A risk register that points at its controls
Risks, their treatments and the controls that mitigate them, tied together so a treatment plan is something you can evidence.
Treatments tied to the controls that carry them
Risk registerRISK-003
Ransomware via an unpatched endpoint
Very highMitigatingResilience & Insider Threat · owned by A. Hassan · reviewed 04 Aug 2026
Exposure
Inherent
10 / 10
Very high · likelihood 4, impact 3
Residual
4 / 10
Low · likelihood 2, impact 2
Appetite
5 / 10
Residual sits inside appetite
The dashed line shows where treatment moves this risk. Six points of reduction.
Likelihood
Treatment
Current strategy · MitigateLet Thiqa draft this plan
From the exposure above, Thiqa can write a treatment plan and rank the tasks and controls most likely to bring this risk down. You review everything before anything is saved or linked.
Comments
1N. Khalil4 days ago
Backup restoration test is overdue. Until it passes I would not call residual 4.
Properties
- Owner
- A. Hassan
- Category
- Resilience
- Identified
- 14 Feb 2026
- Next review
- 12 Nov 2026
ISO/IEC 27001:2022
Clause 6.1.3
CBE Cybersecurity Framework
Art 2.4
Acceptance
Awaiting sign-off
ISO 27001 6.1.3(f) · records your name, the residual level and today’s date.
One linked task is overdue
Accepting now records that you accept the residual level despite it.
A treatment is only as real as the control behind it. Each one points at the controls that mitigate the risk, and those controls carry their own evidence — so the register and the control set cannot tell different stories.
Works with PCI DSS v4.0ISO 27001CBEAgentEvidence
Risk FAQ
- Is the register separate from the controls?
- No. A treatment points at the controls that mitigate the risk, and those controls carry the evidence that proves they are in place.
- Can we use our own risk methodology?
- The register records likelihood, impact and treatment; the scoring approach is yours.