Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Risk Treatment Plan

Converts treatment decisions into owned, dated actions with cost and expected residual reduction, so the plan can be funded.

Available soon

Format
Excel
Size
82 KB
Length
10 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Plan Overview
  • Actions
  • Funding & Timeline
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Plan Overview sheet. The EXAMPLE uses 2026-09-30, the example quarter end; replace it with today's date, or type =TODAY() to keep it current. Days to due date and the overdue flag use this date.
2For every risk in the Information Security Risk Register whose treatment is Reduce, Avoid or Transfer, add one row per action (RM-07). Give it an Action ID (TA-01, TA-02 …) and enter the same ID in the register's Linked actions column. A risk outside appetite needs its treatment decision within the time RM-06 sets.
3Copy the Risk ID, the Risk, the category's Appetite level and today's residual impact and likelihood from the register. Describe the action so that someone else could tell when it is done, and name one Action owner.
4Enter the Due date, the One-off cost and any Running cost per year (0 if none; staff time can be costed or noted in Dependencies). Amounts in the examples are in euros (€); use your own currency.
5Enter the Expected residual impact and likelihood: the residual when this action and any earlier action on the same risk are done. The expected score, band and position after calculate. If the position after is still outside appetite, add actions or record an acceptance for what remains (RM-08).
6Keep the Status current: Not started, Awaiting board approval, In progress, At risk, Done, Cancelled. Do not type Overdue: the Overdue flag shows it once the due date has passed, and Overdue more than 30 days after 30 calendar days (RMM-02). Use At risk for an action that is not yet overdue but will miss its date unless something changes.
7When an action is done, enter Completed on, reassess the risk in the Information Security Risk Register and check the residual reached what was expected. Do not delete done or cancelled actions; they are the record.
8Read the Funding & Timeline sheet: the cost of the plan, what is awaiting approval, the cost and expected position for each risk, and what falls due in each quarter. Take the funding asks to the people who can approve them.
9Complete the Plan Overview: objectives, scope, review points, and each risk owner's approval of the plan and of the residual risk it leaves (RM-08).
10Clear every Record check that does not say OK. Delete the EXAMPLE rows before the plan is approved. Do not type over the white calculated columns.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: one plan for the whole organisation is enough, often under ten actions. Cost staff time where it competes with other work; otherwise enter 0 and say who does it.

Tailoring — regulated entity (NIS2, DORA): the plan is how treatment measures are identified, carried out and documented to bring ICT risk within the tolerance level (Delegated Regulation (EU) 2024/1774 Art 3(c)); keep each quarter's copy with the as-at date fixed. Where personal data is involved, record which actions give security appropriate to the risk to people (GDPR Art 32(1)).

Tailoring — IT run by a service provider: an action the provider delivers still has an owner in your organisation, who holds the provider to the date. Put the contract change or the provider's own plan in Dependencies.

EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. TA-01 is the €180,000 decision in the quarterly board report; TA-02 treats the payment fraud risk; TA-04 is done and brought R-04 back within appetite; TA-03 is at risk because the ordering platform team lost two engineers, but it is not overdue: it is due on 2026-10-31.

Plan Overview

Plan overview

What the plan is for, what it covers, when it is reviewed and who approved it. Yellow cells are yours; the EXAMPLE entries show a completed plan.

As-at date30 Sep 2026EXAMPLE date (the example quarter end). Replace it with today's date, or type =TODAY().

Plan

ItemEntry
Plan owner[[e.g. Head of Information Security or CISO]]
Period covered[[e.g. Q4 2026 to Q3 2027]]
Risks in scope[[EXAMPLE: the risks in the Information Security Risk Register treated by Reduce, Avoid or Transfer that need action: R-01 and R-02, outside appetite; R-05, within appetite but slipping; and R-04, whose action TA-04 was done this quarter]]
Out of scope[[e.g. risks treated by Accept (see the Risk Acceptance Form & Approval Record); projects funded elsewhere]]

Objectives and measures of success

ObjectiveMeasure of successTarget dateStatus
[[Bring every risk outside appetite back within appetite (RMM-01)]][[EXAMPLE: R-01 and R-02 within appetite once TA-01 and TA-02 are done]]31 Dec 2026[[On track / At risk / Met]]
[[Deliver actions on time (RMM-02)]][[Zero older than 30 days]][[Every quarter]][[On track / At risk / Met]]
[[Keep risks within appetite from drifting]][[EXAMPLE: R-05 back to Low once TA-03 restores the patching deadline]]31 Oct 2026[[On track / At risk / Met]]

Review points

WhenWhoWhat is checked
[[Monthly]]Head of Information Security with the action ownersStatus and due dates; At risk and overdue actions; new actions
Every quarter (RM-09)Each risk ownerThat the expected residual is still right and the actions still the right ones
Every quarter (RM-12)[[e.g. Executive Committee]]Treatment progress and RMM-02, through the Risk Reporting Dashboard
On a trigger (RM-10)Risk owner and assessorWhether the plan still brings the risk back within appetite
When an action is doneRisk ownerThe residual reached what was expected; the Information Security Risk Register is updated

