
6Name the existing controls the scenario relies on (EC-nn), then score the residual impact and likelihood with those controls as they work today. The residual can never be higher than the inherent.
7Read the calculated band (RM-04), position against the category's appetite (RM-05), who may accept (RM-08) and the suggested treatment. Choose the treatment and name the risk owner. A risk outside appetite needs a treatment decision within 30 calendar days (RM-06); actions go to the Risk Treatment Plan and acceptances to the Risk Acceptance Form & Approval Record.
8Clear every Check (calc) that does not say OK — on the Threat Checklist, Existing Controls and Scenario Assessment. The Results sheet counts what is left and ranks the scenarios by residual score.
9Register-Ready Output: the rows marked OK appear here in the Information Security Risk Register's columns. Copy the filled rows, and in the register use Paste Special → Values with 'Skip blanks' ('Skip empty cells' in LibreOffice) on its first empty row: the grey columns are left empty so the register's own formulas are kept. Give new risks their R-nn in the register.
10Set the appetite level of each category on the Scales & Appetite sheet to match your approved Cyber Risk Appetite Statement Template. The EXAMPLE levels are the example organisation's.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The EXAMPLE. The workbook opens filled in with the example organisation's reassessment of its online ordering service (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders), dated 2026-09-30, the example quarter end. It produces three register entries — R-01, R-03, R-05 — with the same scores as the example Information Security Risk Register. Rows marked EXAMPLE in column A, and the Scope & Context answers, are the example.

To start your own assessment: save a copy, delete the EXAMPLE rows on the Threat Checklist answers (clear columns F to H), Existing Controls and Scenario Assessment, and clear the Answer column on Scope & Context. Replace the assessment date with the date of your assessment (or =TODAY() while drafting). Nothing else needs changing.

Weights. The standard questionnaire has weighted questions; a risk assessment does not. Impact is the worst of the five areas (RM-03), not an average, because one Severe consequence is Severe however mild the others are. Score = impact × likelihood; the band follows (Low 1–3, Medium 4–6, High 8–9, Critical 12–16).

Tailoring — small organisation: assess your two or three most important services first, one workbook each; keep scenarios few and well owned. Where you have no evidence that a control works, score as if it did not.

Tailoring — regulated entity: NIS2 Article 21(1) expects risk-based measures; DORA Article 8(3) expects a risk assessment on each major change to systems, processes or procedures — use this workbook for that and keep it with the change record. Record 'Major change' as the reason. Where personal data is involved, GDPR Article 32(2) asks that the risks of the processing be taken into account in choosing the level of security: score the Data area on the harm to the people as well as to the organisation.

Tailoring — IT run by a service provider: assess with the provider in the room; ask them for the evidence behind each control (reports, test results), and record the provider's controls as yours only if the contract requires them. The risk owner stays inside your organisation.

Limitations: see the foot of the Results sheet.

Scope & Context

What is being assessed, and its context. Answer in column E. The answers shown are the EXAMPLE; replace them with yours.

