Risk Assessment · NIST SP 800-30 · Free Excel template

Cyber Security Risk Assessment Template and Risk Register (Free Excel)

This free cyber security risk assessment template gives you a complete, defensible method in one Excel workbook. It follows NIST SP 800-30 Rev 1, the most widely used guide for conducting risk assessments, and rates each risk on a 5x5 likelihood and consequence matrix.

Start from a library of 25 common cyber risks, record inherent and residual risk, and the workbook calculates scores, ratings and whether each risk sits within your appetite. Treatment actions map to NIST SP 800-53 Rev 5 control families and ISO/IEC 27001:2022 Annex A.

  • 25starter risks
  • 5x5risk matrix
  • 20NIST 800-53 families
  • Freeno sign-up
Download the free template .xlsx · 80 KB · Excel 2016+ / Microsoft 365 · Updated Oct 2026

What's inside the workbook

For: CISOs, risk managers, security analysts, system owners and consultants preparing system risk assessments, security risk management plans or annual cyber risk reviews.

  1. 01

    Introduction🔒

    How to use the workbook, the method it follows and the colour legend.

  2. 02

    Context & Scope

    System, owner, information handled, confidentiality, integrity and availability impact, obligations and your risk appetite statement.

  3. 03

    Risk Criteria

    Tailorable likelihood and consequence scales, rating thresholds, maximum acceptable residual score and a colour-coded 5x5 matrix.

  4. 04

    Risk Library

    25 common cyber risks, from ransomware to AI misuse, with threat sources, vulnerabilities and mapped controls.

  5. 05

    Risk Register

    Inherent and residual likelihood, consequence, scores and ratings, control effectiveness, appetite check, treatment, owner and status.

  6. 06

    Treatment Plan

    Actions with NIST SP 800-53 controls, owners, due dates, cost, status and overdue tracking.

  7. 07

    Dashboard

    Inherent vs residual risk by rating, risks outside appetite, a live residual heat map and a chart.

  • NIST SP 800-30 method
  • Tailorable 5x5 risk matrix
  • Automatic risk appetite check
  • Live residual heat map
  • NIST SP 800-53 and ISO 27001 mapping
  • Works in Microsoft Excel 2016 and later

What is a cyber security risk assessment?

A cyber security risk assessment identifies the threats that could harm your systems and information, the weaknesses they could exploit, how likely that is, and how bad the result would be. The output is a prioritised list of risks so you can spend your security budget where it matters most.

Almost every framework requires one. ISO/IEC 27001 clause 6.1.2, the NIST Risk Management Framework, the Australian ISM's risk-based approach, the SOCI Act's risk management program rules and the PSPF all expect a documented, repeatable risk assessment.

The method: NIST SP 800-30 in five steps

  • Prepare: define the scope, the information involved and your risk appetite.
  • Identify threats: adversarial, accidental, structural and environmental threat sources, and the events they could cause.
  • Identify vulnerabilities: the weaknesses and predisposing conditions that make those events possible.
  • Determine likelihood and impact: rate each on a 1 to 5 scale, before and after existing controls.
  • Determine risk and respond: calculate the rating, compare it with appetite, and plan treatment.

The workbook follows this flow tab by tab, so less experienced assessors produce results that stand up to review.

How the 5x5 risk matrix works

Each risk gets a likelihood from 1 (Rare) to 5 (Almost certain) and a consequence from 1 (Insignificant) to 5 (Severe). The risk score is likelihood multiplied by consequence, from 1 to 25. By default:

  • Extreme (20 to 25): immediate action and Board attention.
  • High (10 to 16): treat within 3 months.
  • Medium (5 to 9): treat within 6 months.
  • Low (1 to 4): accept and monitor.

You can change every threshold, the scale descriptions and your maximum acceptable residual score on the Risk Criteria tab, and every rating, colour and dashboard figure updates automatically.

Inherent risk, residual risk and appetite

Inherent risk is the risk with only your current controls in place. Residual risk is what remains once you account for how effective those controls really are. The workbook compares every residual score with your risk appetite and flags anything outside it, so the treatment plan focuses on the risks that need a decision.

Treatment actions map to the 20 NIST SP 800-53 Rev 5 control families and to ISO/IEC 27001:2022 Annex A, which makes the register useful for a system security plan, a Statement of Applicability or an ISM security risk management plan. Read more in NIST SP 800-53 and the ISM.

How to use the Cyber Security Risk Assessment Workbook

  1. 1

    Set the context

    On Context & Scope, describe the system, its owner, the information it handles, its impact levels and your risk appetite.

  2. 2

    Tailor the criteria

    On Risk Criteria, adjust the likelihood and consequence guidance, rating thresholds and your maximum acceptable residual score.

  3. 3

    Identify risks

    Start from the Risk Library and copy the relevant risks into the Risk Register, then add any specific to your environment.

  4. 4

    Rate inherent risk

    For each risk, record the threat, vulnerability and existing controls, then rate inherent likelihood and consequence from 1 to 5.

  5. 5

    Rate residual risk

    Judge how effective the controls are and rate residual likelihood and consequence. Ratings and the appetite check calculate automatically.

  6. 6

    Treat and report

    Plan actions for every risk outside appetite on the Treatment Plan, then use the Dashboard and heat map to report to leadership.

Get the Cyber Security Risk Assessment Workbook

Free download. No sign-up, no email required.

Download (.xlsx, 80 KB)

Frequently asked questions

Which framework does this risk assessment template follow?

It follows the NIST SP 800-30 Rev 1 method, uses a 5x5 matrix in the ISO 31000 and ISO/IEC 27005 style common in Australia, and maps treatment to NIST SP 800-53 Rev 5 control families and ISO/IEC 27001:2022 Annex A.

Can I use it for ISO 27001?

Yes. ISO/IEC 27001 clause 6.1.2 requires a defined, repeatable information security risk assessment. The Risk Criteria tab documents your method, the register records results, and the Annex A column links treatment to your Statement of Applicability.

Can I change the risk matrix?

Yes. Every scale description, rating threshold and the maximum acceptable residual score are editable on the Risk Criteria tab, and all ratings, colours and dashboard figures update automatically.

What is the difference between inherent and residual risk?

Inherent risk is the level of risk with your current controls; residual risk is what remains after you judge how effective those controls are. Treatment focuses on residual risks that sit outside your appetite.

Does it work for the Australian ISM?

Yes. The ISM takes a risk-based approach and expects risks to be documented in a security risk management plan. This register, with its NIST SP 800-53 and ISO 27001 mapping, is a practical starting point.

How many risks can it hold?

The register holds 60 risks out of the box, which covers most system or organisation-wide assessments. You can extend it by copying the last row down.

Muhammad Anwar

Built by

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader, ISO 27001 Lead Auditor and Certified GRC Auditor. This template is based on the approach I use in real assessments across Defence, Federal Government and critical infrastructure.

More free templates