Approval of the plan and of the residual risk it leaves (RM-08)

Risk ownerRisks and actionsResidual risk accepted when doneApproved by (name)Date
[[EXAMPLE: Chief Operating Officer]][[R-01: TA-01]][[R-01 at 4 (Medium), within appetite]][[Name]][[YYYY-MM-DD]]
[[EXAMPLE: Chief Financial Officer]][[R-02: TA-02]][[R-02 at 6 (Medium), within appetite]][[Name]][[YYYY-MM-DD]]
[[EXAMPLE: Head of Logistics]][[R-04: TA-04]][[R-04 at 4 (Medium), within appetite]][[Name]][[YYYY-MM-DD]]
[[EXAMPLE: Head of IT]][[R-05: TA-03]][[R-05 at 3 (Low), within appetite]][[Name]][[YYYY-MM-DD]]
Funding over [[€ amount]]: [[e.g. Board, or its Audit & Risk Committee]][[EXAMPLE: TA-01, €180,000]][[Decision: approved / approved in part / not approved]][[Name]][[YYYY-MM-DD]]

A residual risk left outside appetite is accepted by its band's approvers and executive management as well, never instead; outside tolerance, only the board or its equivalent (RM-08).

Actions

One row per treatment action (RM-07). Yellow columns are inputs; white columns calculate. Every colour sits beside a word.

ExampleAction IDRisk IDRiskAppetite levelTreatment actionAction ownerDue dateStatusCompleted onOne-off cost (€)Running cost per year (€)DependenciesCurrent residual impact (1–4)Current residual likelihood (1–4)Current residual scoreCurrent bandCurrent positionExpected residual impact (1–4)Expected residual likelihood (1–4)Expected residual scoreExpected bandExpected position afterDays to due dateOverdue flagRecord checkNotes
EXAMPLETA-01R-01Ransomware takes online ordering offline for more than 2 daysCautiousRebuild the ordering platform's recovery so it can be restored within 24 hoursHead of IT15 Dec 2026Awaiting board approval€180,000€20,000Board approval of the funding at the 2026-10-29 meeting; work must start before the November peak season428HighOutside appetite, within tolerance414MediumWithin appetite76OKThe decision in the quarterly board report: option A, done by 15 Dec 2026. Brings R-01 back within appetite
EXAMPLETA-02R-02Payment fraud through a compromised supplier email accountCautiousCall-back verification of every change to supplier bank details, and a payment verification serviceChief Financial Officer30 Nov 2026In progress€15,000Payment verification service chosen and contracted339HighOutside appetite, within tolerance326MediumWithin appetite61OK
EXAMPLETA-04R-04Ransomware spreads from warehouse office PCs to warehouse systemsCautiousSeparate the warehouse networks from the office network at all three sitesHead of IT11 Sep 2026Done11 Sep 2026€28,000None224MediumWithin appetite224MediumWithin appetiteOKDone: the last site was separated on 2026-09-09 and the separation tested on 2026-09-11. R-04 back within appetite at the quarter-end review
EXAMPLETA-03R-05Critical weaknesses on internet-facing systems exploited before they are fixedCautiousBring the ordering platform's patching back to 95% within deadline after two engineers leftHead of IT31 Oct 2026At risk€0Two engineer vacancies on the ordering platform team filled, or cover arranged with the managed IT provider326MediumWithin appetite313LowWithin appetite31OKNot overdue at the as-at date, but at risk of missing its due date while the team is short of two engineers

Funding & Timeline

Funding and timeline

Calculated from the Actions sheet as at the date on the Plan Overview sheet. Amounts in euros (€) in the EXAMPLE; use your own currency. Cancelled actions are left out.

The plan in figures

MeasureValueTargetStatusWhat it means
Actions in the plan4Every action except cancelled ones.
Open actions3Not yet done.
One-off cost of the whole plan€223,000Every action except cancelled ones, done or not.
of which open actions€195,000Actions not yet done: what is still to be spent.
of which awaiting approval€180,000Open actions whose funding has not yet been approved: the ask to take forward.
of which approved, under way or done€43,000Everything in the whole plan that is not awaiting approval.
Running cost per year€20,000What the plan adds to yearly budgets once the actions are done.
RMM-02 Treatment actions overdue0Open treatment actions past their due date. Calculated from the due date, never typed.
older than 30 days0Zero older than 30 daysOn targetEscalate each to the risk owner and executive management.
Actions at risk1Not overdue, but likely to miss the date unless something changes. Name each in the quarterly report.

