
Risk assessment and management
Whether it’s a SaaS platform, critical business system or custom integration, unmanaged risk can undermine both compliance and confidence. Bastion uses a proven methodology based on AS/NZS ISO 31000 and ISO/IEC 27005 to help you identify and address cyber risks in a structured, repeatable way.
We assess the likelihood and impact of threats, recommend practical controls and support better decision-making by helping you understand what risks remain and whether they’re acceptable to your business.
Our consultants have delivered hundreds of risk assessments across industries. We know how to quickly pinpoint risks and provide clear, actionable advice on how to manage them.
If you don’t yet have a risk management framework, we can help you build one that fits your business, supports strategic goals and empowers leaders to make risk-informed decisions.
Our team have completed thousands of these, and our experience enables us to rapidly identify risks and tell you how they can be treated.
If you don't already have an organisational risk management framework, we can support you in developing one that fits the way you operate and enables your business leaders to make risk-informed decisions.
- Structured assessments aligned with ISO 31000 and ISO 27005
- Clear, actionable risk ratings and prioritised mitigation steps
- Support for business case development and executive reporting
Our approach to risk assessment
Our Risk Assessment Process
A step-by-step approach for clarity and consistency
We follow a structured, repeatable process that ensures every risk assessment is grounded in context, supported by evidence and aligned with your business goals.
- Review relevant documentation to inform the risk assessment.
- Run a Business Context Workshop with key stakeholders to define how the system supports your operations.
- Facilitate a Technical Context Workshop to understand the system’s underlying technology and architecture.
- Assess and identify the key risk items associated with the system being reviewed.
- Create a set of control recommendations to address each identified risk.
- Hold a Risk Validation Workshop to review and confirm gross and residual risk scores using your organisation’s likelihood and consequence criteria.

How we deliver your risk assessment
Why work with us
Frequently asked questions
What is a cyber security risk assessment?
A cyber security risk assessment is a structured process used to identify, analyse and evaluate potential threats to your systems, data and operations. It helps you understand where you're exposed and what actions to take to reduce risk.
Why does my business need a risk assessment?
Risk assessments help you make informed decisions about security investments and compliance. They show you where your biggest risks are, what’s acceptable, and where you need better controls to protect your organisation.
What standards do Bastion’s risk assessments follow?
Our assessments align with recognised frameworks like ISO 31000, ISO 27005 and AS/NZS standards. We adapt our approach to your environment while maintaining consistency, transparency and clear documentation.
How long does a risk assessment take?
Most assessments can be completed in 2 to 4 weeks, depending on the complexity of your systems and the number of stakeholders involved. We’ll give you a clear timeline and delivery plan at the start.
Will the risk assessment help with compliance?
Yes. Our assessments are designed to support compliance with frameworks such as ISO 27001, PCI DSS and NIST CSF. You’ll get clear documentation that can be used for audits, board reporting and certification readiness.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia