
Understanding and managing your organisation’s risk
A risk assessment puts information security threats into context for your business and provides security control recommendations to manage risk to a level that is tolerable to you. We work closely with you to understand how your business functions and how you use technology.
- Helps identify and determine key assets and risks of your organisation by performing an in-depth analysis in all aspects of your business, from technology to people.
- Tailored to your organisation’s specific needs and requirements.
- Provides pragmatic recommendations, strategies and advice to help you mitigate and prevent risks and their overall impact on your organisation.
No two risk assessments are the same
The risk assessment process
Your organisation, our expertise
After gaining a clear understanding of your business and what it makes it tick, our team of experts dives into the finer details, from policy and procedure documentation, technical configurations, to asset identification. Identifying the key risks and threats, how they impact you, and what can be done to improve.
- Key assets are identified and analysed (e.g., servers, databases, customer information), in-depth analysis of various artefacts is conducted, and your level of risk tolerance is determined.
- Risks, threats, and vulnerabilities are identified, with clear rationale as to how they will impact your organisation, along with the likelihood of their occurrence.
- A clear and concise report is provided to you detailing our findings, expert analysis, and practical recommendations for future improvement following industry best practices and standards e.g., NZISM.
Delivery of a Security Risk Assessment
Why work with us
Frequently asked questions
What is a risk assessment?
A risk assessment is a point-in-time assessment of your organisation and/or relevant systems. The process involves in-depth analysis and identification potential threats and vulnerabilities to your organisation and/or systems. The potential likelihood and impact of these risks are assessed, and tailored controls and recommendations are applied and provided to help remediate or mitigate them.
Should I get a risk assessment done?
A risk assessment is applicable to any individual, organisation, or entity that utilises and relies on digital systems, networks, and/or data. Risk assessments can apply to businesses of various sizes, financial institutions, healthcare providers, IT & Cybersecurity professionals, and even government agencies.
When do I get a risk assessment done?
A risk assessment can be initiated at anytime to gain a current understanding of potential risks. However, some key times to start a risk assessment are: Before launching a new system or website, after a security incident or breach, after major regulatory or compliance changes, after major IT infrastructure changes, and finally, risk assessments should be done on a regular basis (e.g., annually) to ensure ongoing compliance and keep up with an ever-evolving threat landscape.
How long does a risk assessment take?
The timeline of a risk assessment will vary depending on the nature of the assessment and the size of the assessment scope. A basic assessment only taking a few days, a standard one ranging from a week or two, to an in-depth one taking 3 weeks or more.
What is the outcome of a risk assessment?
A completed risk assessment will give you a clear understanding of the threats, vulnerabilities, and overall risks your organisation and/or systems face and how to mitigate and/or prevent them. The goal is to help prevent security breaches, ensure you’re compliant with laws and regulations, and prevent financial and reputational harm.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia