Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 6 of 15
A basic risk assessment and management method

On this page
- Introduction
- Step 1 – Establish the context for risk management
- Step 2 – Define a scope for your risk assessment
- Step 3 – Understand your assets and assess impact
- Step 4 - Assess the threat
- Step 5 – Assess your vulnerability
- Step 6 – Estimate likelihood
- Step 7 – Assess cyber security risk
- Step 8 – Prioritise risks and propose risk management action
- Step 9 – Develop a risk treatment plan
- Step 10 – Develop an assurance plan
- Step 11 – Continually iterate and improve
Basic cyber risk assessment, analysis, and management method.
Introduction
This section is for readers who are new to cyber security risk management, or want guidance on a basic step-by-step approach to risk management. The following steps provide a generic and introductory set of steps that can be used to help you better understand the cyber security risks you face, inform and prioritise your risk management responses to those risks.
Health warning #1
The steps covered here are not taken from any single method, standard, approach, or technique. The steps provided below are intended to be introductory in nature and will not alone provide the risk management insight needed to effectively manage cyber risk in large and complicated contexts; they are only suitable for use as a starting point for organisations that are just beginning their cyber security risk management journey. For all these reasons and more, these steps are not intended to be considered as the NCSC’s approved cyber security risk management method.
Step 1 – Establish the context for risk management
In this first step you should think about the things that might influence and direct the cyber security risk management decisions and choices you make. These things are likely to include your organisation’s business priorities and objectives, who or what those things should be protected from (for example, do you need to protect systems and services in the context of the threat model for OFFICIAL information, or is our service or system attractive to cyber criminals or state actors for some reason), any legal and regulatory obligations that apply to your organisation, and the cyber security risk red lines your organisation will and won’t cross to complete the things it needs to do. This context should be expressed in ways that help people understand how cyber security risks should be managed by, as a minimum, expressing a top-down perspective of what absolutely needs to be protected and why, and by providing a statement about the kinds of risks that the organisation would be willing to tolerate and why, and those that they will not. This information will help those charged with making risk management decisions work effectively and confidently.
Step 2 – Define a scope for your risk assessment
Before setting out on any risk assessment activity it is important that you define the scope of what you are assessing. The scope of assessment should define the boundaries of the existing system you are assessing or the new system that is being built, and your scope should clearly define all the assets that are to be contained within it. When expressing the scope of your assessment it can be useful to create a model diagram. This can help enormously in terms of conveying and describing the scope.
As well as expressing the boundaries of your assessment it is also useful for any model of a system’s scope to describe:
- any interconnections both internal within your scope and externally with other systems, services, or organisations
- the boundaries within which you or your organisation can exert control over the assets and systems within it and where you cannot
- any external systems, services, or organisations which the system within the scope of your assessment relies upon in some way
An example scoping diagram is shown below where the scope of a risk assessment is a member of staff’s access to a cloud-based application. This clearly shows the key system components, actors, connections, that are in scope, and what is explicitly out of scope.
Step 3 – Understand your assets and assess impact
This step is about building your understanding of the things you care about and what should be protected. To help with this you could build a register of assets that could include (for example) the equipment, systems, services, software, information and/or processes that are critical to the successful delivery of your business objectives. An important part of this step is to identify and to record ownership of each asset (or groups of assets) within your organisation. This is important because asset owners are key to helping understand the impacts related to their assets, and they are responsible and accountable for what happens to their assets, how they are used and how risks affecting them should be managed.
Now that you have a list of the assets, or things you care about, you should now assess what the impact would be should those assets be, in some way, compromised. Compromise may include someone reading, changing, or deleting information or data that they are not supposed to, someone interfering with the way a system or service works, and losing the ability to use a system, service or information at all because of some failure or cyber security attack. You should express asset impact in ways that are meaningful for you and so that the importance of those assets can be understood in the context of all your business assets. We recommend that you develop a risk register to help you document your assets, identify who is responsible for them, and record how valuable they are to your business.
An asset register might look something like the following table where assets and their ownership are clearly identified along with an assessment and rating of impacts. Care needs to be taken to clearly document the meaning behind any labels used to rate impacts. For example a High impact may mean a complete loss of ability to meet an organisation’s objectives, whereas a Low impact may mean an inconvenience or minor disruption to the operation of an organisation.
