Skip to content

Risk Register & Treatment Plan (Clause 6.1)

Risk ID Threat & Vulnerability Inherent Likelihood Inherent Impact Inherent Score Treatment Strategy Residual Score Risk Owner
RSK-01 Phishing attack compromises engineer credentials. 4 4 16 (High) Enforce FIDO2 / Authenticator MFA, conditional access, and quarterly simulated phishing drills. 4 (Low) CISO
RSK-02 Lost or stolen unencrypted laptop exposes customer data. 3 4 12 (Med) Mandatory BitLocker full-disk encryption via Intune; remote-wipe capability enabled on check-in failure. 3 (Low) IT Lead
RSK-03 Third-party SaaS provider experiences severe breach. 3 4 12 (Med) Pre-onboarding security assessment; DPA execution; restricting sensitive data uploads. 6 (Low) Operations
RSK-04 Critical server vulnerability exploited prior to patching. 3 5 15 (High) Automated 14-day patch enforcement (Cyber Essentials Plus SLA) and daily vulnerability scans. 5 (Low) IT Lead
RSK-05 Accidental data leak via departing employee personal storage. 3 4 12 (Med) Standardized leaver offboarding protocol; immediate IdP credential revocation; USB port blocking. 4 (Low) HR / IT