NorthGRC Blog | GRC, compliance and cybersecurity

How Do You Ensure Your Risk Assessment Is Truly Defensible?

Written by Lone Forland | Aug 28, 2026, 10:57:48 AM

Many organisations conduct risk assessments as a matter of routine. But following a routine is not the same as producing a robust, defensible assessment. A defensible risk assessment is based on solid, documented evidence that can withstand critical questions from auditors and the board. The difference between completing a checklist and conducting a meaningful assessment is rarely a lack of intent. It lies in the process behind it.

 

A Systematic Approach Is a Legal Requirement — Good Intentions Are Not Enough


Article 21 of NIS2 requires essential and important entities to implement appropriate and proportionate measures for managing cybersecurity risks. These measures include policies on risk analysis and information system security.

In practice, this requires a consistent, documented approach. Ad hoc assessments without an established method are no longer sufficient — either from a regulatory or an operational perspective.  This places new demands on how risk assessments are organised. The answer is not to add more fields to a form, but to bring the right knowledge into the process at the right time.

A Common Pitfall: One Person Assesses Everything

 

Risk assessments often become superficial because one person — typically an IT or compliance professional — is left to assess both the likelihood and business impact of an incident involving a system they only know from one perspective.

 

The solution is a clear division of responsibility:

  • Business impact — what an outage or data breach would mean for operations, customers and reputation — is best assessed by the system owner or department manager who understands the business context.
  • Likelihood — how realistic it is that the incident will occur — is best assessed by technical specialists who understand the vulnerabilities and current threat landscape.

Without both perspectives, you may underestimate the business impact or overestimate the technical risk. Either way, you are left with a conclusion that is difficult to defend.

 

Match the Level of Detail to the Risk

 

Another common mistake is assessing every asset to the same level of detail. A low-criticality system does not require the same depth of analysis as a core application that keeps the business running.

 

A more efficient approach is to divide assessments into levels:

  1. High-level assessment: A straightforward assessment of likelihood and impact for less critical assets.
  2. CIA-based assessment: A separate assessment of confidentiality, integrity and availability for assets containing sensitive or otherwise business-critical data.
  3. Threat-based assessment: An in-depth analysis of the most critical assets, where a detailed understanding of individual threats is essential.

This approach saves time on low-risk assets without compromising quality where the potential exposure is greatest.

 

Use the Right Method for Each Assessment

A structured approach that differentiates between high-level and threat-based assessments makes it easier to focus your time where it matters most.

Download the ISO 27005-based risk management guide

 

The Rationale Matters as Much as the Rating

 

A risk rating without a written rationale is difficult to trust — and almost impossible to defend to someone else.

 

If a risk is rated as ‘Medium’ rather than ‘High’, the reasoning should be clear. What considerations informed the assessment? Which controls were taken into account? Was any relevant information unavailable at the time?

 

The written rationale turns an instinctive judgement into a defensible assessment. It is also what you need when an auditor, a new colleague or a supervisory authority asks how you reached your conclusion.

Reuse Existing Knowledge Instead of Starting from Scratch


A defensible risk assessment is not created in isolation. You can reach a faster and more accurate conclusion by drawing on information you already have:

  • Threat catalogues: An up-to-date catalogue provides a structured overview of common threats and supports consistent assessments of likelihood and impact.
  • Incident history: Lessons from previous incidents — whether your own or a vendor’s — provide a more realistic indication of likelihood than a purely theoretical estimate.
  • Existing controls: A risk with effective controls in place should be assessed differently from an uncontrolled exposure. This requires the person conducting the assessment to have access to an up-to-date overview of the relevant controls.

Make Risk Assessment a Recurring Cycle — Not a One-Off Project


Even the most thorough risk assessment becomes outdated. Systems change, new vendors are introduced and the threat landscape evolves. An assessment completed two years ago may say very little about your exposure today.

Establish a regular annual review cycle and supplement it with event-driven assessments. A change of vendor, a significant organisational change or a security incident should trigger a new assessment rather than waiting for the next scheduled review.

Bring the Evidence Together to Improve Quality

 

The most reliable way to improve quality is to make the right process easy to follow. When threat catalogues, control overviews, incident histories and vendor data are available in the same system as the assessment itself, that knowledge becomes a natural part of the process — instead of being overlooked when time is limited.

 

Connecting risk management and vendor management in one platform ensures that assessments are based on the same up-to-date information. The supporting rationale is also readily available whenever someone asks how you reached your conclusion.