Cybersecurity Risk Register
Central register of identified risks, assessments and treatment plans
Colour Legend
R 1–6 Low – Acceptable
R 7–12 Medium – Monitor
R 13–16 High – Treatment required
R 17–25 Critical – Urgent action
L = Likelihood (1–5), I = Impact (1–5), R = Gross Risk (L×I), Rr = Residual Risk after controls.
ℹ️
Each row marked yellow or red must be completed with the organisation's data. Sample rows (R-001 to R-010) contain example risks typical for NIS2 entities – the organisation verifies them, removes irrelevant ones and adds its own.
Risk Register – Main Table
Risks R-001 to R-010: examples typical for NIS2 entities. R-011+: organisation's own risks.
| ID | Asset / System | Threat | Vulnerability | L | I | R | Existing controls | Rr | Strategy | Treatment plan / Measure | Owner | Deadline | Status |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| R-001 | OT/SCADA systems (key services) | Ransomware – encryption of operational systems | No IT/OT segmentation, no patching | 4 | 5 | 20 | Basic antivirus | 16 | Modification | ▸ [Network segmentation, EDR for OT, patching, offline backup] | ▸ [Admin/CISO] | ▸ DD/MM/YYYY | ▸ [Open/In progress/Closed] |
| R-002 | Privileged accounts (AD, servers) | Administrator account takeover – credential stuffing / spear phishing | No MFA, weak passwords, shared accounts | 4 | 5 | 20 | Password policy (min. 8 chars) | 16 | Modification | ▸ [MFA for all privileged accounts, PAM] | ▸ [Admin/CISO] | ▸ | ▸ |
| R-003 | Website / customer portal | DDoS attack – service unavailability | No DDoS protection, single ISP | 3 | 4 | 12 | Basic firewall | 12 | Modification | ▸ [Anti-DDoS service at ISP or CDN, link redundancy] | ▸ [Network Admin] | ▸ | ▸ |
| R-004 | Email / users | Phishing – credential theft or malware installation | No training, no email filtering, no DMARC | 5 | 3 | 15 | Basic spam filter | 12 | Modification | ▸ [Phishing awareness training, DMARC/DKIM/SPF, advanced email filter] | ▸ [CISO / IT] | ▸ | ▸ |
| R-005 | Customer data / database | Data breach – SQL injection or unauthorised access | No WAF, outdated DB engine, excessive permissions | 3 | 5 | 15 | Encryption at rest | 10 | Modification | ▸ [WAF, DB update, permission review, query monitoring] | ▸ [DBA / CISO] | ▸ | ▸ |
| R-006 | Backup systems / copies | Destruction/encryption of backups by ransomware | Online backups, no isolation, untested recovery | 3 | 4 | 12 | Daily backups | 8 | Modification | ▸ [Offline backup (air-gap), 3-2-1 rule, quarterly recovery tests] | ▸ [IT Admin] | ▸ | ▸ |
| R-007 | Suppliers and external services | Organisation compromise via IT supplier (supply chain attack) | No supplier security assessment, broad remote access permissions | 2 | 5 | 10 | NDA agreements with suppliers | 8 | Modification | ▸ [Supplier security assessment per DOC-015, PAM for remote access] | ▸ [CISO / Procurement] | ▸ | ▸ |
| R-008 | Employees / human resources | Insider threat – deliberate or unintentional data disclosure by employee | No activity monitoring, no offboarding procedure | 2 | 4 | 8 | NDA confidentiality agreements | 6 | Modification | ▸ [Offboarding procedure DOC-016, DLP, privileged monitoring] | ▸ [HR / CISO] | ▸ | ▸ |
| R-009 | Server room / physical infrastructure | Unauthorised physical access to server room | Insufficient physical access control | 2 | 3 | 6 | Lock, authorised persons list | 4 | Modification | ▸ [Card access, CCTV, entry log per DOC-018] | ▸ [Facility Manager] | ▸ | ▸ |
| R-010 | SSL/TLS certificates | Certificate expiry – HTTPS service unavailability | No certificate validity monitoring | 3 | 2 | 6 | Manual check once a year | 3 | Acceptance | ▸ [Automated certificate monitoring, alerts 30/7 days before expiry] | ▸ [IT Admin] | ▸ | ▸ |
| R-011 | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ |
| R-012 | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ |
| R-013 | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ | ▸ |
Residual Risk Acceptance
The following residual risks have been consciously accepted by authorised decision-makers:
| Risk ID | Residual Risk (Rr) | Acceptance justification | Accepted by | Date | Review date |
|---|---|---|---|---|---|
| ▸ R-XXX | ▸ [value] | ▸ [cost of control disproportionate / risk within risk appetite] | ▸ [First Last Name, role] | ▸ DD/MM/YYYY | ▸ DD/MM/YYYY |
Summary
| Risk level | Number of gross risks | Number of residual risks | Trend |
|---|---|---|---|
| Critical (17–25) | ▸ | ▸ | ▸ [↑ / ↓ / →] |
| High (13–16) | ▸ | ▸ | ▸ |
| Medium (7–12) | ▸ | ▸ | ▸ |
| Low (1–6) | ▸ | ▸ | ▸ |
| TOTAL | ▸ | ▸ |
CISO Comment on current risk status
▸ CISO completes at each update
▸ [Description of current situation, key risks, RTP progress, changes in threat landscape]
Register Change History
| Version | Date | Author | Description of changes |
|---|---|---|---|
| ▸ 1.0 | ▸ DD/MM/YYYY | ▸ First Last Name | ▸ Initial release – sample risks R-001–R-010 |
| ▸ | ▸ | ▸ | ▸ |
DOC-003 Risk Register | v1.0 | NIS2/ISMS