Risk management is not just about identifying threats. It is about taking structured, measurable actions to mitigate, transfer, accept or avoid them. Within a demand, the Risk Assessment tab follows an 8-step methodology that carries each risk from identification to a documented response.

1. From risk demand to actionable insights

Each demand renders a flow diagram linking the demand to its risks and their remediation plans, so you always see, at a glance:

  • Risk identification: which risks the demand raised and their references.
  • Risk treatment decisions: whether each risk is mitigated, accepted, transferred or avoided.
  • Remediation actions: the plans created to address the mitigated risks, and their status.

With this structure, every risk stays assessed, tracked and aligned with your organisation's risk appetite.

2. The 8 steps

Step 1: Add a Risk

Create the risk on the demand; its RSK reference is generated automatically and it is registered in the Risk Registry.

Step 2: Define the Risk Profile

Categorise the risk in the Risk Profiling tab: Security Domain, Business Attribute, Risk Category, Threat Origin, Threat Actor, Threat Actor Motivation, Threat Vector, STRIDE Threat Action, Threat Action, Victims Quantification, plus free-text notes and threats linked from your Threat Attacks Database.

Step 3: Assess the Inherent Risk

Evaluate the risk in its raw state, before any controls: capture the risk statement, strength, weakness and opportunity, select the impact types, then score likelihood (threat and vulnerability) and risk exposure (likelihood and impact) on the risk matrix.

Step 4: Assess the Current Risk

Evaluate the residual risk with today's controls in place, using the same statement, SWOT and matrix scoring structure.

Step 5: Recommend controls

Link existing policies and controls, or database controls, and describe any additional recommended controls needed to reach an acceptable risk level.

Step 6: Assess the Target risk

Define the desired residual risk once the recommended controls are implemented, aligned with your risk tolerance and appetite.

Step 7: Submit for Risk Response

Under an enforced workflow, the analyst sends the finished analysis to the requester with Send for Risk Response: the whole demand opens to them.

Step 8: Provide a Risk Response

The requester records a response for each risk (Mitigate, Avoid, Accept or Transfer, with an owner and a justification) and sends the demand back to the risk team for completion.

This methodology ensures a consistent, transparent and repeatable approach to managing cybersecurity risks across systems, third parties and organisational processes. The integrated SWOT analysis provides both strategic insight and practical direction at every scoring step.