Our risk method
Know your risk. Decide deliberately. Prove progress.
Risk management isn’t a spreadsheet you refresh before the audit. It’s how leadership decides what to protect, how much to spend, and which risks to accept. We build that decision-making into your business.
The Risk Ledger
Every engagement produces a living risk register we call the Risk Ledger. Each entry records:
- The asset or business process at risk
- The threat scenario, in plain language
- Likelihood and impact — before and after controls
- The treatment decision and its owner
- Due date and current status
- The controls and evidence that back it up
How we assess risk
The right level of rigor for the decision in front of you.
Qualitative, when you need speed
Consistent 5×5 likelihood-and-impact scoring, aligned to NIST SP 800-30, to rank every risk quickly and defensibly.
Quantitative, when dollars matter
FAIR-based loss scenarios for your top risks — ranges of annualized loss for board, budget, and cyber insurance conversations.
Threat-informed, always
Scenarios grounded in how real attackers operate, using MITRE ATT&CK and the threat landscape for your industry.
Risk treatment
Four ways to handle every risk — chosen on purpose.
Mitigate
Reduce likelihood or impact with controls sized to the risk — no more, no less.
Transfer
Shift financial exposure through cyber insurance and contract terms, with the gaps understood.
Accept
Document a conscious, time-limited decision by the right owner, within your risk appetite.
Avoid
Change or stop the activity when the risk outweighs the business value.
Scenarios we assess most often
Top risks, in business terms.
| Risk scenario | Business impact | Common treatments |
|---|---|---|
| Ransomware disrupts operations | Downtime, recovery cost, lost revenue, extortion | Segmentation, immutable backups, endpoint detection, tested recovery |
| Business email compromise | Fraudulent payments and data theft | Phishing-resistant MFA, payment verification, awareness |
| Third-party breach | Customer data exposure and contractual liability | Vendor tiering, contract terms, ongoing monitoring |
| Cloud misconfiguration | Public exposure of sensitive data | Hardened baselines, posture monitoring, change control |
| Insider misuse | Data theft or sabotage | Least privilege, access reviews, activity logging |
| AI agent misuse | Data leakage or unauthorized actions | Scoped credentials, human approvals, red teaming |
Governance
Risk governance that fits your size.
Good risk management needs a rhythm and clear decision rights — not a bureaucracy. We set up just enough structure for leadership to see, own, and act on information security risk.
- Risk appetite and tolerance statements
- A security steering cadence with the right people in the room
- Risk acceptance and exception process with expiry dates
- Board and executive reporting package
Standards we align to
- NIST CSF 2.0 — including the Govern function for risk strategy and oversight
- NIST SP 800-30 Rev. 1 — guide for conducting risk assessments
- ISO/IEC 27005:2022 — information security risk management
- ISO 31000:2018 — enterprise risk management principles
- FAIR — Factor Analysis of Information Risk, for quantification
- MITRE ATT&CK — real-world adversary behavior
Want a ranked list of your real risks?
A Blueprint engagement delivers your Risk Ledger and a treatment roadmap in weeks, not months.