Back to blog
Templates

Cybersecurity risk assessment template (and how to use it)

A reusable cybersecurity risk assessment template - the exact fields to capture, how to score likelihood and impact consistently, and how to turn the output into a defensible risk treatment plan.
GRC Copilot Team
Cybersecurity risk assessment template (and how to use it)

A cybersecurity risk assessment template turns an abstract worry into a scored, owned, trackable record. Every major framework - ISO 27001, NCA ECC, SAMA CSF, SOC 2 - requires a documented risk assessment, and auditors care as much about the method being consistent as they do about the individual scores.

The fields your template needs

  • Risk ID - a stable, unique reference.
  • Asset or process affected - what is at stake.
  • Threat - what could go wrong (ransomware, insider misuse, supplier outage).
  • Vulnerability - the weakness the threat would exploit.
  • Existing controls - what already reduces this risk.
  • Likelihood (1-5) - how probable, given existing controls.
  • Impact (1-5) - the consequence if it happened.
  • Inherent risk score - likelihood multiplied by impact, before new treatment.
  • Risk owner - a named person, never a team or a department.
  • Treatment decision - mitigate, transfer, avoid or accept.
  • Treatment actions, owner and due date.
  • Residual risk score - the expected score once treatment lands.
  • Review date and status.

Scoring that stays consistent

The most common failure in risk assessment is that two people score the same risk differently. Fix that by defining the scale in words before you score anything.

Likelihood

  • 1 Rare - not expected within five years.
  • 2 Unlikely - possible within three to five years.
  • 3 Possible - plausible within a year.
  • 4 Likely - expected within a year.
  • 5 Almost certain - expected within months, or already occurring.

Impact

  • 1 Negligible - absorbed in normal operations.
  • 2 Minor - limited disruption, no reportable consequence.
  • 3 Moderate - service degradation or limited data exposure.
  • 4 Major - regulatory reporting, significant financial or customer impact.
  • 5 Severe - critical service loss, major breach, licence or reputational damage.

Score likelihood after accounting for existing controls, and define your risk appetite up front - for example, treat anything scoring 15 or above, and require executive sign-off to accept anything above 9.

Skip the spreadsheet

GRC Copilot generates a risk assessment from your environment, scores each risk with a consistent method, links risks to the controls that mitigate them, and tracks treatment to closure.

How to run the assessment

  1. Set scope - the systems, processes and business units covered.
  2. Inventory assets and identify which matter most to the business.
  3. Identify risks through workshops, incident history, threat intelligence and control gaps.
  4. Score consistently using your published scales.
  5. Decide treatment and assign a named owner and a date.
  6. Record residual risk and obtain owner acceptance in writing.
  7. Review on a cycle and whenever something material changes.
A risk assessment reviewed once a year is a compliance artefact. A risk assessment reviewed when systems, suppliers or threats change is a management tool.

Frequently asked questions

Qualitative or quantitative scoring?

Qualitative 5x5 scoring is sufficient for most organisations and is what auditors expect. Quantitative methods add value where you need to justify large investments in financial terms.

How often should we reassess?

At least annually for the full register, and immediately upon significant change - a new system, a new supplier, a major incident, or an acquisition.

Who should own a risk?

A named individual with the authority to accept or fund treatment. Assigning a risk to "IT" makes it nobody's responsibility.

What is the difference between inherent and residual risk?

Inherent risk is the score before planned treatment; residual risk is the expected score after it. Auditors want to see both, plus documented acceptance of the residual level.

Key takeaways

  • Define your likelihood and impact scales in words before scoring anything.
  • Every risk needs a named human owner and a review date.
  • Record both inherent and residual risk, with written acceptance.
  • Set risk appetite thresholds so treatment decisions are not ad hoc.
#risk-assessment #template #cybersecurity #methodology #iso27001