| A cyber risk assessment is a structured review of what a business relies on, what could go wrong with it, how likely that is and what it would cost. It takes account of the controls already operating, not just the products you own. The output is a ranked risk register with a named business owner and a dated decision against every line. |
A cyber risk assessment identifies how threats and weaknesses could affect your business, estimates how likely each one is and what the consequences would be, and helps you decide what to do first. It takes account of the protection already in place rather than listing the security products you own.
Most businesses meet the phrase for the first time in somebody else’s paperwork. An insurer asks for one at renewal, a corporate customer attaches it to a supplier questionnaire, or a bank asks before extending a facility.
Cyber risk assessments arrive as somebody else’s requirement far more often than as an internal idea.
The request usually gets answered with a list of the security products the business already owns. A product list will not say what could go wrong, which weakness makes it possible, or what it would cost if it did.
A cyber risk assessment starts from the other end. It asks what you would lose, works back to the weakness that makes the loss possible, and finishes with a dated decision and a named owner against every line. What follows is that method step by step.
What Is a Cyber Risk Assessment?
A cyber risk assessment is the exercise of agreeing what is in scope, listing what the business relies on, describing what could go wrong and the weakness that makes it possible, checking which controls are actually operating, then scoring each risk and giving it a treatment and an owner.
The method is settled and public. NIST Special Publication 800-30 Revision 1, the Guide for Conducting Risk Assessments, sets out the same sequence that commercial frameworks use, and it has been the reference version since September 2012, when it superseded the 2002 original.
The distinction that matters is between a control list and a risk list. A control list says what you have. A risk list says what you would lose, ranked, so the next dollar goes to the largest exposure.
You do not need a formal risk programme to get the value from a cyber risk assessment. A smaller business can produce a defensible register once somebody owns the work, and how long that takes depends on how many systems are in scope and how much of it is already written down.
What should the finished assessment contain?
A risk register, a short covering note and a list of decisions. People ask to see the register, and nothing improves until the decisions against each line are made and dated.
Anything that reads as a list of technical findings with no owner and no decision has stopped short. A finding is an observation. Add a consequence, a likelihood and a name against it and you have a risk.
How Do You Carry Out a Cyber Risk Assessment?
In six steps, and the first two are the ones most first attempts skip.
Steps three and four are what separate a cyber risk assessment from a list of things that happen to businesses. A threat becomes a risk only once you can name the exposure that lets it reach you and the consequence if it does.
What turns a threat into a business risk?
Describe the event, the exposure and the consequence in one line. An unused supplier account with broad access could be taken over and used to interrupt order processing is a risk. Supplier compromise on its own is a category.
Then record what already reduces it and what you remain uncertain about. Both change the rating, and both are the first things a reader will ask about.
How Is a Cyber Risk Assessment Different From a Security Audit or a Penetration Test?
The three answer different questions, and businesses buy the wrong one often enough that it is worth being precise.
A cyber risk assessment asks what could go wrong and what it would cost. A security audit checks existing controls against defined criteria. A penetration test examines exploitable weaknesses within an agreed scope.
The three inform each other. A cyber risk assessment helps you prioritise what needs closer examination, and findings from an audit or a test feed back into the assessment. Choose the scope and the timing around the decision you actually need to make.
Which one does an insurer or a customer usually want?
Read the wording of the request before commissioning anything. A supplier questionnaire asking how you identify and prioritise risk wants a cyber risk assessment. Where a customer names a framework, confirm whether they want a self-assessment, an independent audit, a certification or something else, because a reference to a standard does not automatically mean an audit is required.
Where the request is ambiguous, ask the person who sent it what decision they are making with the answer, because the reply usually names the document they need from you.
Do you need all three?
Not at once, and there is no fixed order. Starting with the cyber risk assessment usually makes sense, because it shows where the other two would be worth spending.
A sequence that often works: assess the risk, fix what the register puts at the top, then audit against a standard once a customer or an insurer asks for that evidence, with testing aimed at whichever system the register says would hurt most. It is not the only workable sequence. A contract deadline or an imminent system launch can require testing before the broader review is finished.
Which Assets Does a Cyber Risk Assessment Cover?
Start with the business services you rely on to trade, then the information behind them. A manufacturer can lose a fortnight of production without a single customer record being disclosed, so an asset list built only around personal information misses half the exposure.
Write down where customer records, staff records, financial data and anything covered by a contract lives, then list the systems that hold or reach each of those. Include the ones that hold no records of their own but stop everything when they fail: identity and sign-on, internet connectivity, and any operational technology on a plant or site.
The gap in almost every first cyber risk assessment is the same. The list covers what the business bought centrally and misses what individual people signed up for.
- Email and file storage, and everything in the same tenancy
- The finance system, payroll and anything connected to either
- The line-of-business system the work runs through
- Backups, and the separate question of where they are held
- Every supplier with remote access into any of the above
- Subscriptions bought on personal or company cards outside the main tenancy
That last line is worth going through with the people who actually use the tools, not only with the card statements. Statements miss free tools, integrations added inside another product, and anything billed through a third party. It reliably finds systems holding customer data that nobody had counted, and those are usually the ones with no multi-factor authentication on them.
What about information you hold for somebody else?
Put it on the list and mark whose it is. A business holding client records under a contract carries the consequence of losing them, and the contract often says so in stronger terms than the law does.
Score them on their own facts: how sensitive the information is, how quickly the client needs it back, and what the contract already commits you to. The client whose records you lost is the one who decides what happens next.
How detailed does the asset list need to be?
Detailed enough that each line has one owner and one decision. A line reading cloud services cannot be scored, because it covers a dozen different exposures, and going down to individual laptops produces a register nobody maintains. Keep the two lists separate. An asset inventory can identify every device; the register groups similar ones so the risks stay readable, and one system can carry several risks while one risk can span several systems.
Keeping the list current afterwards matters more than getting it perfect first time. A register nobody updates describes the business as it was on the day of the assessment.
How Do You Identify the Threats That Apply to Your Business?
A cyber risk assessment threat list starts from what has happened to businesses like yours, then adds the threats specific to how you operate.
For most New Zealand SMEs the realistic list is short:
- Credential theft through phishing
- Ransomware
- Invoice fraud through a compromised mailbox
- A breach at a supplier with access to your systems
- A lost or stolen device
- Staff error
Then add your own circumstances. A firm with one server room in a flood-prone building carries a threat a cloud-only firm does not, and a business whose staff work from personal machines carries another.
Should you include threats you cannot do anything about?
Yes, put them on the register. Whether they end up accepted is a separate decision and not an automatic one. Even where you cannot prevent an event, you can often limit its impact or reduce how much the business depends on the affected service, and that belongs on the line before anyone reaches for acceptance.
A risk left off the register reads as an oversight, and a reader has no way to know it was a choice.
How Do You Score Likelihood and Impact?
Agree the scale and the period being assessed before you score anything. Then estimate how likely the described event is to cause harm given the exposure and the controls operating today, and assess the consequences for operations, money, people, information and the commitments you have made contractually. Plotted against each other the two scores give you a risk matrix. Three, four or five steps on each axis can all work, including the five-level scale NIST itself uses. The test that matters is whether two different people reading your definitions arrive at the same rating.

New Zealand businesses have a statutory version of the harm question worth borrowing. Section 113 of the Privacy Act 2020 lists what an agency must consider when deciding whether a privacy breach is likely to cause serious harm, including how sensitive the information is, the nature of the harm, who now has the information and whether it is protected.
Those factors are a sound basis for the harm side of the scale wherever personal information is involved. Keep the boundary clear, though. Section 113 exists to decide whether a breach has to be notified, and that is a legal threshold. A low score on your own register does not settle it, and an actual breach has to be assessed against the Act separately.
Work out what interruption actually costs you, using recovery scenarios that fit each service rather than one assumed outage length applied to everything. A figure of that kind is the only one on the register that belongs to you, and every impact score should be sensible against it.
How do you keep the scoring honest?
Score against the controls operating today, and write down the main reasons for the rating along with anything uncertain enough to change the decision. Where you also record the position before controls, say what you assumed to estimate it.
Have somebody other than the person who owns the system do the scoring, or at least review it, because owners tend to score their own areas optimistically. Escalate a potentially catastrophic consequence even where the likelihood is low, rather than quietly substituting a different rule for that one line.
What is residual risk?
Residual risk is what remains once controls are applied. Label the current rating and any target rating separately, because a planned control is not yet an operating one. Re-score the line after the change is implemented and somebody has checked that it works, and treat the reduced figure as an estimate rather than proof of what the spending bought.
What counts as a high risk?
Anything where a likely threat meets a serious consequence, and anything where the consequence is severe even at low likelihood.
A rare event that would stop the business trading belongs near the top of the register whatever its likelihood score says, and it should be escalated rather than averaged away.
What Does a Risk Register Look Like?
A cyber risk assessment produces a risk register: one entry per risk, scored against the controls operating today and owned by somebody who can decide about it. The five below are illustrative and tied to the assumptions recorded in each one, so read the shape rather than the wording.
