Cyber Assurance

How to Conduct a Cyber Security Risk Assessment in 7 Steps

How to conduct a cyber security risk assessment step by step: scope, threats, vulnerabilities, a 5x5 risk matrix, appetite and NIST SP 800-53 treatment.

Muhammad Anwar
· 5 min read

A cyber security risk assessment answers one question that every board, regulator and auditor eventually asks: which cyber risks matter most to this organisation, and what are we doing about them? It is the foundation of ISO 27001, the NIST Risk Management Framework, the Australian ISM’s risk-based approach and the SOCI Act’s risk management program rules. Yet many assessments end up as long spreadsheets that nobody reads.

Here is the seven-step method I use, based on NIST SP 800-30 Rev 1, the most widely used guide for conducting risk assessments.

Step 1: Set the context and scope

Start by being clear about what you are assessing and why:

  • Scope: a single system, a new project, a business unit or the whole organisation.
  • Information: what data is involved, from personal information to OFFICIAL: Sensitive or commercially sensitive material.
  • Impact levels: how bad would a loss of confidentiality, integrity or availability be? Rating each as low, moderate or high gives you an overall security category.
  • Obligations: the frameworks, laws and contracts that apply.
  • Risk appetite: in plain English, how much risk leadership is prepared to accept.

Skipping the appetite conversation is the most common mistake. Without it, every risk looks equally urgent and nothing gets prioritised.

Step 2: Agree the risk criteria

Before you rate anything, agree the scales. Most Australian organisations use a 5x5 matrix in the ISO 31000 style:

  • Likelihood from 1 (Rare) to 5 (Almost certain), with time-based guidance so people rate consistently
  • Consequence from 1 (Insignificant) to 5 (Severe), with examples across operations, finance, reputation, compliance and safety
  • Risk score = likelihood x consequence, from 1 to 25, banded into Low, Medium, High and Extreme

Write the definitions down. Two assessors using the same criteria should reach roughly the same rating.

Step 3: Identify threats

NIST SP 800-30 groups threat sources into four types:

  1. Adversarial: criminals, nation states, hacktivists and malicious insiders
  2. Accidental: mistakes by staff, contractors or administrators
  3. Structural: failures of equipment, software or processes
  4. Environmental: fire, flood, storms and utility failures

For each relevant source, describe the threat event: what could actually happen. “Ransomware” is a category; “a criminal group encrypts our file servers and steals customer data for extortion” is an event you can assess.

Step 4: Identify vulnerabilities

Next, find the weaknesses and predisposing conditions that make each event possible. Typical examples:

  • internet-facing systems that are not patched quickly
  • password-only access to email and remote services
  • flat networks with no segmentation
  • backups that are online, not immutable, or never restore-tested
  • suppliers holding your data with limited due diligence
  • staff using public AI tools with confidential information

Be specific. A vulnerability that names the system and the gap points directly to the fix.

Step 5: Rate inherent and residual risk

For each risk, record the existing controls, then rate it twice:

  • Inherent risk: likelihood and consequence with your current controls taken at face value.
  • Residual risk: what remains once you honestly judge how effective those controls are.

The gap between the two is often revealing. A control that exists on paper but is only partially effective barely reduces risk at all.

Step 6: Evaluate against appetite

Compare every residual score with your risk appetite. Risks within appetite are accepted and monitored. Risks outside appetite need a decision:

  • Mitigate: add or strengthen controls
  • Transfer: for example insurance or contractual terms, noting that accountability never transfers
  • Avoid: stop the activity that creates the risk
  • Accept: a formal, documented decision by the risk owner, with a review date

Step 7: Plan treatment and report

Turn every decision into an action with an owner, a due date and an estimated cost. Mapping treatment to a control framework keeps it concrete and auditable. I map actions to the 20 NIST SP 800-53 Rev 5 control families and to ISO 27001 Annex A, which makes the register directly useful for a System Security Plan or a Statement of Applicability.

Finally, report in a form leaders can act on. A heat map of residual risk, the number of risks outside appetite and overdue treatment actions tell a board far more than a 200-row spreadsheet. See cyber risk reporting for boards for the indicators that work.

A worked example

Take ransomware against a mid-sized organisation:

  • Threat event: a criminal group encrypts file servers and steals data
  • Vulnerability: unpatched internet-facing systems, a flat network and online backups
  • Existing controls: endpoint detection, nightly backups, a firewall
  • Inherent risk: likelihood 4, consequence 5, score 20 (Extreme)
  • Residual risk: controls only partially effective, so likelihood 3, consequence 4, score 12 (High)
  • Appetite: maximum residual score of 9, so this risk is outside appetite
  • Treatment: patch internet-facing systems within 48 hours, segment the network and move backups offline with monthly restore tests (NIST SP 800-53 SI-2, SC-7, CP-9 and CP-4)

Want to feel the pressure of that scenario in real time? Try Breach Room, my free 3-minute ransomware tabletop simulation.

Get the template

My free cyber security risk assessment template puts this whole method in one Excel workbook: context and scope, tailorable criteria, a library of 25 common cyber risks, a risk register that calculates ratings and checks appetite automatically, a treatment plan and a live heat map.

Frequently asked questions

How often should a cyber security risk assessment be done?

At least annually, and whenever something significant changes: a new system, a major supplier, a merger, a serious incident or a change in the threat landscape.

What is the difference between a risk assessment and a gap assessment?

A gap assessment compares your controls with a framework’s requirements. A risk assessment asks which threats could harm you and how likely and severe that would be. Good programs use both: the risk assessment sets priorities, the gap assessment checks coverage.

Which framework should I follow for a cyber risk assessment?

NIST SP 800-30 is the most detailed guide to the method itself. ISO 27001 and ISO/IEC 27005 suit organisations pursuing certification, and Australian government entities should align with the ISM and PSPF. The steps above work with all of them.

Who should own cyber security risks?

The business owner of the affected system or process, not the security team. Security advises and supports, but the person accountable for the outcome should own the risk and the decision to treat or accept it.


Need an independent risk assessment, or help turning one into a board-ready program? See services or talk to my AI agent.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.