As an organisation that sends data over the internet, you are always at risk of a cyberattack. To achieve your IT and business goals, you must protect yourself against these attacks as best as possible. And you need to do so proactively, not after the damage is done.
This is where cybersecurity risk assessments come in. They evaluate an organisation’s security posture, identify weak links, and suggest new security measures to harden the attack surface.
In this comprehensive guide, we take a closer look at cybersecurity risk assessments, and why they are important. We also provide you with a proven step-by-step plan to identify and assess risks.
What is a cyber risk?
A cyber risk is the likelihood that your organisation will be harmed by digital attacks targeting its IT infrastructure, business processes, and critical data.
Some of the most common threats include:
- Phishing, i.e., an attacker emailing you, posing as somebody else and trying to steal sensitive data, like login information.
- Malware, e.g., software that spies on user behavior.
- Ransomware, i.e., software that encrypts your systems and prevents you from accessing them until a ransom is paid.
- Insider threats, e.g., an employee selling critical information to a competitor, like intellectual property.
- Distributed denial-of-service (DDoS) attacks, i.e., an attacker flooding your servers with so many requests that the system shuts down.
- IoT-based threats, i.e., an attacker compromising an “Internet of Things” device, like a wearable, smart appliance, or vehicle.
Not all of these risks are created equally — they vary in terms of probability and potential damage. In addition, each organisation has its unique risk landscape. Some businesses and industries are more prone to certain attacks than others.
As an organisation with limited time and budget, your operational resilience depends on how well you prioritise these risks. This is why conducting regular cybersecurity risk assessments is crucial.
What is a cybersecurity risk assessment?
A cybersecurity risk assessment is the process of identifying, analysing, and prioritising cybersecurity risks in an organisation’s digital landscape. It supports the decision-making process of executives and keeps stakeholders informed.
On its most fundamental level, a cybersecurity risk assessment answers the following questions:
- What are our most important assets, services, and data?
- What vulnerabilities exist within our systems?
- What are the most likely types of attacks we are faced with?
- How do we rank these threats in terms of potential damage and business impact?
- What regulatory requirements do we need to pay attention to?
- How can we mitigate risks most cost-effectively?
- What level of risk are we comfortable taking?
- Do we have the right partners and access to specialist skills if we are hit?
Cybersecurity risk assessments are no longer a “nice to have.” For many businesses based in the European Union, they will soon become obligatory. IT security regulations like the NIS-2 directive will affect a multitude of sectors. On top of that, there are industry-specific regulations like DORA for the financial market.
Benefits
Conducting cybersecurity risk assessments comes with many benefits.
Reduce costs
It is often said that it’s not a question of “if” your organisation will be affected by a cyberattack, but “when.” By regularly assessing your security posture, you can mitigate that risk and the associated costs.
For example, putting an effective recovery process in place can be the difference between a minor incident and a major crisis. It might save you millions in ransomware payments.
Avoid reputational damage
Cyberattacks may damage the trust that stakeholders place in your organisation, especially if their data is made public. By having a thorough risk assessment in place, you can actively work to prevent such reputation losses.
Comply with regulations
In many instances, cybersecurity risk assessments are no longer optional. You need to conduct them or be subject to hefty fines. This is especially true for businesses in the European Union. For example, NIS-2 requires businesses across 18 different industries to have “policies on risk analysis and information system security.”
Likewise, the new DORA regulation prescribes a “sound, comprehensive and well-documented ICT risk management framework” for financial institutions. It also requires annual testing.
Avoid downtime
Businesses need to avoid downtime as much as possible. This is true for both customer-facing systems and internal systems, so team members can do their jobs. Cybersecurity risk assessments can help you understand risks and security gaps — and provide you with ways to avoid such costly interruptions.
Prevent data loss
If important trade secrets or critical code gets stolen, your organisation might be out of business. Cybersecurity risk assessments will help you assess these dangers and raise awareness.

The case for cybersecurity risk assessments
The cybercrime industry is flourishing. According to Statista’s Cybersecurity Outlook, the global cost of cybercrime will rise from 8.15 trillion USD (7.52 trillion EUR) in 2023 to 13.82 trillion USD (12.75 trillion EUR) by 2028.
The 2024 Data Protection Trends Report by Veeam offers more alarming details.
- For the fourth year in a row, cyberattacks were responsible for the most impactful outages that organisations had to deal with.
- Among these attacks, ransomware threats reign supreme. Three out of four organisations suffered at least one ransomware attack in the preceding twelve months.
The 2024 Threat Report by Arctic Wolf goes even more granular:
- The median initial ransom demand in incidents rose to $600,000: a year-over-year increase of 20%.
