All Projects
Risk Assessment · 06

Risk Assessment

Client
Confidential Client
Role
GRC Analyst
Year
2025
Category
Risk Assessment

Overview

A formal information-security risk assessment identifying, analyzing and prioritizing risk across systems, vendors and business processes to inform treatment decisions and resourcing.

Key Activities

  • Identified assets, threats and vulnerabilities across the environment
  • Scored risks by likelihood and impact against a defined risk matrix
  • Evaluated third-party and vendor risk exposure
  • Presented findings and a treatment plan to leadership

Outcome

Gave leadership a prioritized, evidence-based risk register and treatment plan to guide security investment.

Frameworks & Standards

ISO/IEC 27005NIST CSFInternal risk register