Cyber Risk Assessment: How to Run One in Your Business

A cybersecurity risk assessment is a structured review of what a business holds, what could go wrong with it, how likely that is and what it would cost. The output is a ranked risk register with a named owner and a decision against every line.

A Timaru manufacturer was three weeks from signing the largest contract in its history when the customer’s procurement team asked for a cybersecurity risk assessment. The firm here is illustrative, though requests like it arrive at New Zealand businesses every week.

Most businesses meet the phrase for the first time in somebody else’s paperwork. An insurer asks for one at renewal, a corporate customer attaches it to a supplier questionnaire, or a bank asks before extending a facility.

Cybersecurity risk assessments arrive as somebody else’s requirement far more often than as an internal idea.

The request usually gets answered with a list of the security products the business already owns. A product list will not say what could go wrong, or what it would cost if it did.

A cybersecurity risk assessment starts from the other end. It asks what you would lose, then works back to what makes that loss likely, and it finishes with a decision against every line. What follows is that method step by step.

What Is a Cybersecurity Risk Assessment?

A cybersecurity risk assessment is the exercise of listing your assets, the threats that could reach them, the likelihood of each threat and the harm it would do, then giving every risk a treatment and an owner.

The cybersecurity risk assessment method is settled and public. NIST Special Publication 800-30 Revision 1, the Guide for Conducting Risk Assessments, sets out the same sequence that commercial frameworks use, and it has been the reference version since September 2012, when it superseded the 2002 original.

The distinction that matters is between a control list and a risk list. A control list says what you have. A risk list says what you would lose, ranked, so the next dollar goes to the largest exposure.

You do not need the full apparatus of a cybersecurity risk assessment to get the value. A business of twenty to fifty people can produce a defensible register in a couple of days if somebody owns the work.

What should the finished assessment contain?

A risk register, a short covering note and a list of decisions. People ask to see the register, and nothing improves until the decisions against each line are made and dated.

Anything that reads as a list of technical findings with no owner and no decision has stopped short. A finding is an observation. Add a consequence, a likelihood and a name against it and you have a risk.

How Is a Cybersecurity Risk Assessment Different From a Security Audit or a Penetration Test?

The three answer different questions, and businesses buy the wrong one often enough that it is worth being precise.

A cybersecurity risk assessment asks what could go wrong and what it would cost. A security audit asks whether your existing controls meet a defined standard. A penetration test asks whether a specific system can be broken into in practice.

The order matters. A cybersecurity risk assessment tells you which systems are worth testing, so running a penetration test first tends to produce a technically accurate report about something that was never the biggest exposure.

Which one does an insurer or a customer usually want?

Read the wording of the request before commissioning anything. A supplier questionnaire asking how you identify and prioritise risk wants a cybersecurity risk assessment, and a clause naming a standard wants an audit against that standard.

Where the request is ambiguous, ask the person who sent it what decision they are making with the answer, because the reply usually names the document they need from you.

Do you need all three?

Not at once, and not in any order. Most businesses start with the cybersecurity risk assessment, because it is the cheapest of the three and it shows where the other two would be worth spending.

A sequence that works: assess the risk, fix what the register puts at the top, then audit against a standard once a customer or an insurer asks for that specific evidence. Testing comes last, aimed at whichever system the register says would hurt most.

Which Assets Does a Cybersecurity Risk Assessment Cover?

Every cybersecurity risk assessment asset list starts with the information before the equipment, because a breach exposes information and the law attaches duties to it.

Write down where customer records, staff records, financial data and anything covered by a contract lives, then list the systems that hold or reach each of those.

The gap in almost every first cybersecurity risk assessment is the same. The list covers what the business bought centrally and misses what individual people signed up for.

  • Email and file storage, and everything in the same tenancy
  • The finance system, payroll and anything connected to either
  • The line-of-business system the work runs through
  • Backups, and the separate question of where they are held
  • Every supplier with remote access into any of the above
  • Subscriptions bought on personal or company cards outside the main tenancy

That last line is worth an hour of somebody’s time with the card statements. It reliably finds systems holding customer data that nobody had counted, and those are usually the ones with no multi-factor authentication on them.

