Skip to content

Cyber risk assessment

Writing risks people can act on, scoring them honestly, and turning a register into decisions with owners and dates.

Free on glitchdata beginner 4 lessons 53 min

What you'll learn

  • Write a risk as a cause, an event and a consequence
  • Score and rank risks without inventing false precision
  • Record treatment decisions with an owner, a date and an approver
  • Present risk to leadership in terms they can decide on

About this course

Risk assessment is where most security programmes either earn their budget or lose their audience. Done badly it produces a spreadsheet of nouns scored out of twenty-five. Done well it produces a short list of decisions somebody has actually made.

This course covers how to write a risk, how to score it without inventing precision, how treatment decisions get made and recorded, and how to present risk to people who have to choose between it and everything else.

Course content

4 lessons · 53 min

  1. 1
    What a risk actually is

    A cause, an event and a consequence — not a one-word category.

    Free preview 13 min
  2. 2
    Scoring and ranking without false precision

    Likelihood and impact as an argument, not an arithmetic result.

    13 min
  3. 3
    Treatment, ownership and exceptions

    Four possible endings, each with an owner, a date and somebody who signed.

    14 min
  4. 4
    Reporting risk to people who decide

    What leadership needs, what to leave out, and how to show change over time.

    13 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in Cyber security