ExampleNo.ItemWhat to recordAnswer
EXAMPLE1Assessment referenceYour own reference, prefix AS- (for example AS-2026-03), so register entries can point back to this assessment. RA- is used by risk acceptances.AS-2026-03
EXAMPLE2Subject typeWhat is being assessed.System or service
EXAMPLE3Subject nameThe system, process or supplier, as the business knows it.Online ordering service
EXAMPLE4DescriptionWhat it does and for whom, in a sentence or two.The customer website and ordering platform. The example organisation is a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders.
EXAMPLE5Business service it supportsThe service that would suffer if this went wrong. Its executive is usually the risk owner (RM-02).Taking and fulfilling customer orders
EXAMPLE6Service ownerThe executive accountable for that service.Chief Operating Officer
EXAMPLE7Information it holds or processesTypes of data, whether personal data is involved, and roughly how much.Business customers' contact names, delivery addresses, order history and account credentials. Personal data: yes. Card details are entered on the payment provider's page, not stored here.
EXAMPLE8UsersWho uses it: customers, staff, suppliers, administrators.Customers ordering online; customer service staff; administrators at the managed IT provider.
EXAMPLE9DependenciesSuppliers, hosting and other systems it needs to work.Managed IT provider (administration and backups); hosting provider; payment service provider; warehouse management system for dispatch.
EXAMPLE10Reachable from the internet?Yes or No, and what is exposed.Yes: the ordering website and customer login.
EXAMPLE11Legal and regulatory scopeLaws, regulations and contracts that apply (for example GDPR, NIS2, DORA, card payment rules).GDPR (customer personal data); NIS2 (the organisation is in scope); customer contracts with service levels.
EXAMPLE12Reason for this assessmentScheduled, new, or a trigger (RM-10).Scheduled reassessment (RM-09)
EXAMPLE13In scopeWhat this assessment covers.The ordering website, its application and database, customer accounts, and their recovery.
EXAMPLE14Out of scopeWhat it does not cover, and where that is assessed instead.Warehouse systems (R-04); staff email and supplier payments (organisation-wide entries R-02 and R-09).
EXAMPLE15AssessorWho ran the assessment.[[e.g. Information Security Manager]]
EXAMPLE16People consultedWho gave evidence: owners, IT, suppliers.Chief Operating Officer; Head of IT; the managed IT provider's service manager.
EXAMPLE17Assessment dateThe date of the assessment. The EXAMPLE uses the example quarter end; replace it with your own date.30 Sep 2026

Threat Checklist

The Cyber Risk Scenario Library's threat list. For each threat, decide whether it could harm this subject, and record what you raised or why not. Columns F to H are yours.

ExampleThreat IDThreat typeWhat it looks likeLibrary scenarios to considerCould it harm this subject?Raised as (A-nn) or covered by (R-nn)Why, and the evidenceCheck (calc)
EXAMPLETH-01Ransomware and extortionCriminals get in, steal data and encrypt systems, then demand payment to restore them or not to publish what they took.SC-01, SC-02, SC-05Yes — scenario raisedA-01The ordering platform faces the internet and ransomware groups target distributors; recovery is slow.OK
EXAMPLETH-02Exploitation of unpatched or exposed systemsAttackers use a known weakness in an internet-facing system (remote access gateway, web server, remote desktop) before it is fixed.SC-03, SC-06, SC-11Yes — scenario raisedA-02, A-03Internet-facing application and customer database; patching has slipped this quarter.OK
EXAMPLETH-03Phishing and account takeoverA member of staff is tricked into giving away a password or approving a sign-in, and the attacker uses their account.SC-22, SC-24, SC-39, SC-41, SC-47Yes — covered by an existing register entryR-09Customer service and administrator accounts are staff accounts, covered organisation-wide.OK
EXAMPLETH-04Payment and invoice fraudA fraudster impersonates a supplier, an executive or an employee to have money paid to the wrong bank account (business email compromise).SC-20, SC-21, SC-23No — not relevant or not materialThe ordering service makes no supplier payments; supplier payment fraud is R-02.OK
EXAMPLETH-05Password attacks on customer or staff accountsAttackers try passwords leaked from other websites, or guess common ones, against login pages (credential stuffing).SC-14Yes — scenario raisedA-02Customer logins are part of A-02's weakness: stolen customer passwords are one route to customer data.OK
EXAMPLETH-06Denial of serviceA flood of traffic makes a website or online service unusable, sometimes with a demand for payment to stop.SC-07No — not relevant or not materialThe website sits behind the hosting provider's denial-of-service protection; an outage of a few hours is within what the service owner accepts.OK
EXAMPLETH-07Malicious insiderSomeone with legitimate access — an employee, contractor or administrator — misuses it to steal, change or destroy information or money.SC-25, SC-40, SC-42, SC-43Yes — covered by an existing register entryR-07Administrator misuse is assessed organisation-wide.OK
EXAMPLETH-08Human errorA mistake by someone with legitimate access: data sent to the wrong person, files deleted, a change that breaks a system.SC-08, SC-15, SC-44, SC-46No — not relevant or not materialChanges go through the managed IT provider's change process with a back-out plan; no failed change in the last 12 months.OK
EXAMPLETH-09Loss or theft of equipmentA laptop, phone or storage device holding the organisation's information is lost, stolen or not returned.SC-13, SC-16No — not relevant or not materialNo ordering data is held on laptops; the warehouse laptops are R-12.OK
EXAMPLETH-10Supplier failure or compromiseA supplier the organisation depends on is attacked, has an outage, or stops trading, and its problem becomes the organisation's.SC-33, SC-34, SC-37Yes — covered by an existing register entryR-06The managed IT provider administers the platform and its backups.OK
EXAMPLETH-11MisconfigurationA system or cloud service is set up so that information or access is open to people who should not have it.SC-10, SC-12, SC-17, SC-19Yes — covered by an existing register entryR-11Cloud storage used by the ordering service is in the monthly configuration scan.OK
EXAMPLETH-12Technical or environmental failureHardware, power, cooling, a hosting region or a failed recovery stops a service, with no attacker involved.SC-04, SC-09, SC-35, SC-38Yes — covered by an existing register entryR-10Restore of critical systems is assessed organisation-wide; the ordering platform's own recovery time is part of A-01.OK
EXAMPLETH-13Software and web supply-chain attackMalicious code arrives through a trusted route: a vendor's software update, a code library, or a script on the organisation's own website.SC-18, SC-36No — not relevant or not materialCard details are entered only on the payment provider's page; no third-party scripts run on it.OK
EXAMPLETH-14Loss of key people or knowledgeThe only people who can run, fix or recover a system leave or are unavailable when needed.SC-45Yes — scenario raisedA-03The ordering platform team lost two engineers this quarter and on-time patching fell to 81% (target 95% within 14 calendar days).OK
EXAMPLETH-15Failure to meet a legal or regulatory obligationA deadline, notification or requirement under law, regulation or contract is missed, whatever the underlying event.SC-26, SC-27, SC-28, SC-29, SC-30, SC-31, SC-32Yes — covered by an existing register entryR-08Incident reporting is assessed organisation-wide.OK

