Specialist Services · Risk Management

Risk registers that drive decisions, not shelfware.

Information security risk management built on ISO 27005 and ISO 31000: a methodology your organisation understands, assessments that reflect real threats, and a register your leadership actually uses to choose where money goes.

ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we build

A risk practice sized for your organisation.

Not a 400-row spreadsheet nobody reads, but a governed cycle that finds what matters, weighs it honestly and treats it deliberately.

Methodology & appetite

A risk method aligned to ISO 27005 and 31000 with impact scales in your business's own terms, and a risk appetite your board has actually signed.

Risk assessments

Facilitated assessments across systems, projects, suppliers and AI: threat-informed, evidence-based and free of copy-paste risks.

Treatment plans

Every significant risk with an owner, a treatment decision and a date: tracked to closure, escalated when it slips.

Third-party risk

Supplier tiering, onboarding assessments and continuous monitoring, proportionate to the data and access each vendor holds.

AI risk assessment

ISO 42001-aligned assessment of AI systems you build or buy: bias, misuse, data leakage and accountability, treated like any other risk.

Risk reporting

Dashboards and quarterly reviews that show movement, not just position: what got better, what got worse, what needs a decision.

Why Cybercontrols

The same methodology auditors test us against.

805+Clients guided across the UK, EU and beyond
ISO 27005And ISO 31000 behind every methodology
QuarterlyRisk cycles our clients run without us
G-Cloud 15UK Government approved supplier
How it works

From gut feel to governed in four moves.

Frame

Method, scales and appetite agreed with leadership, so every later score means the same thing to everyone.

Assess

Workshops and evidence reviews across your estate; risks articulated as scenarios, not vague categories.

Treat

Decisions made and funded: mitigate, transfer, accept or avoid, each recorded with its rationale.

Review

A quarterly rhythm that keeps the register alive, feeds your ISMS and stands up to any auditor.

Questions

Risk management, answered plainly.

Our risk register is huge and nobody uses it. Can you fix that?

That is the most common starting point. We consolidate, rescore against honest scales and cut the register to the risks leadership should actually see: typically a third of the original length, with ten times the use.

Qualitative or quantitative scoring?

Qualitative done rigorously serves most organisations well. Where a decision justifies it, such as cyber insurance or major investment, we layer quantified estimates on the specific risks concerned rather than gold-plating everything.

Does this cover ISO 27001's risk requirements?

Fully: clauses 6.1.2, 6.1.3, 8.2 and 8.3 and the Statement of Applicability. The same practice also feeds ISO 42001, NIS2 and DORA obligations without separate machinery.

Can you run our supplier reviews for us?

Yes, as a one-off tiering and assessment exercise, or as an ongoing managed cycle where we review, chase and report while your team decides.

Know your risks. Prove you manage them.

A 30-minute scoping call with a senior consultant, with no obligation and no sales deck.