Information security risk management built on ISO 27005 and ISO 31000: a methodology your organisation understands, assessments that reflect real threats, and a register your leadership actually uses to choose where money goes.
Not a 400-row spreadsheet nobody reads, but a governed cycle that finds what matters, weighs it honestly and treats it deliberately.
A risk method aligned to ISO 27005 and 31000 with impact scales in your business's own terms, and a risk appetite your board has actually signed.
Facilitated assessments across systems, projects, suppliers and AI: threat-informed, evidence-based and free of copy-paste risks.
Every significant risk with an owner, a treatment decision and a date: tracked to closure, escalated when it slips.
Supplier tiering, onboarding assessments and continuous monitoring, proportionate to the data and access each vendor holds.
ISO 42001-aligned assessment of AI systems you build or buy: bias, misuse, data leakage and accountability, treated like any other risk.
Dashboards and quarterly reviews that show movement, not just position: what got better, what got worse, what needs a decision.
Method, scales and appetite agreed with leadership, so every later score means the same thing to everyone.
Workshops and evidence reviews across your estate; risks articulated as scenarios, not vague categories.
Decisions made and funded: mitigate, transfer, accept or avoid, each recorded with its rationale.
A quarterly rhythm that keeps the register alive, feeds your ISMS and stands up to any auditor.
That is the most common starting point. We consolidate, rescore against honest scales and cut the register to the risks leadership should actually see: typically a third of the original length, with ten times the use.
Qualitative done rigorously serves most organisations well. Where a decision justifies it, such as cyber insurance or major investment, we layer quantified estimates on the specific risks concerned rather than gold-plating everything.
Fully: clauses 6.1.2, 6.1.3, 8.2 and 8.3 and the Statement of Applicability. The same practice also feeds ISO 42001, NIS2 and DORA obligations without separate machinery.
Yes, as a one-off tiering and assessment exercise, or as an ongoing managed cycle where we review, chase and report while your team decides.
A 30-minute scoping call with a senior consultant, with no obligation and no sales deck.