Last updated: April 29, 2026
Risk register = single source of truth for organisational security risks. Too often a spreadsheet that nobody reads. Done right, drives quarterly executive conversation.
Risk record fields
- Risk description
- Likelihood (1-5)
- Impact (1-5)
- Inherent score
- Existing controls
- Residual likelihood + impact
- Residual score
- Owner
- Treatment (accept / mitigate / transfer / avoid)
- Action items + due dates
- Last review date
Scoring matrix
| Trivial | Minor | Moderate | Major | Catastrophic | |
|---|---|---|---|---|---|
| Almost certain | M | H | H | C | C |
| Likely | L | M | H | C | C |
| Possible | L | M | M | H | C |
| Unlikely | L | L | M | H | H |
| Rare | L | L | L | M | H |
Cadence
- Operational team: monthly
- CISO review: quarterly
- Executive committee: quarterly
- Board: annually + on-demand for material risks
Module Quiz · 5 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.