Law 25 — run your compliance in our platform, 1 month free

Risks ranked by business impact, not CVSS

An ISO 27005 risk assessment that produces a treatment plan your executives will actually fund.

The challenge

Technical risk registers list vulnerabilities. Executives fund business risks. Translating one into the other is the whole job.

Scope — included and not included
Included
  • Asset and process inventory
  • Threat and vulnerability identification
  • Likelihood and impact assessment
  • Risk register
  • Treatment plan with owners
  • Residual risk statement
Not included
  • Implementing the treatments
  • Technical testing, that is a pentest
  • Ongoing risk management unless retained
How it works
01
Scope and assets

What matters to the business, and what it runs on.

02
Identify and assess

Threats, vulnerabilities, likelihood and impact — in workshops with your people.

03
Rank and plan

The register, ranked, with a funded, owned treatment plan.

04
Present to leadership

The executive presentation and the residual risk statement for sign-off.

What you receive
  • Risk register in your format
  • Treatment plan with owners and dates
  • Residual risk statement for sign-off
  • Executive presentation
  • Methodology documentation for auditors
What we need from you
  • ·Access to process owners
  • ·Asset inventory or our help building one
  • ·An executive sponsor to accept residual risk
  • ·Workshop time
Timeline and engagement

2 to 4 weeks. Fixed scope.

Standards, methods and tooling
ISO 27005ISO 31000Portal hosted in Canada
Frequently asked questions

Give your board numbers they can act on

Two to four weeks to a ranked register and a plan with owners.