What is an IT risk assessment?
An IT risk assessment answers three questions: What matters to us? What can hit it? And how bad would it be? Note the word IT: The term "risk assessment" is also used about workplace safety and chemicals. Here it is about systems, data and business continuity. Without a risk assessment, IT security becomes a shopping list driven by salespeople and gut feelings; with one, it becomes a prioritised plan management can stand behind.
Step by step: how to do an IT risk assessment
- Map the assets: Which systems, data and processes does the business depend on? Finance system, production, customer data, email. And what does an hour or a day without them cost?
- Identify the threats: ransomware, phishing, hardware failure, power outage, human error, resignations, supplier failure. Be specific: "hacking" is not a threat, "encryption of the file server via a phished account" is.
- Assess the vulnerabilities: What makes the threat realistic in your organisation? Missing MFA, old servers, no tested backup, one person who knows everything?
- Score the risks: likelihood × impact, see the template below.
- Decide how to handle each risk: reduce (technical or organisational measures), transfer (insurance, outsourcing), accept (documented!) or avoid (drop the activity).
- Anchor and repeat: Give every risk an owner and a deadline, and repeat the assessment annually and after major changes.
Risk assessment as a requirement in NIS2, GDPR and ISO 27001
The three major sets of rules all require the risk assessment as their foundation: NIS2 demands "an all-hazards approach" to risk management with management held accountable; GDPR requires security "appropriate to the risk", which presupposes that the risk has been assessed; and in ISO 27001 the risk assessment is the very engine all controls are selected from. The good news: One solid IT risk assessment can be reused across them. It is the same exercise in slightly different packaging. See also IT compliance.
Template: likelihood × impact
Score every risk from 1-4 on both axes and multiply the numbers:
| Likelihood / Impact | Negligible (1) | Noticeable (2) | Serious (3) | Critical (4) |
|---|---|---|---|---|
| Very likely (4) | 4 | 8 | 12 | 16 |
| Likely (3) | 3 | 6 | 9 | 12 |
| Possible (2) | 2 | 4 | 6 | 8 |
| Unlikely (1) | 1 | 2 | 3 | 4 |
Rule of thumb: 12-16 requires action now, 6-9 needs a plan and an owner, 1-4 is monitored. Define impact in business terms (money, downtime, fines, reputation), so management can prioritise without being technicians. The highest-scoring risks are also the scenarios your IT contingency plan must cover.
How MI Support IT can help
MI Support IT carries out IT risk assessments together with you, from mapping to a prioritised action plan, as part of IT advisory and the work on IT contingency plans. If you want a quick, concrete starting point, contact us directly.