We identify and rate your information and cyber security risks using ISO 27005 and ISO 31000 approaches, and turn them into a prioritised risk treatment plan.

// Why it matters

Why does Risk Management Consulting matter?

Investing in security without linking it to risk means spending resources in the wrong places. Regular, methodical risk management shows which asset faces which threat and what to close first. It is also the foundation of standards such as ISO 27001.

// Scope

What does it cover?

Asset inventory and classification

We identify your information assets, their owners and their business value.

Threat and vulnerability analysis

We identify the possible threats to your assets and the weaknesses that exist today.

Risk assessment

We rate likelihood and impact and classify risks against your acceptance criteria.

Risk treatment plan

We turn the options of reduce, transfer, accept or avoid into a plan with owners and target dates.

Supplier and third-party risk

We help you assess the risks coming from suppliers and service providers.

Risk register and reporting

We set up the risk register and prepare clear reports and presentations for management.

// Method

How we work

  1. Scope and contextTogether we define your risk appetite, the scope and the assessment criteria.
  2. Asset and risk identificationWe identify assets, threats and existing controls through workshops and documents.
  3. Analysis and ratingWe rate and prioritise risks by likelihood and impact.
  4. Risk treatmentWe prepare a treatment decision and an actionable plan for each risk.
  5. Monitoring and reassessmentWe set up a periodic review process so the risk register stays current.
// Deliverables

What do we deliver?

  • Risk register
  • Risk assessment report
  • Risk treatment plan
  • Input for the ISO 27001 Statement of Applicability (SoA)
  • Executive summary and presentation
  • Risk assessment methodology document
// Who is it for?

Who is this service for?

Organisations preparing for ISO 27001 or ISO 22301 certificationOrganisations in a KVKK compliance processThose who need to present risk reports to the boardThose who want to manage supplier and third-party risk
// FAQ

Frequently asked questions

How often should we repeat the risk assessment?

We recommend at least once a year and whenever there is a significant change in infrastructure, processes or the threat landscape.

Is it required for ISO 27001?

Yes. The standard requires a risk assessment and documented risk treatment; the Statement of Applicability is based on these results.

Which method do you use?

We build on ISO 27005 and ISO 31000 approaches and adapt the method to your organisation and existing risk management process.

// Related services

Services you can combine

// Information request

Get information about Risk Management Consulting

Fill in the short form and we will get back to you as soon as possible. For a more detailed preliminary assessment you can also use the needs-analysis form below.

    Open the detailed needs-analysis form

    If you share your current situation in a few questions, we can give you a clearer preliminary assessment and scope proposal.

      Your priorities

      Let’s talk about Risk Management Consulting

      Share your needs and current situation, and we will define the right scope and roadmap together.