What about information you hold for somebody else?

Put it on the list and mark whose it is. A business holding client records under a contract carries the consequence of losing them, and the contract often says so in stronger terms than the law does.

Those lines tend to score highest on harm. The client whose records you lost is the one who decides what happens next.

How detailed does the asset list need to be?

Detailed enough that each line has one owner and one decision. A line reading cloud services cannot be scored, because it covers a dozen different exposures, and going down to individual laptops produces a register nobody maintains.

Keeping the list current afterwards matters more than getting it perfect first time. A register nobody updates describes the business as it was on the day of the assessment.

How Do You Identify the Threats That Apply to Your Business?

A cybersecurity risk assessment threat list starts from what has happened to businesses like yours, then adds the threats specific to how you operate.

For most New Zealand SMEs the realistic list is short:

  • Credential theft through phishing
  • Ransomware
  • Invoice fraud through a compromised mailbox
  • A breach at a supplier with access to your systems
  • A lost or stolen device
  • Staff error

Then add your own circumstances. A firm with one server room in a flood-prone building carries a threat a cloud-only firm does not, and a business whose staff work from personal machines carries another.

Should you include threats you cannot do anything about?

Yes, and mark them as accepted with a reason. A risk you have consciously accepted is a decision, and an insurer or a customer can see that you made it.

A risk left off the register reads as an oversight, and a reader has no way to know it was a choice.

How Do You Score Likelihood and Impact?

Score each risk on how likely it is and how much harm it would do, then rank by the two together. Plotted against each other the two scores give you a risk matrix, and three or four steps on each axis is enough, because a five-step scale invites argument about the middle.

Cybersecurity risk assessment grid scoring likelihood against harm with five plotted risks

New Zealand businesses have a statutory version of the harm question worth borrowing. Section 113 of the Privacy Act 2020 lists what an agency must consider when deciding whether a privacy breach is likely to cause serious harm, including how sensitive the information is, the nature of the harm, who now has the information and whether it is protected.

Those factors make a defensible impact scale for anything involving personal information, and they are the ones you would be judged against afterwards.

Work out what a fortnight of not trading would cost your business before you score anything. That figure is the only one on the register that belongs to you, and every impact score should be sensible against it.

How do you keep the scoring honest?

A cybersecurity risk assessment scores the risk before your controls and again after them, and records both. The gap between the two shows what your security spending has bought.

Have somebody other than the person who owns the system do the scoring, or at least review it, because owners tend to score their own areas optimistically.

What is residual risk?

Residual risk is what remains after your controls work as intended. Report and accept the residual figure, because the pre-control score describes a business you do not run.

What counts as a high risk?

Anything where a likely threat meets a serious consequence, and anything where the consequence is severe even at low likelihood.

A rare event that would stop trading for a fortnight belongs near the top of the register whatever its likelihood score says.

What Does a Risk Register Look Like?

A cybersecurity risk assessment produces a risk register, a table with one row per risk, scored and owned. The example below is illustrative, and the shape matters more than the wording.

Risk What it reaches Likelihood Harm Treatment and owner
A staff mailbox is compromised through phishing Email, and every client record attached to it Likely Serious Mitigate: phishing-resistant multi-factor authentication on every account. Owner: IT provider
Ransomware encrypts the file server and the backup beside it Shared drives and job records Possible Severe Mitigate: a copy held offsite that cannot be altered. Owner: operations manager
A leaver keeps access to an app bought on a personal card Whatever that subscription holds Likely Moderate Mitigate: a leavers checklist that covers subscriptions outside the tenancy. Owner: office manager
A supplier with remote access is breached Anything that supplier can reach Unlikely Severe Transfer: notification terms in the contract, plus insurance. Owner: general manager
A laptop is lost with local copies of client files Client personal information Possible Serious Mitigate: disk encryption enforced centrally. Owner: IT provider

A register stays usable a year later when every line names a person, carries a date and shows a version.

Who should be able to open the register?