- After ransomware attacks (48.6%), the most common cyber threats include:
- Business email compromise (BEC) at 29.7%
- Network intrusion at 14.8%
- Other (fraud, malware, disruptions, etc.) at 6.9%
All of this goes to show — getting hit by a cyberattack is not an “if” but a “when.” Hence, cybersecurity risk assessments and other preventive measures should be a staple of any organisation.
But are they?
In the aforementioned report by Veeam, businesses were also interviewed about their level of preparedness.
When asked about testing and documentation update frequency, the average interval was 7.3 months — notably worse than the 4.4-month average just two years ago. Further, 76 percent of organisations noted a “Protection Gap” between how much data they could afford to lose and how often their data is protected. An even higher number — 85 percent — recognised an “Availability Gap” between how fast they could recover versus what the business processes require.
It seems fair to say that many businesses have some catching up to do when it comes to risk remediation. And the first step is to establish a baseline through a thorough cybersecurity risk assessment.
What different approaches exist?
There are at least five distinct approaches to conducting a cybersecurity risk assessment:
- Compliance-driven
- Vulnerability-based
- Threat-based
- Asset-focused
- Function-focused
1. Compliance-driven
Here, you compare your organisation’s security controls against the standards outlined in a regulatory framework, like NIST, ISO/IEC, NIS-2, or DORA. If there is a discrepancy, you improve your security controls to comply with the framework.
The central question of this approach is, “What rules do we have to meet?”
It is important to understand which framework applies, based on your location (e.g., in the European Union), your industry (e.g., the healthcare sector), or your organisation’s size (small businesses often face less strict rules than large enterprises).
The most obvious advantage of this approach — you ensure regulatory compliance while avoiding financial penalties.
A compliance-driven approach also helps establish trust. Customers are more likely to choose you as a vendor when you adhere to well-known industry standards.
One disadvantage is that these frameworks typically provide high-level recommendations. They are not specific to your organisation.
Also, a compliance-driven approach can facilitate a checklist mentality. You might come to fixate on guidelines but ignore the situation on the ground.
2. Vulnerability-based
For this approach, you assess and create a list of your current vulnerabilities. You compile this list by scanning your infrastructure for weaknesses. You also conduct interviews with IT and business executives to find out what they view as the most likely points of failure. You might even hire an outside security consultant to get a fresh pair of eyes.
The central question of this approach is, “What vulnerabilities currently exist?”
The advantage of this approach is that you generate a lot of relevant data. You don’t base your actions on a one-size-fits-all regulatory framework but on the specifics of your organisation.
The downside is that this process is resource-intensive. Compiling this data takes up a lot of time and manpower. Many organisations keep pushing this process off until it’s too late and a cyberattack hits.
3. Threat-based
Here, you evaluate the techniques that threat actors use, typically based on catalogs of known attacks. This approach is often combined with some kind of threat modelling, e.g., attack route mapping (ARM). The idea is to visualise how an attacker accesses your network and then shut these routes down.

The central question of this approach is, “What techniques and paths are the attackers likely to choose?”
The main benefit of this approach is its level of detail. You get into the head of your enemy and understand how they think and act.
Another benefit is how visual this approach is. By mapping out attack routes, even non-technical managers can intuitively grasp the risk landscape.
However, it is easy to get hung up on details. You might obsess over attack patterns and routes when it would be more time- and cost-efficient to harden your attack surface as a whole.
Also, you can’t rely on historical data too much. The cyber threat landscape is constantly evolving. The threats of yesterday are often not relevant anymore, while completely new threats have emerged in the meantime.
Finally, as your IT infrastructure evolves, the attack paths change. The map must be constantly updated.
4. Asset-focused
This approach focuses on identifying and securing your organisation’s most crucial assets. This should include both physical and non-physical assets, for example:
- Physical locations
- Machines
- Sensors
- Controllers
- Servers
- Applications
- Customer data
- Intellectual property
The central question of this approach is, “What are our most valuable assets?”
This approach works well for organisations that own a limited number of high-value assets (HVAs). By starting with the asset in mind, they can improve their security posture quickly and cost-efficiently.
However, this approach can get confusing quickly as the number of assets increases. Also, different custodians have different ways of assessing a single asset. It might be unclear what constitutes an HVA.
Another problem is compartmentalisation. Assets are looked at as monolithic entities, instead of considering their interconnectedness. Finally, this approach tends to ignore the human factor. Operational resilience is not just assets and systems, but the people who use them.
5. Function-focused
This approach looks at the mission-critical services that an organisation provides. The goal is to protect these functions. Assets are still taken into account, insofar as they enable a certain service. They don’t exist in a vacuum, but interact with each other.
The central question of this approach is, “How can we keep doing what we are doing?”
This approach is great for ensuring business continuity. It forces you to account for all the variables needed to produce a certain outcome.