Existing Controls

The controls in place today that affect this subject's threats. Count a control only on evidence that it works. Scenario rows refer to these by EC-nn.

ExampleControl IDControlTypeThreats it addresses (TH-nn)EffectivenessEvidence seenControl ownerCheck (calc)
EXAMPLEEC-01Nightly backups of the ordering platformRespond or recoverTH-01, TH-12Partly effectiveBackup reports checked; a full restore of the platform has not been proven within 2 daysHead of ITOK
EXAMPLEEC-02Endpoint detection on serversDetectTH-01, TH-02EffectiveProvider's monthly service report; alerts testedHead of ITOK
EXAMPLEEC-03Web application firewall in front of the ordering service and other internet-facing systemsPreventTH-02, TH-05EffectiveConfiguration reviewed; blocking mode confirmedHead of ITOK
EXAMPLEEC-04Yearly penetration test of the ordering serviceDetectTH-02, TH-05EffectiveLast report read; its findings are closedHead of ITOK
EXAMPLEEC-05Customer data encrypted at restPreventTH-02EffectiveDatabase encryption setting seenHead of ITOK
EXAMPLEEC-06Monthly vulnerability scanningDetectTH-02EffectiveScan reports for the last three monthsHead of ITOK
EXAMPLEEC-07Patching deadlines by severityPreventTH-02, TH-14Partly effectiveCritical weaknesses fixed on time this quarter: 81%, against 95% within 14 calendar daysHead of ITOK

Scenario Assessment

One row per risk scenario. Yellow columns are yours; the rest calculate. Impact is the worst of the five areas (RM-03); position, who may accept and the suggested treatment follow from the residual band and the category's appetite.

