DOC-003 ← Document Portal

Cybersecurity Risk Register

Central register of identified risks, assessments and treatment plans
Document Number
DOC-003
Register Version
▸ 1.0
Last Updated
▸ DD/MM/YYYY
Next Update
▸ DD/MM/YYYY
Register Owner
▸ CISO
Approved by
▸ Board / CEO
Methodology
DOC-002 (5×5 scale)
Legal Basis
Art. 21(2)(a) NIS2

Colour Legend

R 1–6 Low – Acceptable R 7–12 Medium – Monitor R 13–16 High – Treatment required R 17–25 Critical – Urgent action

L = Likelihood (1–5), I = Impact (1–5), R = Gross Risk (L×I), Rr = Residual Risk after controls.

ℹ️
Each row marked yellow or red must be completed with the organisation's data. Sample rows (R-001 to R-010) contain example risks typical for NIS2 entities – the organisation verifies them, removes irrelevant ones and adds its own.

Risk Register – Main Table

Risks R-001 to R-010: examples typical for NIS2 entities. R-011+: organisation's own risks.

ID Asset / System Threat Vulnerability L I R Existing controls Rr Strategy Treatment plan / Measure Owner Deadline Status
R-001 OT/SCADA systems (key services) Ransomware – encryption of operational systems No IT/OT segmentation, no patching 45 20 Basic antivirus 16 Modification ▸ [Network segmentation, EDR for OT, patching, offline backup] ▸ [Admin/CISO] ▸ DD/MM/YYYY ▸ [Open/In progress/Closed]
R-002 Privileged accounts (AD, servers) Administrator account takeover – credential stuffing / spear phishing No MFA, weak passwords, shared accounts 45 20 Password policy (min. 8 chars) 16 Modification ▸ [MFA for all privileged accounts, PAM] ▸ [Admin/CISO]
R-003 Website / customer portal DDoS attack – service unavailability No DDoS protection, single ISP 34 12 Basic firewall 12 Modification ▸ [Anti-DDoS service at ISP or CDN, link redundancy] ▸ [Network Admin]
R-004 Email / users Phishing – credential theft or malware installation No training, no email filtering, no DMARC 53 15 Basic spam filter 12 Modification ▸ [Phishing awareness training, DMARC/DKIM/SPF, advanced email filter] ▸ [CISO / IT]
R-005 Customer data / database Data breach – SQL injection or unauthorised access No WAF, outdated DB engine, excessive permissions 35 15 Encryption at rest 10 Modification ▸ [WAF, DB update, permission review, query monitoring] ▸ [DBA / CISO]
R-006 Backup systems / copies Destruction/encryption of backups by ransomware Online backups, no isolation, untested recovery 34 12 Daily backups 8 Modification ▸ [Offline backup (air-gap), 3-2-1 rule, quarterly recovery tests] ▸ [IT Admin]
R-007 Suppliers and external services Organisation compromise via IT supplier (supply chain attack) No supplier security assessment, broad remote access permissions 25 10 NDA agreements with suppliers 8 Modification ▸ [Supplier security assessment per DOC-015, PAM for remote access] ▸ [CISO / Procurement]
R-008 Employees / human resources Insider threat – deliberate or unintentional data disclosure by employee No activity monitoring, no offboarding procedure 24 8 NDA confidentiality agreements 6 Modification ▸ [Offboarding procedure DOC-016, DLP, privileged monitoring] ▸ [HR / CISO]
R-009 Server room / physical infrastructure Unauthorised physical access to server room Insufficient physical access control 23 6 Lock, authorised persons list 4 Modification ▸ [Card access, CCTV, entry log per DOC-018] ▸ [Facility Manager]
R-010 SSL/TLS certificates Certificate expiry – HTTPS service unavailability No certificate validity monitoring 32 6 Manual check once a year 3 Acceptance ▸ [Automated certificate monitoring, alerts 30/7 days before expiry] ▸ [IT Admin]
R-011
R-012
R-013

Residual Risk Acceptance

The following residual risks have been consciously accepted by authorised decision-makers:

Risk IDResidual Risk (Rr)Acceptance justificationAccepted byDateReview date
▸ R-XXX ▸ [value] ▸ [cost of control disproportionate / risk within risk appetite] ▸ [First Last Name, role] ▸ DD/MM/YYYY ▸ DD/MM/YYYY

Summary

Risk levelNumber of gross risksNumber of residual risksTrend
Critical (17–25)▸ [↑ / ↓ / →]
High (13–16)
Medium (7–12)
Low (1–6)
TOTAL

CISO Comment on current risk status

▸ CISO completes at each update

▸ [Description of current situation, key risks, RTP progress, changes in threat landscape]

Register Change History

VersionDateAuthorDescription of changes
▸ 1.0 ▸ DD/MM/YYYY ▸ First Last Name ▸ Initial release – sample risks R-001–R-010
DOC-003 Risk Register | v1.0 | NIS2/ISMS