We identify and rate your information and cyber security risks using ISO 27005 and ISO 31000 approaches, and turn them into a prioritised risk treatment plan.
Why does Risk Management Consulting matter?
Investing in security without linking it to risk means spending resources in the wrong places. Regular, methodical risk management shows which asset faces which threat and what to close first. It is also the foundation of standards such as ISO 27001.
What does it cover?
Asset inventory and classification
We identify your information assets, their owners and their business value.
Threat and vulnerability analysis
We identify the possible threats to your assets and the weaknesses that exist today.
Risk assessment
We rate likelihood and impact and classify risks against your acceptance criteria.
Risk treatment plan
We turn the options of reduce, transfer, accept or avoid into a plan with owners and target dates.
Supplier and third-party risk
We help you assess the risks coming from suppliers and service providers.
Risk register and reporting
We set up the risk register and prepare clear reports and presentations for management.
How we work
- Scope and contextTogether we define your risk appetite, the scope and the assessment criteria.
- Asset and risk identificationWe identify assets, threats and existing controls through workshops and documents.
- Analysis and ratingWe rate and prioritise risks by likelihood and impact.
- Risk treatmentWe prepare a treatment decision and an actionable plan for each risk.
- Monitoring and reassessmentWe set up a periodic review process so the risk register stays current.
What do we deliver?
- Risk register
- Risk assessment report
- Risk treatment plan
- Input for the ISO 27001 Statement of Applicability (SoA)
- Executive summary and presentation
- Risk assessment methodology document
Who is this service for?
Frequently asked questions
How often should we repeat the risk assessment?
We recommend at least once a year and whenever there is a significant change in infrastructure, processes or the threat landscape.
Is it required for ISO 27001?
Yes. The standard requires a risk assessment and documented risk treatment; the Statement of Applicability is based on these results.
Which method do you use?
We build on ISO 27005 and ISO 31000 approaches and adapt the method to your organisation and existing risk management process.
Services you can combine
Get information about Risk Management Consulting
Fill in the short form and we will get back to you as soon as possible. For a more detailed preliminary assessment you can also use the needs-analysis form below.
Open the detailed needs-analysis form
If you share your current situation in a few questions, we can give you a clearer preliminary assessment and scope proposal.
Let’s talk about Risk Management Consulting
Share your needs and current situation, and we will define the right scope and roadmap together.