A register stays usable a year later when every entry names a business owner and an action owner, carries a due date and a review date, shows the status of the work, and labels any target rating as a target. In a spreadsheet those become columns. On a page they read better as records, because a risk is a short story about one thing that could happen and not a row of numbers.
Who should be able to open the register?
The owner of the business, the person who runs operations and whoever provides your IT. A board discussion or a customer request will not wait for the IT provider to email a file.
Keep a copy somewhere that survives the loss of the systems it describes, because a copy on the file server goes down with the file server.
What Do You Do With Each Risk Once It Is Scored?
Four responses are available, and a line can need more than one of them. Write down which you chose and why: reduce, transfer, avoid or accept.
- Reduce: put a control in place that lowers the likelihood or the impact, then re-score once it is operating
- Transfer: move some of the financial consequence, usually through insurance or a contractual allocation, and only to the extent the terms actually cover
- Avoid: stop the activity, or change what the business depends on, which is occasionally the cheapest answer
- Accept: an authorised decision that the remaining exposure is tolerable, with a recorded reason, a named decision-maker and a review date

Most of the work lands on reduction, and where you cannot stop an event you can often limit what it costs. Two documents do that work: an incident response plan limits harm once something has started, and a business continuity plan keeps the business trading while you deal with it. A business impact analysis is what tells you how long each service can actually be down before the consequences bite.
Three high risks closed this quarter is a better outcome than twenty risks with a plan against each and nothing done. Accountability for the decision sits with somebody in the business who has the authority to accept exposure. An IT provider can own an implementation task and advise on the rating; it cannot decide what operational risk the business is willing to carry. Anything outside the agreed tolerance goes up rather than being settled on the line.
Does insurance count as a treatment?
For part of the financial consequence, and only for what the policy covers. Insurance has no effect on how likely the event is, and a payout has never repaired a customer relationship. It is rarely the whole answer to a line on its own.
Read the policy conditions against your register before relying on transfer. Cover often depends on controls the register may show you do not have.
Who Needs to Be Involved in a Cyber Risk Assessment?
A cyber risk assessment needs three kinds of input: somebody who can make decisions and accept exposure, somebody who knows how the work gets done in practice, and somebody technical. Most failed attempts are missing the second of the three, because the exercise gets handed to whoever is most technical.
The owner or general manager sets the commercial tolerance, deciding what level of exposure the business will carry. That is a business judgement, and it is separate from the statutory question of serious harm under the Privacy Act, which a manager cannot redefine. Operations staff know the workarounds, the shared logins and the system everybody says is temporary.
The technical input can come from an internal person or a provider. It cannot run the whole exercise alone, since a register written entirely by technical people scores technical risks highly and business process risks barely at all.
The time commitment is unevenly spread. Most of it falls on whoever owns the exercise, with shorter contributions from the people who run the affected work and from the technical side. The total depends on how many systems are in scope and how much is already documented.
Can a business do this without outside help?
Yes, and the first pass of a cyber risk assessment is worth doing internally whatever you decide afterwards. Working through your own asset list surfaces things no external reviewer would think to ask about.
Bringing somebody in helps with the scoring and with what a customer or insurer will accept. Our guide to commissioning a cyber security assessment covers choosing a provider and scoping the work.
How Often Should a Cyber Risk Assessment Be Repeated?
Set a cycle that suits your risks and your obligations. An annual formal review is a reasonable starting point for most businesses, with more frequent checks on the significant risks and on anything overdue.
Some events should trigger a review of the affected entries regardless of the calendar. A new or changed system, a new supplier or a change to what an existing one can reach, a shift in the threats aimed at your sector, a control that has been added or has stopped working, a change to what the business actually does, and any incident or near miss.
A review is not a rerun. Re-score the existing lines, add what is new, and be careful about closing things. Completing an action does not necessarily close the risk, because the underlying exposure often continues at a lower level and still needs watching.
What is the reporting duty if something happens in the meantime?
A breach is notifiable where it is reasonable to believe it has caused serious harm to someone, or is likely to. Under section 114 of the Privacy Act 2020 an agency must then notify the Privacy Commissioner as soon as practicable after becoming aware of it. Affected individuals must be told as soon as practicable too, subject to the exceptions in the Act.
The Office of the Privacy Commissioner puts a working figure on that. Its guidance for agencies says that ideally you will notify within 72 hours of becoming aware you have a notifiable breach, even while you are still investigating.
The 72 hours is guidance intended to encourage prompt reporting, not permission to wait until the third day. Working out in advance who makes the call and what gets said is one of the more useful lines on any register.
What Does a Cyber Risk Assessment Cost?
