Risk Assessment & Management

Cyber risk management that gives you a prioritised risk register, an agreed risk appetite and treatment plans your board can act on, aligned to ISO 27001 and NIST CSF 2.0.

Service Details

Cyber risk management gives you a clear, prioritised view of the security risks that matter most to your business, and an agreed plan for each one. We assess your systems, suppliers, processes and people, then give your leadership a risk register, a risk appetite statement and treatment plans aligned to standards your auditors recognise, such as ISO 27001 and the NIST Cybersecurity Framework (CSF) 2.0.

It sits within our assessments and engineering services, alongside the testing and review work that feeds your register with evidence rather than guesswork.

INFO

You get risk decisions your board can understand and defend, rather than a long list of technical findings with no clear priority.



Risk decisions grounded in your business

We start with the functions your business cannot run without, then work outwards to the systems, data, suppliers and people that support them. That keeps the assessment focused on impact to the business, not on the number of findings.

Each risk is scored by likelihood and impact, given an owner, and compared with how much risk your leadership is willing to carry. You see where you sit today and what it would take to get where you want to be.

A Falx consultant reviewing a risk register with a client leadership team in a meeting room

What you get

Outputs your leadership, auditors and delivery teams can each use:

Risk Register

Every risk scored by likelihood and impact, with a named owner, current controls and a target score.

Risk Appetite Statement

A short, board-approved statement of how much risk you will accept in each area, so decisions stay consistent.

Treatment Plan

A decision for each risk, whether to reduce, transfer, accept or avoid it, with actions, owners and dates.

Board Reporting

Key risk indicators (KRIs) and a one-page summary that shows leadership how exposure is changing over time.


Who it is for

Risk management suits organisations that need to show their security spend is going to the right places. That often means firms preparing for ISO 27001 certification, regulated businesses facing DORA or FCA expectations, and boards that want a clearer picture before approving budget.

It also helps when something has changed. A new supplier, an acquisition, a cloud migration or a near-miss incident are all good moments to reassess where your exposure sits.


A facilitator mapping out a strategy on a whiteboard during a bright office workshop

How we work

Our approach follows the risk process set out in ISO/IEC 27005, the international guidance for information security risk management. It keeps the work repeatable, so your second assessment can be compared with your first.

  • Set the context — We agree scope, the criteria for scoring likelihood and impact, and a draft risk appetite with your leadership.
  • Identify risks — Workshops and interviews map your critical assets, threats, weaknesses and the suppliers you depend on.
  • Analyse and evaluate — Each risk is scored, compared with your appetite and ranked, so the top of the register is where attention goes first.
  • Plan treatment — Risk owners agree a response and the actions needed, which become your treatment plan.
  • Monitor and review — We set the KRIs and review cycle that keep the register current as your business changes.

Treatment you can schedule

A treatment plan is only useful if your teams can deliver it. We group actions by effort and time to value, so you can show progress in the first few weeks while longer pieces of work are planned and funded.

Quick wins

Low-effort fixes that lower exposure straight away

Tactical

Controls and tools your engineers can roll out next

Strategic

Policy, process and people changes for the long term


Supplier and third-party risk

Many incidents now start with a supplier rather than your own systems. We help you list the third parties that hold your data or support critical services, rate them by how much you depend on them, and decide what assurance to ask for.

Supplier risks go into the same register as everything else, so they are scored and owned on the same terms. This also supports the third-party requirements in DORA and the supply chain category in the NIST CSF 2.0 Govern function.

Evidence for audits and regulators

Your risk work becomes evidence auditors and regulators expect to see:

  • ISO 27001: a documented risk assessment and treatment process (clause 6.1), a Statement of Applicability and records of risk assessments carried out.
  • NIST CSF 2.0: outcomes for the Govern function, including risk management strategy, roles and supply chain risk. Our NIST service covers the wider framework.
  • DORA: input to the ICT risk management framework financial entities must maintain.
  • FCA operational resilience: risk input to mapping your important business services and testing against impact tolerances.

Because one register is mapped to several frameworks, you avoid running separate risk exercises for each audit.

Services that work alongside

Risk management draws on evidence from the rest of our assessment work. Security posture reviews show how well your current controls hold up, threat modelling finds design risks in specific systems, and penetration testing confirms which weaknesses can actually be exploited.

To turn the register into board-level decisions, pair it with board advisory. If you need ongoing ownership of security risk without a full-time hire, a fractional CISO can run the review cycle for you.


Frequently asked questions

Know which risks matter most

Tell us what you are worried about, from a supplier you rely on to an audit on the horizon. You get a clear view of how a risk assessment would work for you, and what your board would see at the end of it.