ExampleScenario IDLibrary ID (SC-nn)Register ID (R-nn), if already registeredCategory IDCategory (calc)Risk titleThreat IDThreat — who or whatWeakness it usesAsset or service affectedConsequenceImpact: Financial (1–4)Impact: Service (1–4)Impact: Data (1–4)Impact: Legal and regulatory (1–4)Impact: Reputation (1–4)Inherent impact (calc: worst area)Worst impact area (calc)Inherent likelihood (1–4)Inherent score (calc)Inherent band (calc)Existing controls relied onControl IDs (EC-nn)Residual impact (1–4)Residual likelihood (1–4)Residual score (calc)Residual band (calc)Category appetite level (calc)Position against appetite (calc)Who may accept (calc)Suggested treatment (calc)Treatment chosenRisk ownerScoring notesCheck (calc)Output order (calc)Ranking key (calc)
EXAMPLEA-01SC-01R-01RC-01Service availabilityRansomware takes online ordering offline for more than 2 daysTH-01Criminal ransomware groupThe ordering platform cannot be restored from backup in less than 4 daysThe online ordering service (60% of orders)Loss of about €1.2m of orders per week; customer contracts breached442334Financial, Service312CriticalNightly backups of the ordering platform; endpoint detection on servers; recovery of the whole platform not yet proven within 2 daysEC-01, EC-02428HighCautiousOutside appetite, within toleranceAccountable executive and Head of Information Security, and executive management as wellReduce, avoid or transfer; decide within 30 calendar days (RM-06). Accepting needs executive management as well as the band's approvers.ReduceChief Operating OfficerImpact Severe on Service and Financial: loss of about €1.2m of orders per week; customer contracts breached. Residual likelihood falls to Possible with endpoint detection, but impact stays Severe until the platform can be restored within 2 days (TA-01).OK1812.0996
EXAMPLEA-02SC-11R-03RC-02Customer and personal dataCustomer data exposed through the ordering serviceTH-02Attackers targeting the customer databaseA weakness in the ordering service's web application or its customer accountsCustomer records in the online ordering serviceCustomer personal data exposed at scale. Regulatory fine, notification cost and lost trade; about €0.8m314434Data, Legal and regulatory28HighWeb application firewall; yearly penetration test of the ordering service; customer data encrypted at restEC-03, EC-04, EC-05414MediumCautiousWithin appetiteRisk owner and Head of Information SecurityWithin appetite: accept at the band's level on the Risk Acceptance Form, or reduce further if a cheap control closes the gap.ReduceChief Operating OfficerImpact Severe on Data and Legal: personal data at scale, a notifiable breach (regulatory fine, notification cost and lost trade; about €0.8m). Tested application and encrypted data make it Unlikely.OK2408.0995
EXAMPLEA-03SC-03R-05RC-01Service availabilityCritical weaknesses on internet-facing systems exploited before they are fixedTH-02Attackers scanning the internet for known weaknessesCritical security updates on internet-facing systems are applied later than the agreed deadlineInternet-facing systems (websites, ordering or customer portals, remote access)Attacker gains a foothold for ransomware or data theft; service disrupted while systems are rebuilt233223Service, Data39HighMonthly vulnerability scanning; patching deadlines by severity; internet-facing systems behind a web application firewallEC-03, EC-06, EC-07326MediumCautiousWithin appetiteRisk owner and Head of Information SecurityWithin appetite: accept at the band's level on the Risk Acceptance Form, or reduce further if a cheap control closes the gap.ReduceHead of ITImpact Major on Service and Data. Scanning and the firewall make exploitation Possible rather than Likely; patching is behind after two engineers left (TA-03).OK3609.0994

Results

Results

Calculated from the other sheets. The prioritised list ranks the scenarios by residual score (then inherent score). Nothing here is typed.

This assessment

SubjectOnline ordering service (AS-2026-03)
Assessment date30 Sep 2026EXAMPLE: these results are the worked example. Delete the EXAMPLE rows to see your own.

Counts

MeasureResultWhat it means
Scenarios assessed3Rows on Scenario Assessment with a scenario ID.
Ready for the register3Scenario rows whose check says OK; they appear on Register-Ready Output.
Scenario rows to resolve0Fix these before sign-off.
Threat checklist items to resolve0Including threats not yet assessed.
Control rows to resolve0Controls without an ID, effectiveness or evidence.
Residual Low (1–3)0Who may accept: Risk owner.
Residual Medium (4–6)2Who may accept: Risk owner and Head of Information Security.
Residual High (8–9)1Who may accept: Accountable executive and Head of Information Security.
Residual Critical (12–16)0Who may accept: The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management.
Within appetite2No decision needed beyond the chosen treatment.
Outside appetite, within tolerance1A treatment decision within 30 calendar days (RM-06); accepting needs executive management as well as the band's approvers.
Outside tolerance0Escalate at once; only the board or its equivalent may accept (RM-08).

