Thiqa

A risk register that points at its controls

Risks, their treatments and the controls that mitigate them, tied together so a treatment plan is something you can evidence.

Request a call →Early access · work email only
One risk, from raised to evidenced treatment

Treatments tied to the controls that carry them

Risk registerRISK-003

Ransomware via an unpatched endpoint

Very highMitigating

Resilience & Insider Threat · owned by A. Hassan · reviewed 04 Aug 2026

Exposure

Inherent

10 / 10

Very high · likelihood 4, impact 3

Residual

4 / 10

Low · likelihood 2, impact 2

Appetite

5 / 10

Residual sits inside appetite

The dashed line shows where treatment moves this risk. Six points of reduction.

Likelihood

54321
InsignificantMinorModerateMajorSevere
InherentAfter treatment

Treatment

Current strategy · Mitigate
Mitigate5Accept1Transfer0

Let Thiqa draft this plan

From the exposure above, Thiqa can write a treatment plan and rank the tasks and controls most likely to bring this risk down. You review everything before anything is saved or linked.

Draft plan and suggest linksStart from scratch
01PlanA concrete plan grounded in the tasks and controls you already have.
02LinksTasks and framework controls, ranked for this risk and proposed for your approval.

Comments

1

N. Khalil4 days ago

Backup restoration test is overdue. Until it passes I would not call residual 4.

Leave a comment, or mention someone with @

Properties

Owner
A. Hassan
Category
Resilience
Identified
14 Feb 2026
Next review
12 Nov 2026
Frameworks2

ISO/IEC 27001:2022

Clause 6.1.3

CBE Cybersecurity Framework

Art 2.4

Top controls39
THQ-19 Cryptographic key management0 of 6 evidence
THQ-24 Backup and restoration5 of 5 evidence
Open tasks6
Backup restoration testDue in 9 days

Acceptance

Awaiting sign-off

ISO 27001 6.1.3(f) · records your name, the residual level and today’s date.

One linked task is overdue

Accepting now records that you accept the residual level despite it.

Record acceptance
A risk, its treatment and the controls that evidence it

A treatment is only as real as the control behind it. Each one points at the controls that mitigate the risk, and those controls carry their own evidence — so the register and the control set cannot tell different stories.

Works with PCI DSS v4.0ISO 27001CBEAgentEvidence

Risk FAQ

Is the register separate from the controls?
No. A treatment points at the controls that mitigate the risk, and those controls carry the evidence that proves they are in place.
Can we use our own risk methodology?
The register records likelihood, impact and treatment; the scoring approach is yours.

Stop keeping a risk register nobody can evidence.