Skip to content
Consultancy · · 2 min read

Information security risk assessment in 5 steps (no consultant-speak)

A risk assessment sounds heavy, but it is just structured thinking about what can go wrong. Here is how to do one yourself in five understandable steps.

By Limburg Cyber Group

A risk assessment is the foundation under any serious security approach, and under NIS2 even an explicit expectation. Yet the word puts people off. Unjustly: at its core it is simply structured thinking about what can go wrong and what you do about it. Here it is in five steps, without jargon.

Step 1: map your crown jewels

Start with what you have to protect. Which data and systems can your business not do without? Client files, financial records, your email, that one system everything runs on. You cannot protect everything equally heavily, so determine what is really important.

Step 2: consider what can go wrong

For each crown jewel, run through the threats. Think of: outage, theft, ransomware, human error, a hacked account, a rogue supplier. You do not have to be exhaustive, but do be realistic.

Step 3: estimate likelihood and impact

For each risk, two simple questions: how likely is it (low/medium/high) and how bad is it if it happens? The combination determines urgency. A risk that is both likely and severe you tackle first; something unlikely with small impact can wait.

Step 4: choose your measures

For each important risk, decide what you do. Usually that is: reduce (take a measure, such as MFA or backups), transfer (for example insure), or consciously accept if likelihood and impact are low. Accepting is a valid choice too, as long as it is made consciously.

Step 5: record and repeat

Put the outcome in a simple overview: risk, estimate, measure, who is responsible. This document is immediately your evidence of “demonstrable control” towards clients and regulators. Repeat the assessment yearly or on major changes.

Starting small is fine

Your first risk assessment does not have to be perfect. A simple version on one page is infinitely better than none. It brings focus: you suddenly know where to direct your energy.

Do it together?

We guide businesses in Limburg through a practical risk assessment that fits their size, and translate the outcome into concrete steps. See our consultancy & advice service or book a conversation.

Read more

Consultancy ·

Cyber insurance for SMBs: necessary or not?

Cyber insurance can soften the blow of an incident, but it covers far from everything. What it is and is not for, and what to watch in the small print.

Read more 2 min read

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.