Scenarios in priority order (highest residual score first)

#ScenarioRisk titleResidualPositionSuggested treatmentTreatment chosenRisk owner
1A-01Ransomware takes online ordering offline for more than 2 days8 HighOutside appetite, within toleranceReduce, avoid or transfer; decide within 30 calendar days (RM-06). Accepting needs executive management as well as the band's approvers.ReduceChief Operating Officer
2A-03Critical weaknesses on internet-facing systems exploited before they are fixed6 MediumWithin appetiteWithin appetite: accept at the band's level on the Risk Acceptance Form, or reduce further if a cheap control closes the gap.ReduceHead of IT
3A-02Customer data exposed through the ordering service4 MediumWithin appetiteWithin appetite: accept at the band's level on the Risk Acceptance Form, or reduce further if a cheap control closes the gap.ReduceChief Operating Officer

4

5

6

7

8

Ranking: residual score, then inherent score, then the order on the Scenario Assessment sheet. Up to 8 scenarios are listed. A risk outside appetite is always treated first, whatever its rank (RM-06).

Limitations

The scores are judgements. They are only as good as the evidence behind them and the people in the room; record the evidence in the scoring notes so the next assessor can challenge it.

The workbook assesses one subject. Risks that cut across many subjects (phishing, supplier failure, backups) belong in the register once, owned organisation-wide; this workbook points to them rather than re-scoring them.

Likelihood is over the next 12 months, as the scale defines it. A rare but catastrophic scenario can score Low and still deserve a tested plan: read the impact as well as the band.

The Register-Ready Output is a proposal until the risk owner agrees it. The Information Security Risk Register is the single record (RM-11); this workbook is the working behind it.

Register-Ready Output

In the Information Security Risk Register's columns. Copy the filled rows; in the register, Paste Special → Values with 'Skip blanks' on its first empty row. Grey columns are the register's to calculate or record and are left empty. Do not type here.

ExampleRisk IDCategoryAppetite levelRisk scenarioRisk ownerInherent impact (1–4)Inherent likelihood (1–4)Inherent scoreInherent bandExisting controlsResidual impact (1–4)Residual likelihood (1–4)Residual scoreResidual bandLast quarter's residual scoreMovementPosition against appetiteTreatmentLinked actionsWho may acceptAcceptance refAcceptance review dateLast owner reviewReviewed this quarterTrigger since last assessmentTrigger dateReassessed onTrigger flagRecord checkNotes
EXAMPLER-01Service availabilityRansomware takes online ordering offline for more than 2 daysChief Operating Officer43Nightly backups of the ordering platform; endpoint detection on servers; recovery of the whole platform not yet proven within 2 days42ReduceFrom risk assessment AS-2026-03 of Online ordering service, 2026-09-30, scenario A-01 (library SC-01)
EXAMPLER-03Customer and personal dataCustomer data exposed through the ordering serviceChief Operating Officer42Web application firewall; yearly penetration test of the ordering service; customer data encrypted at rest41ReduceFrom risk assessment AS-2026-03 of Online ordering service, 2026-09-30, scenario A-02 (library SC-11)
EXAMPLER-05Service availabilityCritical weaknesses on internet-facing systems exploited before they are fixedHead of IT33Monthly vulnerability scanning; patching deadlines by severity; internet-facing systems behind a web application firewall32ReduceFrom risk assessment AS-2026-03 of Online ordering service, 2026-09-30, scenario A-03 (library SC-03)

Scales & Appetite

Scales and appetite

The Risk Assessment Methodology & Scoring Model's anchors, to score against, and each category's appetite level. Set the appetite levels (yellow) from your approved Cyber Risk Appetite Statement Template.

