Risk Treatment Plan
Converts treatment decisions into owned, dated actions with cost and expected residual reduction, so the plan can be funded.
Available soon
- Format
- Excel
- Size
- 82 KB
- Length
- 10 sheets
- Version
- 1.1
- Updated
What's inside
- Instructions
- Plan Overview
- Actions
- Funding & Timeline
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Plan Overview sheet. The EXAMPLE uses 2026-09-30, the example quarter end; replace it with today's date, or type =TODAY() to keep it current. Days to due date and the overdue flag use this date. |
| 2 | For every risk in the Information Security Risk Register whose treatment is Reduce, Avoid or Transfer, add one row per action (RM-07). Give it an Action ID (TA-01, TA-02 …) and enter the same ID in the register's Linked actions column. A risk outside appetite needs its treatment decision within the time RM-06 sets. |
| 3 | Copy the Risk ID, the Risk, the category's Appetite level and today's residual impact and likelihood from the register. Describe the action so that someone else could tell when it is done, and name one Action owner. |
| 4 | Enter the Due date, the One-off cost and any Running cost per year (0 if none; staff time can be costed or noted in Dependencies). Amounts in the examples are in euros (€); use your own currency. |
| 5 | Enter the Expected residual impact and likelihood: the residual when this action and any earlier action on the same risk are done. The expected score, band and position after calculate. If the position after is still outside appetite, add actions or record an acceptance for what remains (RM-08). |
| 6 | Keep the Status current: Not started, Awaiting board approval, In progress, At risk, Done, Cancelled. Do not type Overdue: the Overdue flag shows it once the due date has passed, and Overdue more than 30 days after 30 calendar days (RMM-02). Use At risk for an action that is not yet overdue but will miss its date unless something changes. |
| 7 | When an action is done, enter Completed on, reassess the risk in the Information Security Risk Register and check the residual reached what was expected. Do not delete done or cancelled actions; they are the record. |
| 8 | Read the Funding & Timeline sheet: the cost of the plan, what is awaiting approval, the cost and expected position for each risk, and what falls due in each quarter. Take the funding asks to the people who can approve them. |
| 9 | Complete the Plan Overview: objectives, scope, review points, and each risk owner's approval of the plan and of the residual risk it leaves (RM-08). |
| 10 | Clear every Record check that does not say OK. Delete the EXAMPLE rows before the plan is approved. Do not type over the white calculated columns. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Tailoring — small organisation: one plan for the whole organisation is enough, often under ten actions. Cost staff time where it competes with other work; otherwise enter 0 and say who does it.
Tailoring — regulated entity (NIS2, DORA): the plan is how treatment measures are identified, carried out and documented to bring ICT risk within the tolerance level (Delegated Regulation (EU) 2024/1774 Art 3(c)); keep each quarter's copy with the as-at date fixed. Where personal data is involved, record which actions give security appropriate to the risk to people (GDPR Art 32(1)).
Tailoring — IT run by a service provider: an action the provider delivers still has an owner in your organisation, who holds the provider to the date. Put the contract change or the provider's own plan in Dependencies.
EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. TA-01 is the €180,000 decision in the quarterly board report; TA-02 treats the payment fraud risk; TA-04 is done and brought R-04 back within appetite; TA-03 is at risk because the ordering platform team lost two engineers, but it is not overdue: it is due on 2026-10-31.
Plan Overview
Plan overview
What the plan is for, what it covers, when it is reviewed and who approved it. Yellow cells are yours; the EXAMPLE entries show a completed plan.
