Risk management is not just about identifying threats. It is about taking structured, measurable actions to mitigate, transfer, accept or avoid them. Within a demand, the Risk Assessment tab follows an 8-step methodology that carries each risk from identification to a documented response.
1. From risk demand to actionable insights
Each demand renders a flow diagram linking the demand to its risks and their remediation plans, so you always see, at a glance:
- Risk identification: which risks the demand raised and their references.
- Risk treatment decisions: whether each risk is mitigated, accepted, transferred or avoided.
- Remediation actions: the plans created to address the mitigated risks, and their status.
With this structure, every risk stays assessed, tracked and aligned with your organisation's risk appetite.
2. The 8 steps
Step 1: Add a Risk
Create the risk on the demand; its RSK reference is generated automatically and it is registered in the Risk Registry.
Step 2: Define the Risk Profile
Categorise the risk in the Risk Profiling tab: Security Domain, Business Attribute, Risk Category, Threat Origin, Threat Actor, Threat Actor Motivation, Threat Vector, STRIDE Threat Action, Threat Action, Victims Quantification, plus free-text notes and threats linked from your Threat Attacks Database.
Step 3: Assess the Inherent Risk
Evaluate the risk in its raw state, before any controls: capture the risk statement, strength, weakness and opportunity, select the impact types, then score likelihood (threat and vulnerability) and risk exposure (likelihood and impact) on the risk matrix.
Step 4: Assess the Current Risk
Evaluate the residual risk with today's controls in place, using the same statement, SWOT and matrix scoring structure.
Step 5: Recommend controls
Link existing policies and controls, or database controls, and describe any additional recommended controls needed to reach an acceptable risk level.
Step 6: Assess the Target risk
Define the desired residual risk once the recommended controls are implemented, aligned with your risk tolerance and appetite.
Step 7: Submit for Risk Response
Under an enforced workflow, the analyst sends the finished analysis to the requester with Send for Risk Response: the whole demand opens to them.
Step 8: Provide a Risk Response
The requester records a response for each risk (Mitigate, Avoid, Accept or Transfer, with an owner and a justification) and sends the demand back to the risk team for completion.
This methodology ensures a consistent, transparent and repeatable approach to managing cybersecurity risks across systems, third parties and organisational processes. The integrated SWOT analysis provides both strategic insight and practical direction at every scoring step.