Cybersecurity risk assessment scope and priorities

A cybersecurity risk assessment should identify the systems and data your organisation depends on, the threats and weaknesses that could affect them, the controls already in place and the actions that will reduce risk. The final result should be a prioritised business plan with clear owners and target dates.

What should a cybersecurity risk assessment include?

It should cover business-critical systems, sensitive data, identity and access, Microsoft 365, endpoints, email, networks, mobile and remote working, backups, recovery, employees, suppliers, monitoring, vulnerabilities and incident response. Each significant finding should explain likelihood, business impact, existing controls, recommended action, priority, owner and target date.

In this guide

START WITH THE BUSINESS

What Is a Cybersecurity Risk Assessment?

A cybersecurity risk assessment is a structured review of the threats, vulnerabilities and controls affecting an organisation’s technology and information. It should help leaders answer three practical questions: what are we protecting, what could realistically go wrong and what should we address first?

Useful assessment

Connects technical findings to operational, financial, customer, compliance and reputational impact, then gives management a clear order of action.

Weak assessment

Uses a generic checklist, focuses on products such as antivirus and leaves the business without priorities, owners or a remediation plan.

The objective is a defensible understanding of risk. It is not a promise that every threat can be eliminated.

UNDERSTAND WHAT MATTERS

Which Systems, Data and Threats Should Be Assessed?

SYSTEMS

Critical services

Identify Microsoft 365, email, finance, CRM, ERP, specialist applications, servers, cloud platforms, connectivity and telephony that operations depend on.

DATA

Important information

Map customer, employee, payroll, financial, supplier, legal, project and intellectual-property data, including where it is stored and shared.

THREATS

Realistic attack paths

Consider phishing, business email compromise, ransomware, credential theft, malicious or accidental insiders, lost devices, suppliers and data leakage.

IMPACT

Business consequences

Assess downtime, financial loss, privacy harm, customer disruption, regulatory exposure and reputational damage.

OWNER

Business ownership

Record who relies on each service and who can decide how a risk will be treated.

CHANGE

Current context

Include growth, acquisitions, remote work, new systems, supplier changes and previous incidents that alter exposure.

Prioritisation should follow business dependency. A modest-looking weakness in a service that stops operations may deserve more attention than a technically severe issue on an isolated system.

REVIEW THE CONTROL ENVIRONMENT

Which Technical Security Controls Should Be Checked?

Microsoft 365
MFA, Conditional Access, administrator roles, legacy authentication, external sharing, forwarding, suspicious sign-ins and device compliance.
Identity and access
User, administrator, shared, service and third-party accounts; joiners, role changes, leavers, privileges and password management.
Endpoints and servers
EDR or antivirus, encryption, supported operating systems, secure configuration, local administrators and management coverage.
Security updates
Windows, servers, business applications, firewalls and network equipment, including failed patches and unsupported software.
Email protection
Spam, phishing, impersonation, malicious links and attachments, plus SPF, DKIM, DMARC and active alert monitoring.
Network security
Supported firewalls, secure remote access, segmentation, switches, Wi-Fi, guest access and exposed services.
Mobile devices
Encryption, screen locks, MDM or Intune, application controls, remote wipe and lost-device procedures.
Remote working
Managed devices, home networks, public Wi-Fi, VPN use, personal devices and the strength of off-site access controls.

Assessment evidence should be tested where possible. A written policy saying MFA is required is weaker evidence than configuration showing it is enforced for the relevant accounts.

Related guidance includes Accounts and MFA and Devices and Remote Work.

PREPARE FOR DISRUPTION

How Should Backup, Recovery and Business Continuity Be Assessed?

Backup assurance

Confirm what is protected, frequency, retention, storage location, Microsoft 365 coverage, monitoring, immutability where appropriate and whether restores are tested.

Recovery readiness

Define which systems return first, acceptable downtime and data loss, responsible people, technical dependencies and the evidence from recovery exercises.

Business continuity should consider ransomware, cloud and internet outages, device or server failure and supplier disruption. The assessment should identify which processes can continue manually and which depend completely on technology.

A successful backup status is not proof of recovery. The organisation needs evidence that important data and systems can be restored within the required timescale.

PEOPLE, ACCESS AND SUPPLY CHAIN

What Organisational Risks Should Be Included?

AWARE

Security awareness

Review training on phishing, impersonation, passwords, payment changes, data handling and how staff report concerns.

TEST

Phishing exercises

Use results to guide learning, follow-up and improvement over time rather than treating people as a pass or fail statistic.

JML

Joiners and leavers

Check approvals, account creation, device setup, licence allocation, access changes, session revocation and prompt removal.

THIRD

External access

Identify suppliers, contractors and consultants with access, then verify need, MFA, time limits and activity logging.

SUPPLY

Supplier risk

Understand what critical providers can access, what happens if they are compromised and how assurance is obtained.

POLICY

Policies and governance

Review practical policies for acceptable use, identity, remote work, mobile devices, backup, incidents, data and AI use.

