Cybersecurity Glossary
Risk Assessment
Working out what could go wrong, how likely it is and what it would cost you.
What Risk Assessment means
A risk assessment lists your important assets, the plausible threats to each, the likelihood and the impact, and the controls already in place. The output is a ranked list that tells you where the next pound or hour of effort belongs. It should be short enough that people actually read it.
Why Risk Assessment matters for small businesses and nonprofits
Without it, security spending follows whatever was in the news. With it, you can explain to a board or a funder why you chose one control over another, which is increasingly a formal requirement.
What to do about Risk Assessment
- Start with the handful of systems your organisation cannot operate without
- Score impact in terms your leadership recognises, such as days lost or revenue at risk
- Review after any significant change, not only once a year
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.