Skip to main content
Guidance

Risk management

How to understand and manage the cyber security risks for your organisation.

Page 6 of 15

A basic risk assessment and management method

Basic cyber risk assessment, analysis, and management method.


Health warning #1

The steps covered here are not taken from any single method, standard, approach, or technique. The steps provided below are intended to be introductory in nature and will not alone provide the risk management insight needed to effectively manage cyber risk in large and complicated contexts; they are only suitable for use as a starting point for organisations that are just beginning their cyber security risk management journey. For all these reasons and more, these steps are not intended to be considered as the NCSC’s approved cyber security risk management method.





Health Warning #2

It is not practical, cost effective or in most cases even possible to protect your systems and services from every potential threat actor. It is therefore important that you link your analysis and assessment of threat to the context you established in step 1, so that it is clear who exactly you are trying to protect your system and service from and why. For example, if your organisation has decided that your system or service needs to be protected in accordance with the threat model for OFFICIAL information then you might consider threat actors such as hacktivists, journalists, hackers, criminals and criminal gangs to be relevant and in scope, but you might consider state actors to be out of scope because your organisation has made a risk based decision not to seek assurance that your system or service is protected against them. In a different context, the system or service you are dealing with might enable the sale of goods or the payment of money online, meaning that it might be appropriate for your organisation to consider well-resourced online criminal gangs to be the high bar for the threats actors you need to protect the system or service from. 

The next step is to build an understanding of how threats might attack you and the tactics and techniques they might use against your organisation and the things you are trying to protect. Techniques such as threat modelling alongside the use of mnemonics such as STRIDE, cyber kill chains, development of attack trees and publicly available knowledge bases of threat information (such as MITRE ATT&CK) can be extremely helpful in building this understanding and inform your further assessment of cyber security risk.

If you are not sure how to document your threat analysis or have no means to rate one threat against another then you could consider making use of a simple 3x3 matrix where threat capability, motivation, and threat itself are scored on a simple Low to High scale.

Table 2: Example threat analysis
 MOTIVATION
CAPABILITYLowMediumHigh
HighMediumHighHigh
MediumLowMediumHigh
LowLowLowMedium
    

Health Warning #3

You should be aware that whilst matrices are easy to use, they can lead to errors and miscommunication of risk if not used carefully. If you are going to make use of a matrix such as the one shown above, then ensure that you carefully communicate the meaning of your scales and any labels used.








Published

Reviewed

Version

2.0