See Awareness Training, Phishing and Impersonation and Data and Sharing.

FIND AND HANDLE PROBLEMS

Should Monitoring, Vulnerabilities and Incident Response Be Reviewed?

Yes. Prevention is only part of security. The assessment should determine whether suspicious activity is visible, who reviews alerts and how the organisation responds when a control fails.

Logging coverage
Microsoft 365 sign-ins, endpoint alerts, firewalls, administrator actions, failed logins and critical cloud services.
Alert ownership
Who monitors events, what hours are covered and how urgent activity is escalated.
Vulnerability discovery
Internal and external scanning, patch compliance, configuration reviews, assessments and penetration testing where justified.
Remediation workflow
How findings are validated, prioritised, assigned, tracked and retested.
Incident roles
Leadership, technical containment, management reporting, legal or insurance contacts and external communication.
Response procedures
How devices are isolated, accounts secured, evidence preserved, services recovered and lessons recorded.

Explore Monitoring and Response and Reporting Concerns.

PRIORITISE WITH CONSISTENT RULES

How Should Cybersecurity Risks Be Scored?

A simple likelihood and impact model is often sufficient for a small or medium-sized organisation. The assessment should describe the scoring method so different findings can be compared consistently.

LIKELIHOOD × IMPACT = RISK RATING
Consideration Questions to answer
Likelihood How exposed is the weakness, how easy is exploitation and has similar activity occurred?
Impact Could it disrupt operations, cause fraud, expose data, harm customers or breach obligations?
Existing controls What currently prevents, detects or limits the event, and how reliable is the evidence?
Residual risk What risk remains after current controls are considered?
Priority How quickly should the business act, and what dependencies affect the response?

A risk that is easy to exploit and could stop the business should normally be addressed before a low-impact configuration issue.

TURN FINDINGS INTO DECISIONS

What Should the Final Risk Assessment Report Contain?

1

Executive summary

A concise, non-technical explanation of the current risk position and the decisions management needs to make.

2

Scope and method

Systems, locations, data, people and suppliers reviewed, evidence used, limitations and the scoring approach.

3

Clear findings

Describe each weakness, affected assets, threat scenario, existing controls and supporting evidence.

4

Business impact and rating

Explain why the issue matters and assign a consistent critical, high, medium or low priority.

5

Recommended action

State the practical remediation, expected risk reduction, dependencies and any alternative treatment.

6

Owner and target date

Assign accountability and an achievable completion date so progress can be reviewed.

The report should include a risk register that leaders can maintain, with status, evidence and review dates. A document that cannot be converted into managed actions has limited value.

MOVE FROM REVIEW TO IMPROVEMENT

What Should Happen After the Assessment?

Timeframe Typical focus
Immediate Protect administrator accounts, enforce MFA, address actively exploitable weaknesses and restore failed protection.
Short term Improve email and Microsoft 365 security, remove unsupported technology and strengthen endpoint coverage.
Medium term Improve continuity, vulnerability management, network design, supplier assurance and incident response.
Ongoing Track risk owners, review evidence, retest completed actions and report progress to leadership.

For many small and mid-sized organisations, a formal assessment should be completed at least annually and reviewed after major changes such as an acquisition, new office, cloud migration, serious incident or change of IT provider.

Participants should include people who understand operations, finance, HR, compliance, data and technology. Senior leaders need to understand and accept the final priorities.

QUALITY CHECK

What Are the Warning Signs of a Poor Assessment?

Generic checklist
It does not reflect the organisation’s services, information, people or suppliers.
Product-only review
It concentrates on antivirus while ignoring identity, cloud, backup, recovery and human risk.
No business impact
Findings are technical statements without explaining operational or financial consequences.
No evidence
Conclusions rely on policy or assumption without checking configurations, records or coverage.
No prioritisation
Every issue looks equally urgent, leaving management unable to decide where to invest.
No remediation plan
There are no practical actions, owners, target dates or follow-up arrangements.

FREQUENTLY ASKED QUESTIONS

Questions About Cybersecurity Risk Assessments

Does a small business need an assessment?

Yes. Smaller organisations still depend on email, cloud services, finance systems, customer data and remote access that can create material risk.

How often should it be repeated?

At least annually for many organisations, plus after significant business, technology or threat changes.

Who should be involved?

Operational, finance, HR, compliance, data and technology representatives, with senior management reviewing the main risks.

Is a vulnerability scan enough?

No. Scanning can identify technical weaknesses but does not assess business impact, people, suppliers, recovery or governance.

Should cyber insurance be included?

Yes. Verify that controls such as MFA, EDR, backup, awareness and incident response match declarations and policy conditions.

Does the assessment eliminate risk?

No. It helps leaders understand, prioritise, reduce, transfer or consciously accept risk using better evidence.

Need a Clear View of Your Cyber Risk?

Stratiis can review your users, devices, Microsoft 365 environment, networks, suppliers, backup and continuity arrangements, then provide a prioritised improvement plan.

Discuss a Cybersecurity Risk Assessment

Related Cybersecurity Services and Guidance