Security Assessment
Cybersecurity Risk Assessment Checklist
A step-by-step cybersecurity risk assessment checklist: list what matters, identify threats and weaknesses, rate the risk, and turn the results into a plan leadership can act on.
· 9 min read
What a cybersecurity risk assessment is for
A cybersecurity risk assessment answers a practical question: which security problems could hurt this business the most, and which should we fix first? It is not a technical scan and it is not a compliance exercise for its own sake. Done well, it gives leadership a short, ranked list of risks with owners and costs, and gives the IT team a clear reason for what they are doing next.
This cybersecurity risk assessment checklist follows the same steps whether you run it yourself or use an external assessor.
Step 1: Decide the scope
- Which parts of the business are in scope: the whole company, one site, one system?
- Who owns the assessment and who signs off the results?
- Which framework, if any, will you map to: ISO 27001, the NIST Cybersecurity Framework, CIS Controls, or a client's or insurer's questionnaire?
Step 2: List what matters
- Systems: email, finance, CRM, line-of-business applications, file storage, websites.
- Data: customer records, payment data, personal data, intellectual property, contracts.
- Devices: laptops, phones, servers, network equipment, cloud accounts.
- People and suppliers: who has access, including outsourced IT, software vendors and contractors.
For each item, note who owns it and what would happen to the business if it were unavailable, leaked or altered.
Step 3: Identify threats
Typical threats for most organisations include:
- Phishing and stolen passwords leading to account takeover.
- Ransomware encrypting systems and backups.
- Business email compromise and payment fraud.
- Exploitation of unpatched software exposed to the internet.
- Mistakes: misconfigured sharing, deleted data, lost devices.
- Supplier compromise.
Step 4: Check the controls you have
Go through each control and record whether it is in place, partly in place or missing, and what evidence exists:
- Multi-factor authentication on email, remote access and admin accounts.
- Patching of operating systems, applications and network devices.
- Endpoint detection and response on every device.
- Email filtering and user awareness training.
- Backups that are offline or immutable, and restore-tested.
- Admin access limited to named people and reviewed.
- Logging and monitoring that someone actually reviews.
- An incident response plan that has been rehearsed.
Step 5: Rate each risk
For each threat against each important asset, estimate:
- Likelihood: how probable it is, given the controls in place.
- Impact: the financial, operational, legal and reputational effect if it happened.
A simple 1 to 5 scale for each, multiplied together, is enough for most organisations. Consistency matters more than precision.
Step 6: Decide what to do
For each significant risk, choose one of:
- Reduce it with a new or improved control.
- Transfer part of it, for example through cyber insurance or a contract.
- Avoid it by stopping the activity.
- Accept it, with a named person agreeing and a review date.
Step 7: Write it down and review it
Keep the results in a risk register: the risk, its rating, the owner, the agreed action, the due date and the review date. Review the register at least quarterly and after any major change or incident.
Common mistakes
- Treating a vulnerability scan as a risk assessment. Scans find technical weaknesses; a risk assessment decides which ones matter to the business.
- Rating everything as high. If everything is a priority, nothing is.
- Writing a report and filing it. The register only reduces risk if actions are tracked to completion.
Getting an independent view
An internal IT risk assessment is a good start, but an outside view finds what familiarity hides. A Techx4u security posture review assesses your controls against a recognised framework, produces a ranked cyber risk assessment for leadership, and gives your team a prioritised plan to close the gaps.
Common questions
- What is a cybersecurity risk assessment?
- It is a structured review of the systems and data that matter to a business, the threats against them and the controls in place, which rates each risk by likelihood and impact and produces a prioritised plan of what to fix first.
- How often should a business do a cyber risk assessment?
- At least once a year, and again after any major change such as a merger, a move to the cloud, a new critical system or a security incident. The risk register it produces should be reviewed quarterly.
- What is the difference between a risk assessment and a penetration test?
- A risk assessment looks across the whole business to decide which risks matter most. A penetration test is a technical exercise that proves whether specific systems can be broken into. Most organisations use the risk assessment to decide where penetration testing is needed.

Let's talk about your environment
Tell us what you are running and what worries you. We will come back with a straight assessment and a costed plan — no obligation.