Table 1: Example asset register
| Asset ID | Description | Impact assessment |
|---|---|---|
| 0001 | Owner: IP owner Intellectual property - The designs and other intellectual property (IP) information relating to our primary product. | Impact rating: High Unauthorised release, modification, or loss of access to our IP would likely cause us to lose competitive advantage over our competitors causing financial harm to the organisation. |
| 0002 | Owner: IT owner Corporate IT system – this system provides office automation, storage, and processing of business information (including IP and staff information), communication with customers and access to the Internet. | Impact rating: Medium Unauthorised access to our corporate system or any failure in its availability or in the way it works would mean that we will not be able to meet our organisational objectives or deliver against our contractual, legal, or regulatory responsibilities. |
| 0003 | Owner: HR owner HR and staff information - this is sensitive personal information relating to staff and their employment. | Impact rating: High Unauthorised release, disclosure, change or deletion of this information may lead to sanction under privacy laws and/or loss of trust and reputation with staff. |
| 0004 | Owner: OT owner OT and ICS system – this is the system used to produce and control the production of our primary product | Impact rating: High Any change to the way these systems work, failure, or denial of their availability would mean that we are unable to produce our primary product resulting in financial and reputational losses for the business. |
| 0005 | Owner: Owner of corporate sales Online sales service - This is the systems and services we use to sell our primary products to our customers. This system includes our website, payment services, stock control and inventory systems, customer datasets, and our delivery services. | Impact rating: High Unauthorised access to or release of the customer information stored and processed by this system, unauthorised change to the way it works, unavailability of the system and its services or fraudulent use of it would likely result in financial loss for the organisation, damage to our reputation and legal or regulatory sanction. |
Step 4 - Assess the threat
This step is about understanding two things,
- Who or what might pose a threat to your organisation and its objectives.
- How they might go about attacking or otherwise compromising the things you care about.
To achieve the first objective of this step you should seek out authoritative sources of threat information that can help you understand who might seek to do you and your organisation harm, and why. This threat information could come from national authorities such as the NCSC or NPSA, from vendors and or industry groups or be based on historical knowledge about who has attacked organisations such as yours, or your sector. If you are unsure about how to go about describing and communicating information about your threats and threat information in a consistent and repeatable way, then STIX v2.1 from the Oasis Open organisation provides a useful vocabulary.
Health Warning #2
It is not practical, cost effective or in most cases even possible to protect your systems and services from every potential threat actor. It is therefore important that you link your analysis and assessment of threat to the context you established in step 1, so that it is clear who exactly you are trying to protect your system and service from and why. For example, if your organisation has decided that your system or service needs to be protected in accordance with the threat model for OFFICIAL information then you might consider threat actors such as hacktivists, journalists, hackers, criminals and criminal gangs to be relevant and in scope, but you might consider state actors to be out of scope because your organisation has made a risk based decision not to seek assurance that your system or service is protected against them. In a different context, the system or service you are dealing with might enable the sale of goods or the payment of money online, meaning that it might be appropriate for your organisation to consider well-resourced online criminal gangs to be the high bar for the threats actors you need to protect the system or service from.
The next step is to build an understanding of how threats might attack you and the tactics and techniques they might use against your organisation and the things you are trying to protect. Techniques such as threat modelling alongside the use of mnemonics such as STRIDE, cyber kill chains, development of attack trees and publicly available knowledge bases of threat information (such as MITRE ATT&CK) can be extremely helpful in building this understanding and inform your further assessment of cyber security risk.
If you are not sure how to document your threat analysis or have no means to rate one threat against another then you could consider making use of a simple 3x3 matrix where threat capability, motivation, and threat itself are scored on a simple Low to High scale.
Table 2: Example threat analysis
| MOTIVATION | |||
|---|---|---|---|
| CAPABILITY | Low | Medium | High |
| High | Medium | High | High |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
Health Warning #3
You should be aware that whilst matrices are easy to use, they can lead to errors and miscommunication of risk if not used carefully. If you are going to make use of a matrix such as the one shown above, then ensure that you carefully communicate the meaning of your scales and any labels used.