Impact — score each area, then take the worst (RM-03)

Area1 Minor2 Moderate3 Major4 Severe
Financialless than [[€50,000]][[€50,000]] to [[€250,000]][[€250,000]] to [[€1,000,000]]more than [[€1,000,000]]
Servicean internal service degraded for hoursa customer service degraded, or an internal service stopped, for up to [[1]] daya core customer service stopped for up to [[2]] daysa core customer service stopped for more than [[2]] days
Datainternal, non-personal datainternal confidential data, or personal data of a few peoplepersonal or customer data of [[hundreds]] of people, or commercially sensitive datapersonal or customer data at scale
Legal and regulatoryno notification or breacha minor breach of contract or policy, put right without penaltya formal enquiry by a regulator or customer, or a contract breach with penaltiesa notifiable breach, enforcement or contract termination
Reputationnot noticed outside the teamnoticed by some customers or supplierscomplaints from several major customers, or regional or trade pressnational press, or loss of a major customer
Where personal data is involved, score the Data area on the worse of the harm to the organisation and the harm to the people whose data it is (GDPR Article 32). General meaning of each level: 1 Minor — affects one system of Standard criticality or non-sensitive data; no customer or regulatory effect. 2 Moderate — affects a High criticality system or internal confidential data; limited, recoverable disruption. 3 Major — affects a Critical system, personal or customer data, or a regulated service; notifiable if it went wrong. 4 Severe — could stop a core business service, expose sensitive data at scale, or breach a legal obligation.

Likelihood — the chance over the next 12 months (RM-03)

LevelChanceSigns
1 Unlikelyless than [[20]]% in the next 12 monthsNot seen at organisations like ours in recent years, or only with rare skill or access.
2 Possible[[20]]% to [[50]]% in the next 12 monthsHappens regularly to organisations like ours; our controls make it harder but not rare.
3 Likely[[50]]% to [[90]]% in the next 12 monthsHappening now to organisations like ours, or has happened to us, and the gap is still open.
4 Almost certainmore than [[90]]% in the next 12 months, or already happeningBeing attempted against us now, with little in the way.

Bands and who may accept (RM-04, RM-08)

BandScoresWho may acceptAcceptance reviewed within
Low1–3Risk owner12 months
Medium4–6Risk owner and Head of Information Security12 months
High8–9Accountable executive and Head of Information Security6 months
Critical12–16The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management3 months

Outside appetite: the band's approvers, and executive management as well (Critical is already the board's). Outside tolerance: the band's approvers recommend; only the board or its equivalent may accept.

Appetite levels

LevelAppetite (highest band accepted)Tolerance (highest band tolerated while a plan brings it back)Meaning
AverseLowMediumWe avoid this risk and act on anything above Low.
CautiousMediumHighWe accept some risk for a clear business benefit, with controls.
OpenHighHighWe accept higher risk to pursue opportunity; Critical is never within tolerance.

Category appetite — set yours (EXAMPLE levels shown)

Category IDCategoryAppetite levelAppetite (calc)Tolerance (calc)
RC-01Service availabilityCautiousMediumHigh
RC-02Customer and personal dataCautiousMediumHigh
RC-03Financial fraudCautiousMediumHigh
RC-04Regulatory complianceAverseLowMedium
RC-05Third-party dependencyCautiousMediumHigh
RC-06People and insiderCautiousMediumHigh

EXAMPLE: the levels shown are the example organisation's. Replace them with the levels in your approved Cyber Risk Appetite Statement Template.

Lists

CategoryIDThreatIDImpactAreaBandNameBandMinAcceptApproverAppetiteLevelLevelAppetiteLevelToleranceTreatmentChecklistAnswerControlTypeEffectivenessSubjectTypeReason
RC-01TH-01FinancialLow1Risk ownerAverseLowMediumReduceYes — scenario raisedPreventEffectiveSystem or serviceScheduled reassessment (RM-09)
RC-02TH-02ServiceMedium4Risk owner and Head of Information SecurityCautiousMediumHighAvoidYes — covered by an existing register entryDetectPartly effectiveProcessNew system, process or supplier
RC-03TH-03DataHigh8Accountable executive and Head of Information SecurityOpenHighHighTransferNo — not relevant or not materialRespond or recoverNot effectiveSupplierA major incident, or a near miss that shows a risk was underrated
RC-04TH-04Legal and regulatoryCritical12The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive managementAcceptNot yet assessedNot testedProject or changeA major change to systems, processes, suppliers or the organisation
RC-05TH-05ReputationA new or changed threat relevant to our services (threat intelligence)
RC-06TH-06An audit, test or assessment finding
TH-07A change in law, regulation or a key contract

