GuideRisk Management

Your First Risk Assessment: A No-Nonsense Walkthrough

A practical guide to running your first ISO 27001 risk assessment without getting lost in methodology debates.

Updated 12 Mar 2026

Don't Overthink Methodology

Many teams stall on risk assessment because they try to find the "perfect" methodology. ISO 27001 requires a documented, repeatable approach — not a specific one.

A Pragmatic Process

1. Identify Assets

List information assets: databases, applications, documents, people with critical knowledge.

2. Identify Threats & Vulnerabilities

For each asset, ask: what could go wrong? Think about confidentiality, integrity, and availability.

3. Assess Likelihood & Impact

Use a simple scale (e.g., 1–5). Don't agonise over precision — consistency matters more than accuracy.

4. Calculate Risk Level

Likelihood × Impact gives you a risk score. Categorise as Low, Medium, High, Critical.

5. Decide Treatment

For each risk: Accept, Mitigate, Transfer, or Avoid. Document your rationale.

What Good Looks Like

30–80 identified risks for a typical SME
Clear ownership for every risk
Treatment plans with deadlines
Regular review cycle (quarterly minimum)

What Auditors Check

Is the methodology documented and consistently applied?
Are risk owners assigned and aware?
Do treatment plans link to actual controls?
Is the risk register actively maintained (not a point-in-time document)?

Related Modules

Risk Register
Standard Controls

Related Controls / Clauses

6.1.2
8.2
8.3

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.