Consulting / Risk and impact assessments

Risk and impact assessments

Most risk registers are a spreadsheet nobody reads. Ours are run by experts certified by the National Security Authority (NBÚ) and ISACA CRISC: they start from your real systems, data flows and people, score each scenario for likelihood and impact under the methodology that fits you — ISO/IEC 27005, ISO 31000, business-impact analysis (BIA) under ISO 22301 or the Slovak Cybersecurity Act 69/2018 — and end with a short list of controls your team can actually operate. If you want the register to stay alive, we deliver it into the Asign GRC platform, of which we are an implementation partner.

What you receive
  • Asset and data-flow inventory of the systems in scope
  • Risk register with likelihood, impact and estimated cost per scenario (ISO/IEC 27005, ISO 31000 or NIST, as required)
  • Business-impact analysis (BIA): critical processes, recovery objectives (RTO/RPO) and dependencies, ready for ISO 22301 or the Cybersecurity Act
  • Prioritised treatment plan: which controls, in what order, owned by whom
  • Optional delivery into the Asign GRC platform (we are an implementation partner), so risks, BIA and controls are monitored continuously instead of living in a spreadsheet
  • Board-level summary and a reusable methodology for annual reviews
Typical triggers
  • An ISO 27001 or SOC 2 programme needs a defensible risk assessment
  • Leadership wants to know which security spend actually reduces risk
  • A regulator, bank or enterprise customer has asked for your risk register
  • A new product, market or vendor changes what could go wrong
How an engagement runs
  1. 1
    Kick-off & inventoryWorkshops with engineering, ops and business owners
    2 d
  2. 2
    Threat modellingScenarios per system and data flow; likelihood and impact scoring
    3–5 d
  3. 3
    Treatment planControls selected against cost and effort; owners assigned
    2 d
  4. 4
    PresentationRegister and plan walked through with leadership
    ½ d
Consulting

Other consulting services

Security auditing
ISO 27001 · ISO 22301 · DORA · pentest

Audits and certification readiness for ISO/IEC 27001, ISO 9001 and ISO 22301, DORA compliance for financial entities, penetration testing — and the technical submissions your regulator or the National Bank of Slovakia asks for.

Read more →

Technical due diligence

Our certified auditors combine governance know-how with deep technical skill and experience to assess your partner’s code, infrastructure, team and security against well-designed methodologies — so you make the right decision before the money moves.

Read more →

AWS configuration & scaling

Well-Architected reviews, IAM and network hardening, cost cuts and autoscaling designs from an AWS Partner who runs business-critical applications on it every day. The applications we work on grow to tens of terabytes — with response times and costs kept under control.

Read more →
Contact

A consultation with one of our engineers

Tell us what you are dealing with. Within two working days you get a concrete proposal with scope and price.

  • Reply from a senior engineer or lead auditor, not an account manager
  • Fixed scope and price before any work starts
  • ISO 9001 and ISO 27001 certified processes, NDA on request