Sample Risk Register Composable
Sample Risk Register Composable
A risk register is a valuable communications tool for Security and Risk Management Leaders. This tool will help effectively
communicate the potential business impacts of risks, record issues and control weaknesses and help support the design,
implementation and monitoring of risk treatment activities.
The instructions, intent and objective of this template are contained in the source document. Please refer back to that document for details.
© 2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. or its affiliates. This
presentation, including all supporting materials, is proprietary to Gartner, Inc. and/or its affiliates and is for the sole internal use of the
intended recipients. Because this presentation may contain information that is confidential, proprietary or otherwise legally protected, it may
not be further copied, distributed or publicly displayed without the express written permission of Gartner, Inc. or its affiliates.
# Classification: Internal
© 2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. or its affiliates. This
presentation, including all supporting materials, is proprietary to Gartner, Inc. and/or its affiliates and is for the sole internal use of the
intended recipients. Because this presentation may contain information that is confidential, proprietary or otherwise legally protected, it may
not be further copied, distributed or publicly displayed without the express written permission of Gartner, Inc. or its affiliates.
# Classification: Internal
# Classification: Internal
Instructions
Security and Risk Management Leaders should use the risk register to record and monitor the current status of Cyber and I
treatment of related control weaknesses within an organization. It is designed to record all identified issues and findings an
Risk Management leaders to :
In the risk register Excel spreadsheet, modify the following tabs to match the organization's definitions and preferences:
- Pick List Data
- Likelihood Assessment
- Impact Assessment
- Risk Assessment Matrix
Note that any changes made in any one of these tabs must be reflected in other tabs to ensure internal consistency.
# Classification: Internal
# Classification: Internal
# Classification: Internal
RISK REGISTER
We suffer a coordinated operation of multiple claims against existing • Payment procedures using phasing and delay mechanisms to
Significant fraud event arising from fraudulent retirement funds to fraudsters impersonating existing clients, based on identify potentially fraudulent claims and prevent outflow of funds.
ISSUE001 - Inadequate authentication of claimants
RISK001 Cybercrime - Business Email Compromise Cybercrime payment to a person impersonating a senior CFO Cyber and IT what appears to be authentic paperwork and knowledgeable calls to our Rare/Remote/Improbable Large Medium • Payment claims of greater than $100,000 must be lodged Effective Rare/Remote/Improbable Moderate Low Low Annual
ISSUE002 - Lack of fraud detection and training
executive. customer service line. We fail to recover the payments. Such a fraud physically and identification sighted.
requires a well-informed, coordinated operation.
We suffer a significant outage to customer service workstations due to a • Desktop and network anti-malware software installed and updated
Significant system downtime on customer service
ransomware outbreak. This inhibits our ability to serve customers regularly.
RISK002 Cybercrime - Ransomware Cybercrime workstations due to an uncontrolled ransomware Head of Retail Cyber and IT Almost Certain/Frequent Large Extreme Partially Effective Probable/Likely Large High Low Annual ISSUE003 - Limited Zero day attack mitigation
effectively. There are also secondary financial and brand impacts. • Forensic and diagnostics support available on demand.
outbreak.
A rumor appears in social media or the popular press that the company is
about to become embroiled in a financial scandal. The rumor is not true, ISSUE006 - Lack of Brand monitoring
Online Brand Risk - Social media Unfounded rumor in social or popular media that a
RISK005 Online Brand Risk SVP, Public Affairs Cyber and IT but it causes a depression on the stock price. The rumor does not Almost Certain/Frequent Moderate High None. Ineffective Almost Certain/Frequent Moderate High Low Annual ISSUE007 - Inadequate incident response plan
misinformation financial scandal is about to engulf the company.
subside and continues to depress the price. The most likely scenario is ISSUE008 - Poor perception of brand related to security and trust
that this will be started by activists who object to our business.
RISK011
RISK012
RISK013
RISK014
RISK015
RISK016
RISK017
RISK018
RISK019
RISK020
RISK021
RISK022
RISK023
RISK024
RISK025
Unique Unique
Free Text Free Text Fixed Choice Free text Free text Free text Free Text Free Text Fixed Choice Free text Free text Free text
identifier identifier
ISSUE014
ISSUE015
ISSUE016
ISSUE017
ISSUE018
ISSUE019
ISSUE020
ISSUE021
ISSUE022
ISSUE023
ISSUE024
ISSUE025
Classification: Internal
#
Impact Assessment Decision Table
Business Impact
Financial Impact Customer Impact Opportunity Impact
Insolvency, or negative Complete failure of We lose rights to our IP.
profit outlook. service across multiple Competitor gains first-
lines of business >= 5 mover advantage.
Severe minutes.
# Classification: Internal
Impact Dimensions
Shareholder Impact Commercial Impact Staff Impact Brand Impact
Attributable negative Commercial liability Actual or high risk of Company name
share price movement exposure threatens death or injury. becomes a byword for
>= 10%. viability of the company. corporate misconduct or
misadventure.
Attributable negative Exposure to punitive Risk of death or injury Loss of multiple high-
share price movement damages, or loss of Tier rated higher than value customers, or
>= 5% but < 10%. 1 customer. insignificant, or major job introduction of
losses. widespread negative
brand sentiment.
Attributable negative Exposure to restitution or Minor job losses, or Loss of one high-value
share price movement similar damages for significant loss of customer or multiple
>= 1% but < 5%. breach of contract, or productivity (>= 30 midlevel customers, or
loss of lower-tier person days). introduction of short-term
customer. negative brand
sentiment.
Attributable negative Minor penalties incurred Minor staff disruption, or Loss of multiple low-
share price movement < for exceptions explicitly minor loss of productivity value customers, or
1%. articulated in the (< 30 person days). reinforcement of existing
contract. negative brand
sentiment.
# Classification: Internal
Media Impact Regulator Impact
International long-term One or more lines of
media coverage. business are shut down,
or an executive faces
personal legal liability.
# Classification: Internal
Likelihood Assessment Criteria Table
Likelihood Criteria
Likelihood Level
Likelihood of occurrence in next 12 months
Rare/Remote/Improbable Less than 5%
Unlikely/Seldom 5% - 20%
Possible 20% to 50%
Probable/Likely 50% to 80%
Almost Certain/Frequent Greater than 80%
# Classification: Internal
Likelihood Criteria
Frequency in years
Every 10+years
Every 5-10 years
Every 3-5 years
Every 2-3 years
Every year
# Classification: Internal
Risk Assessment Matrix
Likelihood of Risk
Rare/Remote/Improbable Unlikely/Seldom
# Classification: Internal
Likelihood of Risk Scenario
Possible Probable/Likely Almost Certain/Frequent
# Classification: Internal