| As-at date | 30 Sep 2026 | EXAMPLE date (the example quarter end). Replace it with today's date, or type =TODAY(). |
Plan
| Item | Entry | |||
|---|---|---|---|---|
| Plan owner | [[e.g. Head of Information Security or CISO]] | |||
| Period covered | [[e.g. Q4 2026 to Q3 2027]] | |||
| Risks in scope | [[EXAMPLE: the risks in the Information Security Risk Register treated by Reduce, Avoid or Transfer that need action: R-01 and R-02, outside appetite; R-05, within appetite but slipping; and R-04, whose action TA-04 was done this quarter]] | |||
| Out of scope | [[e.g. risks treated by Accept (see the Risk Acceptance Form & Approval Record); projects funded elsewhere]] | |||
Objectives and measures of success
| Objective | Measure of success | Target date | Status | |
|---|---|---|---|---|
| [[Bring every risk outside appetite back within appetite (RMM-01)]] | [[EXAMPLE: R-01 and R-02 within appetite once TA-01 and TA-02 are done]] | 31 Dec 2026 | [[On track / At risk / Met]] | |
| [[Deliver actions on time (RMM-02)]] | [[Zero older than 30 days]] | [[Every quarter]] | [[On track / At risk / Met]] | |
| [[Keep risks within appetite from drifting]] | [[EXAMPLE: R-05 back to Low once TA-03 restores the patching deadline]] | 31 Oct 2026 | [[On track / At risk / Met]] | |
Review points
| When | Who | What is checked | ||
|---|---|---|---|---|
| [[Monthly]] | Head of Information Security with the action owners | Status and due dates; At risk and overdue actions; new actions | ||
| Every quarter (RM-09) | Each risk owner | That the expected residual is still right and the actions still the right ones | ||
| Every quarter (RM-12) | [[e.g. Executive Committee]] | Treatment progress and RMM-02, through the Risk Reporting Dashboard | ||
| On a trigger (RM-10) | Risk owner and assessor | Whether the plan still brings the risk back within appetite | ||
| When an action is done | Risk owner | The residual reached what was expected; the Information Security Risk Register is updated | ||
Approval of the plan and of the residual risk it leaves (RM-08)
| Risk owner | Risks and actions | Residual risk accepted when done | Approved by (name) | Date |
|---|---|---|---|---|
| [[EXAMPLE: Chief Operating Officer]] | [[R-01: TA-01]] | [[R-01 at 4 (Medium), within appetite]] | [[Name]] | [[YYYY-MM-DD]] |
| [[EXAMPLE: Chief Financial Officer]] | [[R-02: TA-02]] | [[R-02 at 6 (Medium), within appetite]] | [[Name]] | [[YYYY-MM-DD]] |
| [[EXAMPLE: Head of Logistics]] | [[R-04: TA-04]] | [[R-04 at 4 (Medium), within appetite]] | [[Name]] | [[YYYY-MM-DD]] |
| [[EXAMPLE: Head of IT]] | [[R-05: TA-03]] | [[R-05 at 3 (Low), within appetite]] | [[Name]] | [[YYYY-MM-DD]] |
| Funding over [[€ amount]]: [[e.g. Board, or its Audit & Risk Committee]] | [[EXAMPLE: TA-01, €180,000]] | [[Decision: approved / approved in part / not approved]] | [[Name]] | [[YYYY-MM-DD]] |
A residual risk left outside appetite is accepted by its band's approvers and executive management as well, never instead; outside tolerance, only the board or its equivalent (RM-08).
Actions
One row per treatment action (RM-07). Yellow columns are inputs; white columns calculate. Every colour sits beside a word.
| Example | Action ID | Risk ID | Risk | Appetite level | Treatment action | Action owner | Due date | Status | Completed on | One-off cost (€) | Running cost per year (€) | Dependencies | Current residual impact (1–4) | Current residual likelihood (1–4) | Current residual score | Current band | Current position | Expected residual impact (1–4) | Expected residual likelihood (1–4) | Expected residual score | Expected band | Expected position after | Days to due date | Overdue flag | Record check | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | TA-01 | R-01 | Ransomware takes online ordering offline for more than 2 days | Cautious | Rebuild the ordering platform's recovery so it can be restored within 24 hours | Head of IT | 15 Dec 2026 | Awaiting board approval | €180,000 | €20,000 | Board approval of the funding at the 2026-10-29 meeting; work must start before the November peak season | 4 | 2 | 8 | High | Outside appetite, within tolerance | 4 | 1 | 4 | Medium | Within appetite | 76 | OK | The decision in the quarterly board report: option A, done by 15 Dec 2026. Brings R-01 back within appetite | ||
| EXAMPLE | TA-02 | R-02 | Payment fraud through a compromised supplier email account | Cautious | Call-back verification of every change to supplier bank details, and a payment verification service | Chief Financial Officer | 30 Nov 2026 | In progress | €15,000 | Payment verification service chosen and contracted | 3 | 3 | 9 | High | Outside appetite, within tolerance | 3 | 2 | 6 | Medium | Within appetite | 61 | OK | ||||
| EXAMPLE | TA-04 | R-04 | Ransomware spreads from warehouse office PCs to warehouse systems | Cautious | Separate the warehouse networks from the office network at all three sites | Head of IT | 11 Sep 2026 | Done | 11 Sep 2026 | €28,000 | None | 2 | 2 | 4 | Medium | Within appetite | 2 | 2 | 4 | Medium | Within appetite | OK | Done: the last site was separated on 2026-09-09 and the separation tested on 2026-09-11. R-04 back within appetite at the quarter-end review | |||
| EXAMPLE | TA-03 | R-05 | Critical weaknesses on internet-facing systems exploited before they are fixed | Cautious | Bring the ordering platform's patching back to 95% within deadline after two engineers left | Head of IT | 31 Oct 2026 | At risk | €0 | Two engineer vacancies on the ordering platform team filled, or cover arranged with the managed IT provider | 3 | 2 | 6 | Medium | Within appetite | 3 | 1 | 3 | Low | Within appetite | 31 | OK | Not overdue at the as-at date, but at risk of missing its due date while the team is short of two engineers |
Funding & Timeline
Funding and timeline
Calculated from the Actions sheet as at the date on the Plan Overview sheet. Amounts in euros (€) in the EXAMPLE; use your own currency. Cancelled actions are left out.
The plan in figures
| Measure | Value | Target | Status | What it means | |||||
|---|---|---|---|---|---|---|---|---|---|
| Actions in the plan | 4 | Every action except cancelled ones. | |||||||
| Open actions | 3 | Not yet done. | |||||||
| One-off cost of the whole plan | €223,000 | Every action except cancelled ones, done or not. | |||||||
| of which open actions | €195,000 | Actions not yet done: what is still to be spent. | |||||||
| of which awaiting approval | €180,000 | Open actions whose funding has not yet been approved: the ask to take forward. | |||||||
| of which approved, under way or done | €43,000 | Everything in the whole plan that is not awaiting approval. | |||||||
| Running cost per year | €20,000 | What the plan adds to yearly budgets once the actions are done. | |||||||
| RMM-02 Treatment actions overdue | 0 | Open treatment actions past their due date. Calculated from the due date, never typed. | |||||||
| older than 30 days | 0 | Zero older than 30 days | On target | Escalate each to the risk owner and executive management. | |||||
| Actions at risk | 1 | Not overdue, but likely to miss the date unless something changes. Name each in the quarterly report. | |||||||
Cost and expected effect by risk
| Risk ID | Actions | One-off cost | Running cost per year | Residual today | Position today | Lowest expected score | Expected band | Expected position after | Last action due |
|---|---|---|---|---|---|---|---|---|---|
| R-01 | 1 | €180,000 | €20,000 | 8 (High) | Outside appetite, within tolerance | 4 | Medium | Within appetite | 15 Dec 2026 |
| R-02 | 1 | €15,000 | €0 | 9 (High) | Outside appetite, within tolerance | 6 | Medium | Within appetite | 30 Nov 2026 |
| R-04 | 1 | €28,000 | €0 | 4 (Medium) | Within appetite | 4 | Medium | Within appetite | 11 Sep 2026 |
| R-05 | 1 | €0 | €0 | 6 (Medium) | Within appetite | 3 | Low | Within appetite | 31 Oct 2026 |
| All risks | 4 | €223,000 | €20,000 | 15 Dec 2026 |
Type the Risk IDs in the yellow cells. Lowest expected score: the lowest residual expected by any of the risk's actions, which is the one expected when all are done.
Timeline: what falls due, by quarter
| Period | From | To | Open actions due | One-off cost due |
|---|---|---|---|---|
| Past due at the as-at date | 30 Sep 2026 | 0 | €0 | |
| Q4 2026 | 1 Oct 2026 | 31 Dec 2026 | 3 | €195,000 |
| Q1 2027 | 1 Jan 2027 | 31 Mar 2027 | 0 | €0 |
| Q2 2027 | 1 Apr 2027 | 30 Jun 2027 | 0 | €0 |
| Q3 2027 | 1 Jul 2027 | 30 Sep 2027 | 0 | €0 |
| Later | 1 Oct 2027 | 0 | €0 |
Past due counts open actions and their cost; each quarter counts open actions due, and the cost of every action due that is not cancelled. Quarters are calendar quarters after the as-at date.
