Home / Security Program / Risk Assessment

Risk Assessment
(ISO 27005)

A structured information-security risk assessment aligned to ISO 27005 — identifying, analysing, and evaluating your risks, with a risk register and treatment plan ready for the board.

Overview

Decide on risk with evidence.

Good security decisions start with a clear-eyed view of risk: what could go wrong, how likely it is, and what it would cost. A structured risk assessment replaces gut feel with evidence the board can act on.

We run an ISO 27005-aligned assessment — identifying assets and threats, analysing and scoring risk, and producing a risk register and treatment plan with clear options to mitigate, transfer, or accept each risk. It underpins ISO 27001 and satisfies regulators and investors alike.


Coverage

What we deliver.

A structured, defensible view of information-security risk.

Aligned to: ISO/IEC 27005 ISO 27001 NIST CSF

FAQ

Risk assessment FAQ

The questions we're asked most about scope, cost, and timing.

How much does a risk assessment cost?
An ISO 27005-aligned risk assessment is typically €3,000–6,000 depending on scope. Use our estimator for a tailored figure.
What is an ISO 27005 risk assessment?
A structured method to identify, analyse, and evaluate information-security risks, producing a risk register and treatment plan aligned to the ISO 27005 standard.
How long does it take?
Most risk assessments take 2–4 weeks, including workshops, analysis, and a board-ready report.
How is this different from a maturity assessment?
A risk assessment evaluates specific risks to your assets; a maturity assessment scores your capabilities against a framework. Many organisations do both.
Does this support ISO 27001 certification?
Yes — a documented risk assessment and treatment plan are core requirements of ISO 27001, and this deliverable feeds directly into it.
What do we receive?
A risk register, a risk treatment plan, control recommendations, residual-risk analysis, and a board-ready report.
Who needs a formal risk assessment?
Any organisation pursuing ISO 27001, meeting NIS2/DORA, or needing to demonstrate risk-based decision-making to a board, regulator, or investor.
Can you help us treat the risks you find?
Yes — via our security program, compliance, or managed security services, we help execute the treatment plan.

Related services

Explore more.

Ready to quantify your risk?

A 30-minute scoping call costs nothing. An unmanaged risk costs considerably more.

Book a meeting Send an email