Step 5 – Assess your vulnerability
Vulnerabilities can exist in people, processes, places and technology and these vulnerabilities may be exploited by threat actors to achieve their aims and objectives. There are several techniques and resources that can help you assess your vulnerabilities:
- you could use good guidance such as the NCSC’s Secure system administration guidance, secure design principles or cloud security guidance to help you think about where vulnerabilities might exist in the systems and service you use
- you could build attack trees to help you understand the steps a threat actor would need to take in order to achieve their aims and objectives
- you could make use of catalogues or databases of publicly disclosed technology vulnerabilities (for example MITRE’s Common Vulnerability Enumeration [CVE] database) to help you understand the vulnerabilities that are known about affecting the technology you use
- you could use the knowledge bases of threat information, such as MITRE ATT&CK to help you understand more about the vulnerabilities that are exploited as part of a real world and known attack
- you could assess vulnerability in terms of the ease by which a vulnerability could be exploited, how widespread a vulnerability is across your organisation and its systems, and how easy it is for a threat actor to know or assume that you have a vulnerability affecting your systems and services
If you are not sure how to document your vulnerability analysis or have no means to rate one vulnerability against another then you could consider making use of a simple 3x3 matrix where threat exposure, exploitability, and the vulnerability itself are scored on a simple Low to High scale.
Table 3: Example vulnerability analysis
| EXPOSURE TO THREAT | |||
|---|---|---|---|
| EASE OF EXPLOITATION | Low | Medium | High |
| High | Medium | High | High |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
Step 6 – Estimate likelihood
Combine your analysis of threat and vulnerability in some way to arrive at an assessment of how likely it is that a particular threat would make use of a particular tactic or technique to exploit a vulnerability to achieve their aims and objectives, and thereby causing an impact to occur.
Likelihood is an estimate about the chance of something happening, likelihood can be described on a scale where 0 is no chance of something happening and 1 is certainty that something will happen, with various states of certainty/uncertainty as scale intervals in between. Likelihood can also be expressed as a percentage chance of something occurring with 0% being no chance to 100% being certainty that something will happen. These scales can be represented using labels, for example Low, Medium, and High.
When thinking about likelihood you should seek out information on what effect these threats, vulnerabilities and attacks are having on other organisations, or sectors, that are like yours. For example if your competitors or partner organisations that you work with are suffering similar attacks then it is safe to say that you will likely be attacked too.
An alternative approach to estimating likelihood is to consider it to be some product of a threat’s motivation and capability, how easy a vulnerability is to exploit, and your exposure to it. A simple way to document and analyse likelihood in this context is to use a matrix as shown below where threat and vulnerability ratings, along with likelihood are scored and expressed on a simple Low to High scale.
Table 4: Example likelihood analysis
| VULNERABILITY RATING | |||
|---|---|---|---|
| THREAT RATING | Low | Medium | High |
| High | Medium | High | High |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
However you decide to estimate, analyse and describe likelihood you should remember that risk management is an exercise in working with uncertainty. This means that we need to take care to not give decision makers a false sense of certainty through the estimates, assessments or ratings we apply to any of the components of risk (that is, threat, vulnerability, impact and likelihood). This can be achieved by helping decision makers understand the methods, processes and information that have been used to analyse, assess and rate components of risk, such as likelihood, and by communicating risk in a meaningful way. This is discussed in more detail in the next step.
Step 7 – Assess cyber security risk
A cyber security risk is a future event, related to the use of technology systems and services, that might have some form of impact on someone, a system, a business, or an organisation. In contrast to risk management in other business areas, say in the financial world, in the cyber security world we consider this future event relating to our use of technology. Harms might include the traditional impacts relating to the confidentiality, integrity, and availability of information assets, but organisations and businesses should not constrain their thinking to these information asset qualities only. The harms could include the correct operation of a system or service, its availability, the good reputation of a business, a failure of an organisation to meet its legal, regulatory, or contractual responsibilities or financial impacts.
As discussed earlier, to improve your understanding and assessment of a cyber security risk and how they might be realised, you might find it helpful to conduct some threat modelling, or to build some attack trees. Publicly available sources of information detailing technology vulnerabilities and attacks such as Common Vulnerability Enumeration List and the ATT&CK knowledge base, both provided by the MITRE corporation, may also be helpful to you in helping you understand what could go wrong, and how.