A cyber risk assessment is quoted after scoping, because the effort follows the scope and the state of the environment rather than headcount. Four things move the figure.
- How many systems and sites are in scope, and whether an asset list already exists
- How many people need to be interviewed to understand how the work is done
- Whether the output has to satisfy a named standard or a customer’s own template
- Whether you want the remediation planned as part of the engagement or handled separately
What it should get you for the money is short and specific. A register you can open and edit, a covering note a non-technical reader can follow, and an order of work with the highest-scoring risks at the top.
Working through your own asset list and scoring it internally gets a business a long way toward a first cyber risk assessment register, and it shortens any later engagement. It still uses staff capacity, which is a real cost even where no invoice follows.
Where you want it run properly, our cyber security team does that alongside the wider IT risk management picture. Our guide to commissioning a cyber security assessment covers choosing a provider and scoping the work.
Frequently Asked Questions
Is a cyber risk assessment the same as a cybersecurity risk assessment?
In this guide they mean the same review of threats, weaknesses and possible business consequences. Providers use assessment labels differently, so confirm the scope and the intended output when you commission work rather than relying on the name.
What is the difference between a risk assessment and a security audit?
A risk assessment asks what could go wrong in your business and what the consequences would be. An audit checks existing controls against defined criteria and reports where they fall short. Starting with the assessment usually makes sense, because it shows which controls are worth auditing, and findings from an audit feed back into the assessment.
How long does a cyber risk assessment take?
It depends on the systems and processes in scope, the information already available, and how deeply the controls need to be checked. Agree the effort and the timetable after scoping rather than before. Updating an existing assessment takes less work where its inventory and records are current.
What is a risk register?
A risk register is the table the exercise produces. Each row records the scenario and the service it affects, the controls operating today, the likelihood and impact ratings and the reasoning behind them, the decision taken, the business owner and the action owner, the due date and the review status. Keep current and target ratings clearly labelled, and date every line, because an undated register cannot be shown to anybody as evidence.
How do you score cyber risk?
Use agreed likelihood and impact definitions over a stated period, consider the controls actually operating, and write down the assumptions behind each rating. Rank against the tolerance the business has set, escalating severe consequences and significant uncertainty rather than averaging them away. Where personal information is involved, section 113 of the Privacy Act 2020 lists useful factors for the harm side, though it exists to decide whether a breach is notifiable and does not settle that question from your own score.
What are the options for treating a risk?
Reduce it with controls, avoid the activity, transfer some of the financial consequence, or accept the remaining exposure through an authorised decision. A single line can need more than one of these. Record the decision, the reason and the review date, and revisit it as circumstances change.
What triggers a review outside the annual cycle?
A new or changed system, a new supplier or a change to what an existing one can reach, a control that has been added or has stopped working, a shift in the threats aimed at your sector, a change to what the business does, or any incident or near miss. Each changes the shape of what you are protecting, so the affected entries stop describing the business until they are re-scored.
Do small businesses in New Zealand need a cyber risk assessment?
An assessment helps a small business decide where protection is needed, and often somebody else asks for one first. Insurers raise it at renewal and corporate customers attach it to supplier questionnaires. The Privacy Act 2020 requires reasonable safeguards for personal information at any size, though it does not prescribe one assessment format for every business.
Who should take part in a cyber risk assessment?
A business decision-maker with the authority to accept exposure, people who understand how the work is done day to day, and somebody with suitable technical knowledge. Agree who owns each risk and who can approve accepting one. A first pass done in-house is worthwhile whatever you decide afterwards, and specialist input helps where the systems or the requirements call for it.
How much does a cyber risk assessment cost in New Zealand?
It is quoted after scoping. Cost follows the scope, the complexity of the environment, how much information already exists and how deep the review needs to go. Confirm what is included, what you will receive, and whether help with the resulting actions forms part of the engagement. Internal work uses staff capacity, which is a real cost too.
What has to be reported if a breach happens?
Two duties apply. The Privacy Commissioner must be told as soon as practicable once you know a breach is notifiable, meaning you have reasonable grounds to believe it has caused serious harm or is likely to. Affected individuals must be told as soon as practicable as well, unless one of the exceptions in the Act applies. The Commissioner’s guidance sets a working target of 72 hours from becoming aware, which encourages promptness rather than permitting delay.
Next step
Turn your cyber risks into clear priorities
The subscription somebody bought on a personal card, the backup sitting on the same network as the file server, the supplier who still has remote access. Talk to us about the risks affecting your business and the scope of an assessment that would be useful. We can clarify the technical side and agree the next steps with the people accountable for the business.
For a broader starting point, see our IT assessment.