The owner of the business, the person who runs operations and whoever provides your IT. A board discussion or a customer request will not wait for the IT provider to email a file.

Keep a copy somewhere that survives the loss of the systems it describes, because a copy on the file server goes down with the file server.

What Do You Do With Each Risk Once It Is Scored?

Choose one of four treatments for every line, and write down which one you chose: mitigate, transfer, avoid or accept.

  • Mitigate: put a control in place that lowers the likelihood or the harm, and re-score afterwards
  • Transfer: move the financial consequence to somebody else, usually through insurance or a contract term
  • Avoid: stop doing the thing that creates the risk, which is occasionally the cheapest answer
  • Accept: decide the risk is tolerable, record who decided and when, and review it on a date
Cybersecurity risk assessment diagram of the four risk treatments: mitigate, transfer, avoid and accept

Most of the work lands on mitigation. Two of them produce documents: an incident response plan limits harm once something has started, and a business continuity plan keeps the business trading while you deal with it.

Three high risks closed this quarter is a better outcome than twenty risks with a plan against each and nothing done.

Does insurance count as a treatment?

Yes, for the financial consequence, and only for what the policy covers. Insurance has no effect on how likely the event is, and a payout has never repaired a customer relationship.

Read the policy conditions against your register before relying on transfer. Cover often depends on controls the register may show you do not have.

Who Needs to Be Involved in a Cybersecurity Risk Assessment?

A cybersecurity risk assessment needs three kinds of input: somebody who can make decisions, somebody who knows how the work gets done in practice, and somebody technical. Most failed attempts are missing the second of the three, because the exercise gets handed to whoever is most technical.

The owner or general manager sets what counts as serious harm, because that is a commercial judgement. Operations staff know the workarounds, the shared logins and the system everybody says is temporary.

The technical input can come from an internal person or a provider. It cannot run the whole exercise alone, since a register written entirely by technical people scores technical risks highly and business process risks barely at all.

The time commitment is smaller than people expect and unevenly spread. An hour each from three or four staff, half a day from whoever owns the exercise, and a couple of hours from the technical side.

Can a business do this without outside help?

Yes, and the first pass of a cybersecurity risk assessment is worth doing internally whatever you decide afterwards. Working through your own asset list surfaces things no external reviewer would think to ask about.

Bringing somebody in helps with the scoring and with what a customer or insurer will accept. Our guide to commissioning a cyber security assessment covers choosing a provider and scoping the work.

How Often Should a Cybersecurity Risk Assessment Be Repeated?

Once a year for most businesses, and again after anything that changes the shape of the organisation. An annual cycle keeps the register close enough to reality to be worth reading.

Four events should trigger a review regardless of the calendar. A new system holding customer data, a move to new premises, an acquisition, and any incident or near miss.

A review is not a rerun. Re-score the existing lines, close what has been dealt with, and add what is new.

What is the reporting duty if something happens in the meantime?

Under section 114 of the Privacy Act 2020 an agency must notify the Privacy Commissioner as soon as practicable after becoming aware that a notifiable privacy breach has occurred. Affected individuals must be told as well, subject to the exceptions in the Act.

The Office of the Privacy Commissioner puts a working figure on that. Its guidance for agencies says that ideally you will notify within 72 hours of becoming aware you have a notifiable breach, even while you are still investigating.

Seventy-two hours is not long to work out who to tell and what to say. Deciding it in advance is one of the cheaper lines on any register.

What Does a Cybersecurity Risk Assessment Cost?

A cybersecurity risk assessment is quoted after scoping, because it scales with the size of the environment and not with headcount, and four things move the figure.

  • How many systems and sites are in scope, and whether an asset list already exists
  • How many people need to be interviewed to understand how the work is done
  • Whether the output has to satisfy a named standard or a customer’s own template
  • Whether you want the remediation planned as part of the engagement or handled separately

What a cybersecurity risk assessment should get you for the money is short and specific. A register you can open and edit, a covering note a non-technical reader can follow, and an order of work with the highest-scoring risks at the top.

Working through your own asset list and scoring it internally gets a business a long way toward a first cybersecurity risk assessment register, and it shortens any later engagement.