It can also help with breaking up silo structures within your organisation. By focusing on the resilience of a whole service, different business units will work together more closely.
It is more difficult to prove compliance, though. Most regulatory frameworks are asset-centric and focus on securing individual resources. The function-focused approach takes more work in this regard.
This approach can also lead to interpersonal conflicts. Certain custodians within an organisation might feel like they “own” an asset. When forced into a more holistic service view, they might act territorial.
How to perform a cybersecurity risk assessment in 10 steps
The following framework combines several risk assessment methods to give you a wide array of benefits.
Step 1: Determine the scope
The first step is to determine the scope of your cybersecurity risk assessment. Will you be evaluating your organisation as a whole? Or will you zoom in on a certain business unit, asset, or function?
There are pros and cons to both approaches. An all-encompassing assessment is more likely to take interdependencies into account. You get an overview of your organisation and its security posture. This will help with the decision-making processes at the executive level.
However, these general assessments tend to glance over details. Also, for businesses of a certain size, they might not be feasible. Once you get to the enterprise level, you might have to break your assessments up.
In comparison, zooming in on certain business units, assets, or functions is easier. You can also go very granular. The danger is that you might miss the big picture and thus make less-informed long-term decisions.
Step 2: Identify stakeholders
You should identify stakeholders and get their input on the risk assessment you are about to conduct. This might include:
- IT and business executives
- Team leaders
- Key users
- Customers
- Suppliers
- Service providers
Get information about the following:
- Critical business processes and functions
- Key assets (both physical and digital)
- Existing security policies and procedures
- Current ability to recover from security events
This might seem like an extra step, but you will be surprised by how much valuable information you will gather. You will identify risks that you would have missed otherwise.
Step 3: Pay attention to compliance requirements
The IT compliance landscape is shifting, specifically for businesses based in the European Union and the UK. Several regulatory frameworks are coming into effect soon:
- NIS-2, the Network and Information Security Directive of the EU, will become national law by October 18th, 2024.
- DORA, the Digital Operational Resilience Act of the EU for financial institutions, will apply as of January 17th, 2025.
- FCA PS21/3 pertains to financial firms in the UK and will become binding by March 31st, 2025.
These frameworks require organisations to regularly assess their cyber risks and mitigate any vulnerabilities they might uncover. Non-compliance is not an option, as there are severe fines in place.
The first step is to determine which frameworks are relevant to your organisation. Next, work through the requirements and conduct a gap analysis. Which requirements do you already meet? Which requirements do you still need to implement? Note the discrepancies and factor them into your cybersecurity risk assessment.
Step 4: Identify assets
Create an inventory of all physical and logical assets in your organisation. Do not prioritise them yet, but focus on creating as complete a list as possible. This might include:
- Servers
- Drives
- Workstations
- Networking equipment
- Applications
- Licenses
- Data
- Clouds
- Data centers
- Interfaces
- Endpoint devices
For each asset, create a small database, noting its specifics, like:
- Name
- Vendor
- Internal/external
- Interfaces
- Date of last update
- Response time
- Business unit
- Contact information
Step 5: Identify services
Create a complete list of the services that your business provides. This includes both customer-facing services and services relevant to your staff.
For example, if you are a bank, one of your customer-facing services might be your online banking suite. On the backend, it might be a CRM that your team members use to manage key accounts.
Unlike assets, these functions typically span several departments. That makes it more difficult to assign a single custodian. Consider mapping out your services to see which stakeholders are involved.
Visualising your services will also help you understand interdependencies. How does a certain function enable another function? How do they integrate? For example, your supply chain might be closely intertwined with your inventory control.
Step 6: Identify vulnerabilities
Next, think about the existing vulnerabilities of your systems. Some of these vulnerabilities you might already be aware of, others you still have to discover. Examples include:
- Unpatched software
- Misconfigurations
- Poorly-protected wireless access
- Unprotected endpoints
- Lack of encryption
- Weak passwords
- Human vulnerabilities, e.g., team members opening infected email attachments
Use questionnaires. Interview the stakeholders you identified earlier and ask them what vulnerabilities they are aware of.
Also, consult databases of publicly disclosed technology vulnerabilities, e.g., MITRE’s Common Vulnerability Enumeration (CVE) database.
Finally, it can be an excellent idea to bring in an outside consultant. Many IT executives suffer from tunnel vision when it comes to their own systems. A fresh pair of eyes will remedy that.
Step 7: Identify threats
There are different ways of keeping yourself up-to-date with the current threat landscape. One way is to consult libraries like the Mitre ATT&CK Knowledge Base or join an organisation like the Cyber Threat Alliance.
You could also form partnerships with other businesses in your industry to share information on current cyber threats. This practice is strongly encouraged by the upcoming Digital Operational Resilience Act (DORA) of the European Union.
