Pillar 01 · Audit

Cyber Risk Assessment

Every business carries cyber risk. Very few can tell you how much, where it sits, or which parts of it are worth spending money on.

A cyber risk assessment answers those questions. It is a structured look at what you would lose, what could cause you to lose it, how likely that is, and what it would be worth to reduce. It is the piece of work that turns cyber security from an uncomfortable subject into a set of decisions you can make.

Output
Risk register with likelihood, impact and recommended response
Reads as
A management document, not a technical scan report
Method
Five stages, broadly how NIST and ISO 27001 approach it
Includes
Remediation roadmap split into now, next and later
Price
Fixed, agreed in writing before work starts
Good for
Boards, insurers and client questionnaires asking a fast question

What Is a Cyber Risk Assessment?

The most compact form of cyber security analysis

A cyber risk assessment identifies the things that matter to your business, the threats to them, and the weaknesses that would turn those threats into incidents. It then rates each combination by how likely it is and how much it would hurt. It is enough to make decisions on, without the depth of a full audit.

The output is a risk register that provides a prioritised list of your exposures, each with a likelihood, an impact and a recommended response. It reads as a management document, not a technical scan report.

A cyber security audit is broader and deeper. It examines your systems, controls, software and people in detail and tells you what is wrong. A risk assessment is more focused as it starts from business consequence and works backwards to the controls that would prevent it.

For most businesses, the audit is the practical first step, and the risk assessment is a part of that. The standalone assessment makes sense when you want a lighter-touch view before committing to the full piece. If you are not sure which you need, we will tell you on a call rather than sell you the larger one.

Why Businesses Need Cyber Risk Analysis

Spend where the risk is

Cyber security budgets are finite and threats are not, so the only sensible approach is to spend where the risk is.

Without an assessment, decisions are based on the loudest input available, such as a vendor's pitch, a newspaper story about ransomware, or whatever the IT provider mentioned last. This is how organisations end up with an expensive tool addressing a risk they did not really carry, while an unpatched server holding the customer database sits there untouched.

There is usually a second reason too, and it is external. Someone has asked.

Four common triggers

  • Insurance applications and renewals, where underwriters are asking more, and more specific, questions. See what cyber insurers require.
  • Client and supply chain questionnaires. Only 15% of UK businesses currently review the cyber risk posed by their immediate suppliers, rising to 30% of medium-sized firms and 48% of large ones. If you sell to the larger end of that scale, you are the supplier being reviewed.
  • Board and audit committee reporting. 31% of UK businesses have a board member with explicit responsibility for cyber security, and that person needs something to base their report on.
  • Regulatory obligations. Under UK GDPR, security measures have to be appropriate to the risk, which presupposes you have assessed the risk.

Our Assessment Methodology

Five stages, nothing exotic

This is broadly how NIST and ISO 27001 approach it, applied at a scale that suits a business without a security team.

  1. What matters

    We identify your critical assets and processes: the data you hold, the systems you depend on, the services your customers rely on, and the suppliers and platforms you cannot operate without. Cloud services and third-party dependencies get counted properly, which they often are not.

  2. What could go wrong

    For each of these assets and processes, we evaluate the realistic threats, such as ransomware, business email compromise, insider error, supplier failure, lost devices and credential theft. We keep this specific to your business, as a manufacturer's realistic threat list looks different from a solicitor's.

  3. What would let it through

    The vulnerabilities and control gaps that would allow each threat to succeed. This is the technical layer, and it is grounded in what we can observe, not in what a questionnaire claims.

  4. How likely, how bad

    Each risk receives a likelihood and an impact rating, and we are explicit about the reasoning behind both. Impact is expressed in business terms, including days of disruption, cost, contractual exposure, and regulatory consequence.

  5. What to do

    Every cyber assessment should end in decisions, so each risk is assigned one: treat, tolerate, transfer or terminate. Most get treated, some get tolerated with a documented reason, and some get transferred to an insurer.

From Risk to Action: The Remediation Roadmap

Now, next, later

A risk register that nobody acts on is just a well-organised worry. Our assessment ends with a roadmap that is sequenced, costed where we can cost it, and split by timeframe.

Now

Things you should fix this month, usually because they are both serious and cheap, including MFA gaps, dormant accounts, unpatched internet-facing systems, and backups nobody has tested.

Next

Work needing planning or budget over a quarter or two, such as network segmentation, endpoint replacement, formalising an incident response plan, and a training programme.

Later

Structural changes with a longer horizon. This could include replacing an unsupported line-of-business system, moving to a better-architected cloud setup, and certification if it is not already on the list.

Everything is ordered by risk reduced per pound spent. If two items would cost the same, the one that removes more exposure goes first. It sounds obvious, but it is remarkable how rarely security recommendations arrive in this order.

We also flag which items your insurer is most likely to care about, so the roadmap does double duty at renewal.

The Insurance Perspective on Cyber Risk

Likelihood from loss experience, not headlines

Fourarmed came out of an insurance broker, and it shapes how we assess risk.

Insurers are in the business of pricing risk accurately, because getting it wrong costs them money. That gives them a grounded, slightly unromantic view of what causes losses, and it is often not what the security industry talks about most. The Association of British Insurers reported £197m paid out on UK cyber claims in 2024, up 230% on the previous year, with ransomware and malware accounting for 51% of claims. This is a picture of what happens, drawn from what got paid.

We assess likelihood from loss experience instead of threat headlines. A well-publicised attack technique is not necessarily one that is likely to hit you. We weight our ratings towards the things that generate claims for businesses like yours.

We also assess impact the way an underwriter would, which means quantifying business interruption. How long you would be down, what that costs per day, and what recovering would involve. This number is the one that gets budgets approved internally, and it is the one your insurer is already estimating with less information than you have.

Common questions

Four questions
What is the difference between a cyber risk assessment and a cyber security audit?
A cyber security audit is broader and deeper. It examines your systems, controls, software and people in detail and tells you what is wrong. A risk assessment is more focused: it starts from business consequence and works backwards to the controls that would prevent it. For most businesses the audit is the practical first step, and the risk assessment is a part of that.
How long does a cyber risk assessment take?
It is a lighter-touch piece of work than a full audit and is scoped and quoted on a call. The standalone assessment makes sense when you want a view before committing to the full piece, often because a board or an insurer has asked a question you need to answer quickly.
How often should we reassess?
Annually is the usual rhythm, and after any significant change to your systems, suppliers or the services your customers depend on. Under UK GDPR, security measures have to be appropriate to the risk, which presupposes you have assessed the risk.
What do we get at the end?
A risk register listing your exposures with a likelihood, an impact and a recommended response for each, plus a remediation roadmap split into now, next and later, ordered by risk reduced per pound spent. We also flag which items your insurer is most likely to care about.
Get your risk assessment

Has a board member asked where you are exposed?

If a board member has asked where the business is exposed and the honest answer is that nobody knows, this is the piece of work that changes that. The same applies if there is a renewal or a client questionnaire in front of you. We will scope it on a call and quote a fixed price.