A cyber risk register is not a vulnerability list. Its purpose is to connect technical conditions to business impact, risk ownership, and decisions. A useful register answers “What should we invest in, what are we accepting, and what is overdue?”
Core fields
- Risk ID
- Clear risk statement
- Affected business asset/process
- Business impact
- Likelihood
- Impact/severity
- Inherent risk
- Risk owner
- Treatment: mitigate / accept / transfer / avoid
- Action owner and target date
- Existing controls
- Closure/improvement evidence
- Residual risk
- Acceptance/exception decision and expiry
- Next review date
How should a risk statement be written?
“Missing patch” is a finding, not a complete risk. A better statement is: “Exploitable vulnerabilities remaining outside SLA on an internet-facing critical service could increase the risk of unauthorized access and customer-service disruption.” It connects technical condition to business effect.
A 5x5 score is not enough by itself
Likelihood x impact can be a practical starting point, but the score should be accompanied by rationale, business context, and control effectiveness. Two risks scoring 15 do not automatically deserve identical priority.
Who should be the risk owner?
Security can coordinate the register, but the business-risk owner is often the decision-maker for the affected product, system, or business function. Risk acceptance should be made by someone with real authority over budget and business impact.
Keep the register alive
Connect monthly/quarterly review, overdue actions, exception expiry, and board reporting. A spreadsheet can be sufficient; operating discipline matters more than buying a risk platform.
Use the in-browser Cyber Risk Register Builder to export a CSV or inspect sample deliverables.
Next step
Instead of only reading, run the related free assessment, identify missing evidence, and then scope advisory work around the decision that is actually required.
Frequently asked questions
Does this guide replace company-specific advisory?
No. It provides a general decision framework; scope, regulatory, contractual, and risk context should be evaluated for the company.
What should the first step be?
Write down the current pressure, decision owner, evidence gap, and the output that should exist in the next 30–90 days.
Sources
This content is educational. It is not legal advice, an audit opinion, or a compliance guarantee.