All insights
Cyber Risk & Strategy May 29, 2026 7 min read

Conducting a Cybersecurity Risk Assessment

Every organisation makes security decisions, whether deliberately or by default. The ones that do it deliberately start with a risk assessment: a structured way of working out what could go wrong, how likely it is, how much it would hurt, and therefore what deserves attention first. Done well, it turns an overwhelming list of threats into a ranked set of decisions a board can actually make.

This guide sets out how to conduct a cybersecurity risk assessment that produces real decisions rather than a document that sits on a shelf, with reference to the two frameworks Australian organisations most commonly align to: ISO 27005 and NIST SP 800-30.

Why frameworks matter

You do not need to invent a method. Two established frameworks describe how to do this well, and using one gives your assessment structure, defensibility and consistency over time.

ISO 27005 provides guidance on information security risk management and underpins an ISO 27001 management system. It is process-oriented and the natural choice if you are pursuing or hold ISO 27001 certification. NIST SP 800-30, part of the broader NIST family, is detailed, practical and freely available, and is common in government and sectors influenced by US standards. The two are compatible in approach. Pick the one that fits your existing obligations and frameworks, and apply it consistently. The steps below reflect the common ground between them.

Step 1: Identify and value your assets

You cannot assess risk to things you have not identified. The first step is to build an inventory of what matters: not just servers and laptops, but the data, applications, services and processes that the organisation depends on. Include cloud services and third-party systems, which are easy to overlook precisely because they sit outside your walls.

For each asset, capture its value to the business in terms of confidentiality, integrity and availability. Which data would be damaging if exposed? Which systems would halt operations if unavailable? Which records would cause harm if altered? This valuation is what lets you focus the rest of the assessment on what counts, rather than treating every asset as equally important.

Step 2: Identify threats and vulnerabilities

With assets understood, identify what could harm them. It helps to separate two ideas. A threat is a potential cause of harm: a ransomware crew, a malicious insider, a phishing campaign, a hardware failure, even a flood in the data centre. A vulnerability is a weakness that a threat can exploit: an unpatched server, an account without MFA, an over-privileged user, a process with no checks.

Risk arises where a credible threat meets a real vulnerability. Draw on multiple sources: the Australian Cyber Security Centre’s threat advisories, your own incident history, vulnerability scans, penetration test results and the experience of the people who run each system. Be concrete. “Cyber attack” is not a usable threat; “ransomware encrypting unsegmented file servers via a phished credential” is something you can assess and treat.

Step 3: Analyse likelihood and impact

This is the heart of the assessment. For each risk, you estimate two things: how likely it is to occur, and how much harm it would cause if it did. Risk is the combination of the two, often expressed simply as likelihood multiplied by impact.

Most organisations use a qualitative scale, for example rating both likelihood and impact from one to five, and plotting the result on a risk matrix. This is perfectly defensible and far more practical than spurious precision. To keep ratings consistent, define what each level means before you start. Agree, for instance, what “high impact” represents in dollar terms, hours of downtime, number of affected records or reputational damage. Without shared definitions, ratings drift between assessors and the results lose credibility.

Crucially, impact must be judged by the business, not by IT alone. The people who own a process understand what its loss actually costs. Bring them into this step, because their input is what makes the priorities believable to leadership.

Step 4: Evaluate and prioritise

Now compare each risk against your organisation’s risk appetite, the level of risk leadership is willing to accept. Risks above the threshold demand action; those below it may be tolerable. The output is a ranked register that tells you, clearly, which risks to address first.

This prioritisation is the single most valuable product of the whole exercise. Security budgets are finite, and a ranked register lets you spend them where they reduce the most risk, rather than on whatever felt urgent or was easiest to buy.

Step 5: Decide on risk treatment

For every risk above appetite, make a deliberate decision. There are four recognised options, and each risk should be assigned one, with an owner and a date.

  • Mitigate. Reduce the risk by adding or strengthening controls. The Essential Eight is an excellent source of high-value mitigations for the most common threats, addressing patching, MFA, application control and backups.
  • Transfer. Shift some of the risk to another party, typically through cyber insurance or by contracting a specialist provider. Note that transfer rarely removes all of the harm, particularly reputational damage.
  • Avoid. Stop the activity that creates the risk, for example by decommissioning an end-of-life system or declining to collect data you do not need.
  • Accept. Consciously tolerate the risk where the cost of treatment outweighs the benefit. Acceptance is legitimate, but it must be a documented, signed-off decision, not an oversight.

Whatever the choice, record it. An assessment without owned, dated treatment decisions is an analysis, not a risk management process.

Step 6: Monitor, review and repeat

Risk assessment is a cycle, not an event. Your environment changes constantly: new systems arrive, threats evolve, controls degrade and the business shifts direction. Review the risk register regularly, track treatment actions to completion, and reassess fully at least once a year or whenever something material changes, such as a merger, a major new system or a significant breach. The register should be a living document that leadership revisits, not a report filed and forgotten.

Inherent risk, controls and residual risk

One distinction repays the effort of getting right: the difference between inherent and residual risk. Inherent risk is the level of risk before any controls are considered, the raw exposure if nothing were protecting the asset. Residual risk is what remains after your existing controls are taken into account. The gap between the two is the value your current controls deliver.

This matters because it is residual risk that you compare against your appetite and treat. Assessing inherent risk first, then crediting the controls actually in place, forces you to verify that those controls work rather than assuming they do. A backup policy that exists on paper but has never been tested provides little real reduction, and a clear-eyed residual assessment will expose that. The exercise also reveals where you are over-investing: controls layered on a low-impact asset that was never a priority.

Qualitative or quantitative analysis

Most organisations assess risk qualitatively, using descriptive scales and a matrix, and for good reason: it is fast, accessible and good enough to drive sound prioritisation. But it has limits. Two risks both rated “high” may differ enormously in real terms, and qualitative ratings can struggle to justify a large investment to a finance-minded board.

Quantitative analysis expresses risk in money and probability, for example an estimated annual loss expectancy for a given scenario. It demands more data and effort, but it produces figures a board can weigh against the cost of treatment and against other business risks. A pragmatic approach is to assess most risks qualitatively and reserve quantitative analysis for the handful of top risks where a large spending decision hangs on the answer. You do not need to choose one method for everything.

Avoiding the common traps

A few patterns separate useful assessments from box-ticking ones. Keep risks concrete and specific rather than vague. Involve the business, not just IT, so impact ratings reflect reality. Define your rating scales before you start to keep them consistent. And always close the loop with owned, dated treatment decisions, because an assessment that does not change behaviour has achieved nothing.

How CISO Advisory can help

A risk assessment is only as valuable as the decisions it drives, and the hardest part is often translating technical findings into language a board can act on. CISO Advisory conducts independent cybersecurity risk assessments for Australian organisations across government and local council, financial services and enterprise, aligned to ISO 27005 or NIST as suits your obligations. Through our Virtual CISO service we can also own the resulting risk register and treatment program over time, and our work pairs naturally with cyber due diligence where a transaction is involved. To arrange an assessment, call 07 2112 8502 or visit our contact page.

Frequently asked questions

What is a cybersecurity risk assessment?

A cybersecurity risk assessment is a structured process for identifying what an organisation needs to protect, the threats and vulnerabilities that could harm it, and the likelihood and impact of each risk. The result is a prioritised view of risk that informs decisions about where to invest, what to fix first and what to accept.

What is the difference between ISO 27005 and NIST for risk assessment?

Both describe sound risk assessment methods. ISO 27005 supports an ISO 27001 information security management system and is process-oriented and certification-friendly. NIST SP 800-30 is detailed, freely available and widely used in government and US-influenced sectors. The methods are compatible; choose the one that aligns with your existing framework and obligations.

How often should we conduct a risk assessment?

At least annually, and whenever something material changes: a new system, a merger, a significant breach, a regulatory change or a shift in the threat landscape. Treat risk assessment as an ongoing cycle rather than a once-a-year compliance exercise, because the environment it measures changes constantly.

Who should be involved in a risk assessment?

More than the IT team. Effective assessment needs input from business owners who understand the impact of losing a system, from people who run the affected processes, and from leadership who own risk appetite. IT or security can facilitate, but business context is what makes the impact ratings meaningful and the priorities credible.

What is risk treatment?

Risk treatment is the decision about what to do with each identified risk. The four options are: mitigate it by adding controls, transfer it through insurance or a third party, avoid it by stopping the risky activity, or accept it consciously when the cost of treatment outweighs the benefit. Every assessed risk should have a documented, owned decision.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act