TH-08

TH-09

TH-10

TH-11

TH-12

TH-13

TH-14

TH-15

Definitions

Definitions

TermMeaning in this workbook
Risk assessmentIdentifying the risks to one system, process or supplier, scoring them and deciding what to do (ISO/IEC 27001 Clause 8.2 asks for it at planned intervals and on significant change).
SubjectThe system, process or supplier this workbook assesses. One workbook, one subject.
Risk scenarioA threat, the weakness it uses, the asset or service affected, and the consequence (RM-01).
Threat typeA group of threats from the Cyber Risk Scenario Library's threat list (TH-nn).
Existing controlA measure in place today that makes a scenario less likely or less harmful. Counted only on evidence.
EffectivenessEffective: evidence shows it works as intended. Partly effective: it works but with a known gap. Not effective: it does not do what it should. Not tested: no evidence either way — do not rely on it.
Impact areaThe kinds of consequence impact is judged on: Financial, Service, Data, Legal and regulatory, Reputation.
InherentBefore the existing controls are counted.
ResidualWith the existing controls as they work today.
ScoreImpact × likelihood, 1 to 16.
Band — LowScore 1–3. Who may accept: Risk owner.
Band — MediumScore 4–6. Who may accept: Risk owner and Head of Information Security.
Band — HighScore 8–9. Who may accept: Accountable executive and Head of Information Security.
Band — CriticalScore 12–16. Who may accept: The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management.
AppetiteThe highest residual band a category accepts without escalation.
ToleranceThe highest residual band a category tolerates while a plan brings it back within appetite. Critical is never within tolerance.
Appetite level — AverseWe avoid this risk and act on anything above Low. Appetite Low; tolerance Medium.
Appetite level — CautiousWe accept some risk for a clear business benefit, with controls. Appetite Medium; tolerance High.
Appetite level — OpenWe accept higher risk to pursue opportunity; Critical is never within tolerance. Appetite High; tolerance High.
Position against appetiteWithin appetite, Outside appetite, within tolerance, Outside tolerance — the residual band compared with the category's appetite and tolerance (RM-05).
Treatment — ReduceChange the likelihood or the impact with controls.
Treatment — AvoidStop the activity that creates the risk.
Treatment — TransferShare the impact with a third party, for example by insurance or contract; the risk owner still owns the risk.
Treatment — AcceptKeep the residual risk knowingly, recorded and approved at the right level (Risk Acceptance Form).
Risk ownerThe executive accountable for the service or asset the risk would hurt, not the security team (RM-02).
Register-readyA scenario row whose check says OK: complete enough to enter in the Information Security Risk Register.
RM-nnThe rules in the Risk Assessment Methodology & Scoring Model.
AS-, A-nn, EC-nn, R-nn, SC-nn, TH-nnAssessment reference (AS-, so it is not confused with a risk acceptance, RA-); scenario in this assessment; existing control in this assessment; entry in the Information Security Risk Register; entry in the Cyber Risk Scenario Library; threat type in its threat list.
(calc)A column or cell the workbook calculates. Do not type or paste over it.
EXAMPLE rowA row of the worked example (the online ordering service). Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 8.2 — Information security risk assessmentThe workbook as a whole: one assessment of one subject, run on schedule or on change
ISO/IEC 27001:2022Clause 6.1.2 — Information security risk assessmentScenario Assessment: RM-01 scenarios, impact and likelihood, bands and position; Scales & Appetite
NIST CSF 2.0ID.RA-03 — “Internal and external threats to the organization are identified and recorded”Threat Checklist
NIST CSF 2.0ID.RA-05 — “Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization”Scenario Assessment: inherent and residual scores; Results: scenarios in priority order
DORA — Regulation (EU) 2022/2554Article 8(3) — perform a risk assessment upon each major change in systems, processes or proceduresInstructions: tailoring for a regulated entity — an assessment on each major change
GDPR — Regulation (EU) 2016/679Article 32(2) — in assessing the appropriate level of security, account is taken of the risks presented by processingScenario Assessment: the Data impact area scored on the harm to the people as well as the organisation

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)