Many organisations conduct risk assessments as a matter of routine. But following a routine is not the same as producing a robust, defensible assessment. A defensible risk assessment is based on solid, documented evidence that can withstand critical questions from auditors and the board. The difference between completing a checklist and conducting a meaningful assessment is rarely a lack of intent. It lies in the process behind it.
Article 21 of NIS2 requires essential and important entities to implement appropriate and proportionate measures for managing cybersecurity risks. These measures include policies on risk analysis and information system security.
In practice, this requires a consistent, documented approach. Ad hoc assessments without an established method are no longer sufficient — either from a regulatory or an operational perspective. This places new demands on how risk assessments are organised. The answer is not to add more fields to a form, but to bring the right knowledge into the process at the right time.
Risk assessments often become superficial because one person — typically an IT or compliance professional — is left to assess both the likelihood and business impact of an incident involving a system they only know from one perspective.
The solution is a clear division of responsibility:
Without both perspectives, you may underestimate the business impact or overestimate the technical risk. Either way, you are left with a conclusion that is difficult to defend.
Another common mistake is assessing every asset to the same level of detail. A low-criticality system does not require the same depth of analysis as a core application that keeps the business running.
A more efficient approach is to divide assessments into levels:
This approach saves time on low-risk assets without compromising quality where the potential exposure is greatest.
Use the Right Method for Each Assessment
A structured approach that differentiates between high-level and threat-based assessments makes it easier to focus your time where it matters most.
Download the ISO 27005-based risk management guide
A risk rating without a written rationale is difficult to trust — and almost impossible to defend to someone else.
If a risk is rated as ‘Medium’ rather than ‘High’, the reasoning should be clear. What considerations informed the assessment? Which controls were taken into account? Was any relevant information unavailable at the time?
The written rationale turns an instinctive judgement into a defensible assessment. It is also what you need when an auditor, a new colleague or a supervisory authority asks how you reached your conclusion.
A defensible risk assessment is not created in isolation. You can reach a faster and more accurate conclusion by drawing on information you already have:
Even the most thorough risk assessment becomes outdated. Systems change, new vendors are introduced and the threat landscape evolves. An assessment completed two years ago may say very little about your exposure today.
Establish a regular annual review cycle and supplement it with event-driven assessments. A change of vendor, a significant organisational change or a security incident should trigger a new assessment rather than waiting for the next scheduled review.
The most reliable way to improve quality is to make the right process easy to follow. When threat catalogues, control overviews, incident histories and vendor data are available in the same system as the assessment itself, that knowledge becomes a natural part of the process — instead of being overlooked when time is limited.
Connecting risk management and vendor management in one platform ensures that assessments are based on the same up-to-date information. The supporting rationale is also readily available whenever someone asks how you reached your conclusion.