However, many businesses still reject this idea for fear of looking “weak” in the eyes of their competitors. But confronted with existential cyber risks, it might be time to rethink this attitude.
Combine this step with mapping out attack routes that a hacker might choose. This will help you think like the intruder and understand their toolbox.
Don’t forget about insider threats. According to the 2023 Insider Threat Report, 74 percent of organisations experienced an increase in insider attacks.
Things to monitor:
- Administrative privileges, i.e., what data a team member can access
- Activity logs, i.e., how a team member behaves while logged in
- Third-party service providers and their access rights/logs
- Software vendors and their ability to access your systems
Keep in mind that insider threats are not always due to malicious intent. For example, a team member may try to copy a file and accidentally delete it. Your cybersecurity risk assessment should account for such accidents.
Step 8: Assess the risks
Next, you need to determine the likelihood of the different risk scenarios and the impact they could have on your organisation.
To rank likelihood, assign each risk scenario a number from 1 (“Very Unlikely”) to 5 (“Extremely Likely”). For impact, also assign a number, from 1 (“Very Mild”) to 5 (“Highly Disruptive”).
The result will be a 5×5 risk matrix:

When ranking likelihood, look at these three factors:
- Discoverability. How easy is it for us to spot a particular threat, e.g. an attacker injecting malware into a database? And vice versa, how easy is it to spot a certain vulnerability for an attacker? Discoverability goes both ways.
- Exploitability. How easy is it to exploit a certain asset, service, or vulnerability? Is the attack path full of obstacles? Or can the attackers move through the system easily?
- Reproducibility. Once the attackers have succeeded with a certain approach, how likely will they be able to do it again? Can they potentially keep using the same vulnerability or attack path over and over?
When ranking impact, look at these three factors:
- Confidentiality. If the attack succeeds, what will this mean for our data discretion? Will the attack only affect less sensitive data? Or might attackers gain access to highly confidential data, like payment details?
- Integrity. If an attack succeeds, how will this affect our data integrity? How easy will it be for hackers to manipulate, encrypt, or erase information? And how will this tampering affect our core services?
- Availability. If an attack succeeds, how will this affect availability? Will our customers still be able to use our services, like logging into their accounts? Will our team members still be able to go about their tasks, like replying to support tickets?
Step 9: Look at other costs
Cyber risks come with different prevention costs. Some risks might be expensive to mitigate, others less so. Ask yourself — “Will it cost more to protect this asset than it’s worth?” If the answer is “Yes,” you might choose not to protect it.
However, also consider reputational damage. While the monetary value of losing a certain asset might be bearable, the loss of reputation might not.
Finally, you could also consider “outsourcing” some of the costs by purchasing cyber insurance. This was a go-to strategy for many CIOs in the past. However, with new regulations like NIS-2 and DORA coming into effect soon, this might no longer be an option. In many instances, management is now liable for all cybersecurity infringements.
Step 10: Document your risks
For this final step, create a central risk register. This will enable your decision-makers to understand what is at stake and what actions need to be taken. Make sure to include the following information:
- Name of risk
- Probability
- Potential damage (organisational, monetary, and reputational)
- Affected assets and services
- Affected stakeholders
- Existing security controls
- Recommended security controls, e.g., intrusion detection, data encryption, multi-factor authentication, employee training, etc.
- Cost of prevention
- Residual risk, i.e., the remaining risk after all security controls have been implemented
- Risk owner, i.e., the person responsible for managing the residual risk
Note that risk assessments are never static. Likelihood, impact, and other factors will constantly change as both your organisation and the threat landscape evolve. You must repeat this exercise regularly to stay up to date.
Let Proact do it for you!
Conducting a cybersecurity risk assessment is a complex and time-intensive process. At the same time, your in-house team is already busy managing your day-to-day operations. It doesn’t have the resources to take on another major project.
However, putting off regular cybersecurity risk assessment is not an option. First, you will eventually fall victim to a cyberattack; the question is not “if” but “when.” Second, for many businesses, cybersecurity risk assessments will soon be legally required (or already are). Non-compliance will leave you subject to hefty fees or even criminal prosecution.
This is where Proact comes in. We will conduct your cybersecurity risk assessment for you. Outsourcing this process comes with a number of benefits:
- You get immediate access to our pool of security specialists. No cumbersome recruiting process.
- We conduct your risk assessments on time and in regular intervals so you can meet your compliance requirements.
- We implement all missing security controls for you. You can choose from a wide array of services:
- We tailor our solutions to your needs. You can choose to only purchase certain security modules to complement your in-house team, or you can outsource all your security operations to Proact.
Ready to take your risk assessments to the next level? Contact us today for a free demo! We are excited to hear from you.