To arrive at a qualitative level of risk we can combine in some way your estimate of likelihood (which encompasses threat and vulnerability) with your assessment of impact to arrive at a risk. Ensure that your risk is communicated in a meaningful way and that you convey the uncertainty associated with your assessment of risk.
If you are not confident enough to write a risk statement freely based on the threat, vulnerability and impact information you have considered, or you do not know how to go about combining them to result in a risk rating then you might consider using a simple matrix such as the one below where likelihood and impact assessments are combined to result in a rating for risk. This risk rating can then be used to help you communicate the significance of an identified risk to a decision maker or to prioritise one risk amongst others.
Table 5: Example risk statement
| IMPACT RATING | |||
|---|---|---|---|
| LIKELIHOOD RATING | Low | Medium | High |
| High | Medium | High | High |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
Communicating and documenting your risks
Ensure that you communicate risks in a meaningful way using risk statements that enable decision makers to understand the timescales and uncertainty that is involved.
When describing risks to decision makers it is important that you communicate to them the certainty or uncertainty surrounding your analysis. Not to do so would communicate to decision makers that you are completely certain that a risk would be realised as you describe. For example, a risk statement that recognises uncertainty could look something like this:
“There is a High or 80% chance (give or take 10%) of us being targeted by a cyber criminal gang using a ransomware attack in the next 12 – 24 months. If a ransomware attack were to be successful it could deny us access to our IT and OT systems completely leaving us unable to communicate with customers and partners, make our products or deliver our services for a period until access to our systems and information is restored, costing us around £1-2M per day.”
You can see from this statement that there is uncertainty in our assessment of likelihood, timescale, and impact.
Step 8 – Prioritise risks and propose risk management action
During this step you should review the whole set of risks you came up with during the previous steps and prioritise them for risk management. As an analyst and as part of this process, you will need to recommend to the business ways in which the risks you have identified can be most effectively managed. For instance, you could recommend that the business:
- treats the risk using some sort of technical or non-technical cyber security control
- avoids the risk by changing or stopping the activity that led to the risk existing
- transfers the risk by transferring responsibility for dealing with its financial impact to a third party (for example via insurance), noting that transferring risk through cyber insurance only deals with the financial impacts of a risk being realised; other aspects and impacts of a risk, such as reputation, legal or regulatory impacts, would need to be managed in other ways
- accepts the risk and does nothing, whilst accepting that they will have to deal with the consequences of a risk should it be realised as your analysis has described
This step also provides a useful opportunity to remove or combine duplicate risks, and to identify links and relationships between risks. For example a successful denial of service risk may be reliant on a phishing or malware risk being realised initially. See below a table that illustrates how a prioritised list of risks might be presented.
Table 6: Example of prioritised risks
| Risk ID | Risk description | Risk level |
|---|---|---|
| R0001 | There is a risk that cyber criminals will successfully conduct a ransomware attack, denying our users access to our corporate IT systems and the information they store and process, impacting our ability to deliver our core services. | High |
| R0002 | There is a risk that cyber criminals will successfully conduct a ransomware attack, denying our users access to our corporate IT systems and the information they store and process, impacting our ability to deliver our core services. | High |
| R0003 | There is a risk that an insider could use their authorise access to intentionally copy and release externally sensitive business information causing us to lose revenue through loss of IPR and reputation. | Medium |
Step 9 – Develop a risk treatment plan
Where you have recommended that cyber security risk be treated using technical or non-technical controls, it is necessary to document and describe those controls, providing as far as possible guidance and information on how they could/should be implemented. When thinking about the controls you might seek to apply, it can be useful to consider the use of standards or schemes that provide a baseline of good controls. For example those provided by the International Standards Organisation (ISO) or the NCSC’s Cyber Essentials scheme. What ever controls or controls baseline you choose to apply care should be taken ensure that they are applied intelligently and proportionately to avoid situations where controls are being applied unnecessarily or worse where controls are not effectively helping to manage risk. Whilst a real risk treatment plan would include much more detail around a proposed treatment and how it should be implemented, a basic treatment plan may look something like this:
Table 7: Example risk treatment plan
Risk ID Risk description Risk impacts | Risk treatment ID Proposed risk treatment (PRT) | Implementation guidance / compliance / standards |
|---|---|---|
ID: R0001 Description: Ransomware Risk Impacts: Confidentiality of information and availability of business systems. | ID: RT0001 PRT: System and information backups
| Mitigating malware and ransomware attacks (NCSC)
Device security guidance (NCSC) |
ID: RT0002 PRT: System hardening and lockdown | ||
ID: RT0003 PRT: Sign up to NCSC ACD services | ||
ID: RT0004 PRT: Enable MFA | ||
ID: RT0005 PRT: Vulnerability management | ||
ID: RT0006 PRT: Incident management | ||
ID: R0002 Description: Phishing Risk Impacts: A phishing attack could impact the confidentiality, integrity and availability of the systems, services and information we rely upon. | ID: RT0007 PRT: Employ anti-spoofing measures (incl. DMARC, SPF and DKIM) | Phishing attacks: defending your organisation (NCSC) |
ID: RT0008 PRT: Mail filtering and blocking | ||
ID: RT0009 PRT: Suspicious email reporting | ||
ID: RT0010 PRT: User training | ||
ID: RT0011 PRT: Password management and MFA | ||
ID: RT0012 PRT: Incident management | ||
Step 10 – Develop an assurance plan
Assurance is a means of providing confidence that the things we care about are protected and that security controls are working individually and together in the way you expect to ensure the security of the system. Assurance should be continually sought from the controls (whether these are procedural, physical, personnel or technical) you apply to treat cyber security risks. Gaining this confidence in your risk treatments - through the effective use of assurance activities - is therefore essential for managing cyber risks. To complete this step you will need to think about how you are going to gain and maintain assurance in the security controls you have proposed. Assurance can be sought:
- in the way security controls work in combination to protect a business outcome, system or service we care about. For example through design reviews, architectural reviews, security testing etc.
- in the way controls have been designed
- in the way controls have been implemented
- in the way controls are used
- through the testing of controls
- in the people that use and manage your systems and services
- in the places you work and that house your systems and services
- in your business processes and in the technology systems and services you use
You should ensure that you have thought about assurance for all the controls you have recommended, and an assurance plan may look like the following table.
Table 8: Example assurance plan
| Risk treatment ID | Proposed risk treatment | How we will maintain assurance or confidence in controls |
|---|---|---|
| RT0001 | System and information backups | We will take full and incremental backups at least weekly; these will be a mix of online and offline backups that are stored in a secure facility. The backups themselves and restore processes will be tested regularly. |
| RT0002 | System hardening and lockdown | Systems will be secure by design, architectures and designs will be reviewed by internal and external subject-matter experts; systems and services will be security tested prior to deployment and regularly once in service. |
| RT0003 | Sign up to NCSC ACD services | Enrolment with applicable NCSC ACD services will be checked as part of regular security testing processes. |
| RT0004 | Enable MFA | Apply MFA in accordance with NCSC and other good practice - systems and services will be security tested prior to deployment and regularly once in service. |
| RT0005 | Vulnerability management | Systems and services will be subject to pre-deployment and regular in-service vulnerability scanning. |
| RT0006 and RT0012 | Incident management | Our incident management plans will be developed in accordance with NCSC’s guidance on IM. |
| RT0007 | Employ anti-spoofing measures (incl. DMARC, SPF and DKIM) | We will test our mail security using NCSC’s mail check service. |
| RT0008 | Mail filtering and blocking | Our mail filtering and blocking setting will be tested as part of pre-deployment and in-service security testing. |
| RT0009 | Suspicious email reporting | As part of our regular security testing, a random selection of users will be asked to describe how they would protect themselves and the business from phishing and what they would do should the receive a suspicious e-mail. |
| RT0010 | User training | As for RT0009 above. |
| RT0011 | Password management and MFA | We will apply password and authentication policies in accordance with NCSC’s and other good practice. Password policies and rules will be checked as part of pre-deployment and in service security testing. |
Step 11 – Continually iterate and improve
It is important that you consider risk assessment and management to be a continuous process. Not to do so would mean that you will quickly fail to adapt your systems, services, and security to address new technologies and emerging threats. This means that you should revisit your cyber security risk assessments and your controls at regular intervals and immediately when something significant changes. A change that might prompt a review could include a change in the threat, or a significant change in the way a system or service is used.