If you would rather start with a picture of the whole environment, an IT assessment is free and covers what you are running as well as how well it is defended. Where you want it run properly, our cyber security team does that alongside the wider IT risk management picture.

The Timaru manufacturer took nine days to produce its first cybersecurity risk assessment register, most of that spent finding the systems nobody had counted, and the procurement team accepted it as it was.

Find Out Which Risks Your Business Has Never Scored

Exodesk has supported South Island businesses since 1989 and works with clients across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. We build the asset list with you, score each risk against a scale you can defend, and hand over a register with a named owner on every line.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Frequently Asked Questions

Is a cyber risk assessment the same as a cybersecurity risk assessment?

Yes. Cybersecurity risk assessment, cyber security risk assessment and cyber risk assessment all name the same exercise, and providers use the three interchangeably. This page uses the shortest form throughout. The method behind all three names is the one set out above.

What is the difference between a risk assessment and a security audit?

A risk assessment asks what could go wrong in your business and what the consequences would be. An audit checks existing controls against a defined standard and reports where they fall short. Most businesses want the cybersecurity risk assessment first, because it establishes which controls are worth auditing.

How long does a cybersecurity risk assessment take?

For a business of twenty to fifty people, expect a couple of days of effort spread across two or three weeks. The bulk of that time goes on building the asset list and talking to staff. Repeat rounds are quicker, because the register already exists and only needs re-scoring.

What is a risk register?

A risk register is the table the exercise produces. One row per risk, recording what it would affect, how likely it is, how much harm it would do, the treatment chosen and the person responsible. Every line needs a date so a reader can judge how current it is, since an undated register cannot be shown to anybody as evidence.

How do you score cyber risk?

Score each entry on likelihood and on harm, then rank by the two together, keeping the scale to three or four steps. Where personal information is involved, section 113 of the Privacy Act 2020 lists the factors used to judge whether a breach is likely to cause serious harm. Those factors make a defensible basis for the harm side of the scale.

What are the four ways to treat a risk?

Mitigate, transfer, avoid and accept. Mitigating adds a control that lowers likelihood or harm, transferring moves the financial consequence through insurance or a contract term, avoiding stops the activity altogether, and accepting records that the risk is tolerable together with who decided and when.

What triggers a review outside the annual cycle?

A new system holding customer data, a change of premises, an acquisition, or any incident or near miss. Each of those changes the shape of what you are protecting, so the register stops describing the business until it is re-scored.

Do small businesses in New Zealand need a cybersecurity risk assessment?

Yes, and often somebody else asks for it first. Insurers raise it at renewal, corporate customers attach it to supplier questionnaires, and the Privacy Act 2020 applies to a business of any size that holds personal information.

Who should carry out a cybersecurity risk assessment?

It needs three kinds of input: somebody who can make commercial decisions about what counts as serious harm, somebody who knows how the work is done day to day, and somebody technical. A first pass done in-house is worthwhile whatever you decide afterwards. Outside help is worth paying for on the scoring and on what a customer or insurer will accept.

How much does a cybersecurity risk assessment cost in New Zealand?

It is quoted after scoping. The number of systems and sites in scope drives the figure, along with whether you already hold an asset list and how many staff need interviewing. A first pass run internally costs nothing but time and shortens any later engagement.

What has to be reported if a breach happens?

Two duties apply. The Privacy Commissioner must be told as soon as practicable once you know a breach is notifiable, and affected individuals must be told as well unless one of the exceptions in the Act applies. The Commissioner’s guidance for agencies sets a working target of 72 hours from becoming aware, even while the investigation is still open.

Next step

Which of your risks has nobody scored?

The subscription somebody bought on a personal card, the backup sitting on the same network as the file server, the supplier who still has remote access. An IT assessment finds what you are running and how well it is defended, which is the asset list a register needs before anything can be scored.

Or read more about our cyber security services.

Start typing and press Enter to search

Zinform Accounting SoftwareCybersecurity training for employees -- flat vector of trained NZ business staff deflecting AI-powered cyber threats as confident defenders Call Us Now