Cost and expected effect by risk

Risk IDActionsOne-off costRunning cost per yearResidual todayPosition todayLowest expected scoreExpected bandExpected position afterLast action due
R-011€180,000€20,0008 (High)Outside appetite, within tolerance4MediumWithin appetite15 Dec 2026
R-021€15,000€09 (High)Outside appetite, within tolerance6MediumWithin appetite30 Nov 2026
R-041€28,000€04 (Medium)Within appetite4MediumWithin appetite11 Sep 2026
R-051€0€06 (Medium)Within appetite3LowWithin appetite31 Oct 2026
All risks4€223,000€20,00015 Dec 2026

Type the Risk IDs in the yellow cells. Lowest expected score: the lowest residual expected by any of the risk's actions, which is the one expected when all are done.

Timeline: what falls due, by quarter

PeriodFromToOpen actions dueOne-off cost due
Past due at the as-at date30 Sep 20260€0
Q4 20261 Oct 202631 Dec 20263€195,000
Q1 20271 Jan 202731 Mar 20270€0
Q2 20271 Apr 202730 Jun 20270€0
Q3 20271 Jul 202730 Sep 20270€0
Later1 Oct 20270€0

Past due counts open actions and their cost; each quarter counts open actions due, and the cost of every action due that is not cancelled. Quarters are calendar quarters after the as-at date.

Lists

LevelBandBandMinScoreAppetiteLevelLevelAppetiteLevelToleranceActionStatusPosition
1Low1AverseLowMediumNot startedWithin appetite
2Medium4CautiousMediumHighAwaiting board approvalOutside appetite, within tolerance
3High8OpenHighHighIn progressOutside tolerance
4Critical12At risk

Done

Cancelled

Definitions

Definitions

TermMeaning in this workbook
TreatmentReduce: change the likelihood or the impact with controls. Avoid: stop the activity that creates the risk. Transfer: share the impact with a third party, for example by insurance or contract; the risk owner still owns the risk. Accept: keep the residual risk knowingly, recorded and approved at the right level (Risk Acceptance Form).
Treatment actionA piece of work that changes a risk's likelihood or impact, with an owner, a due date, a cost and the residual expected when it is done (Treatment actions have an owner, a due date, a cost and the residual score expected when they are done).
Action IDYour unique reference for the action, such as TA-01. The same ID goes in the register's Linked actions column.
Action ownerThe person who delivers the action. [[whoever delivers a treatment action]] The risk owner stays accountable for the risk.
StatusNot started, Awaiting board approval, In progress, At risk, Done, Cancelled. Awaiting board approval: the action cannot start until its funding is approved. At risk: not overdue, but likely to miss its date. Overdue is never a status: it is calculated.
One-off cost, running costWhat the action costs to deliver, and what it adds each year once in place. Amounts in the examples are in euros (€); use your own currency.
Current residualToday's residual impact, likelihood, score and band, copied from the Information Security Risk Register.
Expected residualThe residual impact and likelihood expected when this action, and any earlier action on the same risk, is done.
BandLow: score 1–3; Medium: score 4–6; High: score 8–9; Critical: score 12–16.
Appetite levelAverse: appetite up to Low, tolerance up to Medium; Cautious: appetite up to Medium, tolerance up to High; Open: appetite up to High, tolerance up to High.
PositionWithin appetite, Outside appetite, within tolerance or Outside tolerance: the band compared with the category's appetite and tolerance (RM-05). Expected position after uses the expected band.
Days to due dateCalendar days from the as-at date to the due date, for open actions. Negative once the date has passed.
Overdue flagOverdue: an open action past its due date. Overdue more than 30 days: past it by more than 30 calendar days (RMM-02).
Record checkA calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding.
As-at dateThe date days to due date and overdue are measured against. Set on the Plan Overview sheet.
EXAMPLE rowA worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. Delete before approval.
RM-nn, RMM-nnRule and measure numbers in the Risk Assessment Methodology & Scoring Model.
Likelihood, impactThe 1–4 scales in the Risk Assessment Methodology & Scoring Model: impact 1 Minor, 2 Moderate, 3 Major, 4 Severe; likelihood 1 Unlikely, 2 Possible, 3 Likely, 4 Almost certain.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 6.1.3 — Information security risk treatmentThe plan as a whole: treatment options chosen, the actions they need, and the risk owners' approval of the plan and of the residual risk
ISO/IEC 27001:2022Clause 8.3 — Information security risk treatmentStatus, due dates, overdue flag and completion: the plan carried out and its results kept as records
NIST CSF 2.0ID.RA-06 — “Risk responses are chosen, prioritized, planned, tracked, and communicated”Actions with owners, dates, costs and expected residual; funding and timeline; review points
DORA — Delegated Regulation (EU) 2024/1774Article 3(c) — a procedure to identify, implement and document treatment measures that bring ICT risk within the tolerance levelActions and their expected position after: treatment measures identified, carried out and documented to bring risk within tolerance
GDPR — Regulation (EU) 2016/679Article 32(1) — appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the likelihood and severity of risk to people's rights and freedomsExpected residual for risks involving personal data: measures chosen by the likelihood and severity of the risk

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)