Security Risk Assessments
Most risk assessments produce a heat map and a shelf document. Ours produces a working risk register. We run a formal NIST 800-30 assessment at the level that matters, your whole organization or a single system, score every risk from inherent to residual against the controls you run today, and decompose your top scenarios into dollars. Every risk lands in a live register in Glance tied to a real system, an owner, and a treatment plan, so the assessment becomes the starting state of a managed program rather than a point-in-time report.
Two scopes
Organization
12 weeksEnterprise-wide risk at Tier 1 of the NIST three-tier hierarchy. Crown jewel systems, business processes, and the regimes that regulate you.
System
8 weeksOne system or application in depth. Its data, its interfaces, its trust boundaries, and its threat model.
Department and business-process scope available on request.
Two depths
Risk Assessment
Threat sources and events, vulnerabilities and predisposing conditions, likelihood, impact, and risk. Inherent and residual scored per scenario with written rationale. Control input is asserted or evidenced, and every score shows which.
Risk Assessment with Control Validation
Everything above, plus we test the controls your top risks actually depend on. Twelve to twenty controls typically carry most of the residual determination. We test those to NIST 800-53A, upgrade them to tested provenance, and rescore. Add four weeks to either scope.
Base assessment reaches evidenced control input. Control Validation reaches tested.
What's Included
Signed assessment plan defining the boundary, the threat sources in scope, and the scoring scales
Threat scenario set tailored to your environment and industry
Inherent and residual scoring for every identified risk, with written rationale and control provenance
FAIR taxonomy decomposition on your top scenarios, expressed in dollars
Live risk register in Glance, active from week two
Prioritized treatment recommendations with owners and target dates
Assessment report generated from the register
Executive risk briefing for leadership and the board
Practitioner signature on the assessment
The team behind every engagement
Executive Security Advisor
Applies the assessment methodology, reviews scoring and rationale, and signs the result.
Senior Security Consultant
Runs scenario workshops and stakeholder interviews, drives scoring and treatment design.
Security Analyst
Builds the register in Glance, gathers evidence, and maintains scenario documentation.
Glance
Keeps the register live, recomputes exposure as controls change, and drafts updates between reviews.
Who This Is For
Organizations that need a defensible, current view of their cyber risk, for the board, an auditor, an insurer, or a regulator, and want the assessment to become a managed register rather than a static document.
Our Process
Prepare
Define the boundary, identify the threat sources in play, and agree the likelihood, impact, and risk scales. Signed before anyone is interviewed. 1 week for a system, 2 for an organization.
Conduct
Threat sources and events, vulnerabilities and predisposing conditions, likelihood, impact, and risk. Interviews, documentation, technical evidence, and a facilitated scenario session. Your register goes live in Glance in week two and populates as scoring completes. 5 weeks for a system, 8 for an organization.
Validate (Control Validation only)
Control Validation engagements only. 800-53A testing on the selected controls, then a residual rescore against the verdicts. Adds 4 weeks.
Communicate
The report, the treatment plan, and an executive readout delivered live. 2 weeks.
Maintain
The fourth step of 800-30 runs continuously in Glance. Your annual refresh becomes a documented review of a live register rather than a rebuild from scratch.
Frequently Asked Questions
How is this different from a compliance gap assessment?
A gap assessment measures you against a framework's requirements. A risk assessment measures what can actually go wrong in your environment and what it would cost. Both matter, and they reinforce each other, but a risk assessment is what lets you prioritize spending by business impact.
What methodology do you use?
NIST SP 800-30. Threat sources, threat events, vulnerabilities and predisposing conditions, likelihood, impact, and risk, scored inherent to residual per scenario. Your top scenarios are decomposed using the FAIR taxonomy and expressed in dollars. The method is fixed and published in the report. Your Executive Security Advisor applies it and signs the result.
What happens to the register after the engagement?
It lives in Glance. Your team can run it directly, or Z Cyber can operate it as part of an ongoing engagement, with treatments tracked to closure and scores updated as your controls change. Glance subscribers get the annual refresh included at a defined scope, because the register stayed live all year and the work is genuinely smaller.
How long does a risk assessment take?
An organizational assessment runs 12 weeks and a system assessment runs 8, measured from signature to final deliverable. Add four weeks to either for Control Validation. Your register goes live in Glance in week two, so you are working the risks well before the report lands.
Does this include penetration testing?
No. A risk assessment identifies vulnerabilities and predisposing conditions through controls review, architecture review, configuration review, and documentation. Penetration testing and application security testing are separate engagements. If you already hold current test results, we accept them as evidence and they strengthen the residual scores.
What does control provenance mean?
Residual risk depends on how well your controls actually work, so every residual score shows what its control input rests on. Asserted means you stated the control is in place. Evidenced means a document, configuration, or platform signal confirms it. Tested means an 800-53A verdict proves it operates. A base risk assessment reaches evidenced. Control Validation reaches tested. Most assessments hand you a residual score with nothing behind it and never tell you which is which.
Do insurers and auditors accept the output?
The report is designed to be defensible to third parties: documented methodology, scoring rationale per risk, and an advisor's signature. Many clients run the assessment specifically ahead of a renewal or audit.
Related Services
Controls Effectiveness Assessment
Every in-scope control is tested against evidence and receives a documented effectiveness assessment with a validity window, giving you auditor-defensible proof your controls work.
FAIR Risk Quantification
We decompose your top loss scenarios using the FAIR taxonomy and express them as governed dollar-based estimates, so security investments can be weighed like any other business decision.
Ready to see where you actually stand?
Book a 30-minute briefing with the team that would run your program. We'll assess your needs, scope the right engagement, and follow up with a fixed-fee proposal - no pressure, no generic pitches.
Book a Strategy Call →Not ready to book? Get advisory insights delivered to your inbox.