Skip to content

Risk Registers That Stay Useful

Recording risk so decisions get made, rather than producing a spreadsheet nobody reads.

Editorial team 2 min read

A risk register earns its place only if somebody makes decisions from it. Most do not, for predictable reasons.

Write risks as sentences

A risk is not "phishing". It is a sentence with a cause, an event and a consequence: an employee enters credentials on a phishing page, an attacker signs in to the finance system and initiates payments, costing up to £X before detection. Written this way, the controls and the owner become obvious.

Score for comparison, not precision

Likelihood and impact scales are a way of ranking things against each other. Treat a score as an argument, record the reasoning, and re-score when the reasoning changes. Multiplying two invented numbers to three decimal places does not add rigour.

Give every risk an owner who can act

The owner is the person who can accept the risk or fund the fix — a business owner, not the security team. Security maintains the register; it does not own the risks.

Treatment is a decision with a date

Each risk ends in one of four places: treat, transfer, tolerate or terminate. Tolerating is a legitimate answer when recorded, signed and given a review date. An untreated risk with no decision is just a note.

Keep it small

Fifty live risks is a programme. Five hundred is a filing system. Aggregate the detail into themes and keep the register to what leadership can genuinely consider.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025