Lists
| Level | Band | BandMinScore | AppetiteLevel | LevelAppetite | LevelTolerance | ActionStatus | Position |
|---|---|---|---|---|---|---|---|
| 1 | Low | 1 | Averse | Low | Medium | Not started | Within appetite |
| 2 | Medium | 4 | Cautious | Medium | High | Awaiting board approval | Outside appetite, within tolerance |
| 3 | High | 8 | Open | High | High | In progress | Outside tolerance |
| 4 | Critical | 12 | At risk |
Done
Cancelled
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Treatment | Reduce: change the likelihood or the impact with controls. Avoid: stop the activity that creates the risk. Transfer: share the impact with a third party, for example by insurance or contract; the risk owner still owns the risk. Accept: keep the residual risk knowingly, recorded and approved at the right level (Risk Acceptance Form). |
| Treatment action | A piece of work that changes a risk's likelihood or impact, with an owner, a due date, a cost and the residual expected when it is done (Treatment actions have an owner, a due date, a cost and the residual score expected when they are done). |
| Action ID | Your unique reference for the action, such as TA-01. The same ID goes in the register's Linked actions column. |
| Action owner | The person who delivers the action. [[whoever delivers a treatment action]] The risk owner stays accountable for the risk. |
| Status | Not started, Awaiting board approval, In progress, At risk, Done, Cancelled. Awaiting board approval: the action cannot start until its funding is approved. At risk: not overdue, but likely to miss its date. Overdue is never a status: it is calculated. |
| One-off cost, running cost | What the action costs to deliver, and what it adds each year once in place. Amounts in the examples are in euros (€); use your own currency. |
| Current residual | Today's residual impact, likelihood, score and band, copied from the Information Security Risk Register. |
| Expected residual | The residual impact and likelihood expected when this action, and any earlier action on the same risk, is done. |
| Band | Low: score 1–3; Medium: score 4–6; High: score 8–9; Critical: score 12–16. |
| Appetite level | Averse: appetite up to Low, tolerance up to Medium; Cautious: appetite up to Medium, tolerance up to High; Open: appetite up to High, tolerance up to High. |
| Position | Within appetite, Outside appetite, within tolerance or Outside tolerance: the band compared with the category's appetite and tolerance (RM-05). Expected position after uses the expected band. |
| Days to due date | Calendar days from the as-at date to the due date, for open actions. Negative once the date has passed. |
| Overdue flag | Overdue: an open action past its due date. Overdue more than 30 days: past it by more than 30 calendar days (RMM-02). |
| Record check | A calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding. |
| As-at date | The date days to due date and overdue are measured against. Set on the Plan Overview sheet. |
| EXAMPLE row | A worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. Delete before approval. |
| RM-nn, RMM-nn | Rule and measure numbers in the Risk Assessment Methodology & Scoring Model. |
| Likelihood, impact | The 1–4 scales in the Risk Assessment Methodology & Scoring Model: impact 1 Minor, 2 Moderate, 3 Major, 4 Severe; likelihood 1 Unlikely, 2 Possible, 3 Likely, 4 Almost certain. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 6.1.3 — Information security risk treatment | The plan as a whole: treatment options chosen, the actions they need, and the risk owners' approval of the plan and of the residual risk |
| ISO/IEC 27001:2022 | Clause 8.3 — Information security risk treatment | Status, due dates, overdue flag and completion: the plan carried out and its results kept as records |
| NIST CSF 2.0 | ID.RA-06 — “Risk responses are chosen, prioritized, planned, tracked, and communicated” | Actions with owners, dates, costs and expected residual; funding and timeline; review points |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 3(c) — a procedure to identify, implement and document treatment measures that bring ICT risk within the tolerance level | Actions and their expected position after: treatment measures identified, carried out and documented to bring risk within tolerance |
| GDPR — Regulation (EU) 2016/679 | Article 32(1) — appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the likelihood and severity of risk to people's rights and freedoms | Expected residual for risks involving personal data: measures chosen by the likelihood and severity of the risk |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)