Skip to main content

Compliance

What is an IT risk assessment?

An IT risk assessment maps the threats to your systems and data and prioritises the effort. See the method step by step, with a likelihood × impact template.

In short

An IT risk assessment is a systematic review of what can go wrong in your IT (outages, ransomware, data leaks, human error) and how hard it would hit the business.

The method is simple: Map the most important systems and data, identify the threats against them, and score each risk on likelihood and impact, so the effort can be prioritised where the risk is greatest. The result is not a report for the drawer, but a prioritised action plan: which risks should be reduced with technical measures, which can be insured against or accepted, and who owns each one.

The IT risk assessment is at the same time a direct requirement in NIS2, a core principle in GDPR and the foundation of ISO 27001. All modern compliance starts here. The assessment must be repeated regularly, typically annually and after major changes. MI Support IT carries out IT risk assessments for Danish businesses as a fixed part of security and contingency work.

Back to the glossary

What is an IT risk assessment?

An IT risk assessment answers three questions: What matters to us? What can hit it? And how bad would it be? Note the word IT: The term "risk assessment" is also used about workplace safety and chemicals. Here it is about systems, data and business continuity. Without a risk assessment, IT security becomes a shopping list driven by salespeople and gut feelings; with one, it becomes a prioritised plan management can stand behind.

Step by step: how to do an IT risk assessment

  1. Map the assets: Which systems, data and processes does the business depend on? Finance system, production, customer data, email. And what does an hour or a day without them cost?
  2. Identify the threats: ransomware, phishing, hardware failure, power outage, human error, resignations, supplier failure. Be specific: "hacking" is not a threat, "encryption of the file server via a phished account" is.
  3. Assess the vulnerabilities: What makes the threat realistic in your organisation? Missing MFA, old servers, no tested backup, one person who knows everything?
  4. Score the risks: likelihood × impact, see the template below.
  5. Decide how to handle each risk: reduce (technical or organisational measures), transfer (insurance, outsourcing), accept (documented!) or avoid (drop the activity).
  6. Anchor and repeat: Give every risk an owner and a deadline, and repeat the assessment annually and after major changes.

Risk assessment as a requirement in NIS2, GDPR and ISO 27001

The three major sets of rules all require the risk assessment as their foundation: NIS2 demands "an all-hazards approach" to risk management with management held accountable; GDPR requires security "appropriate to the risk", which presupposes that the risk has been assessed; and in ISO 27001 the risk assessment is the very engine all controls are selected from. The good news: One solid IT risk assessment can be reused across them. It is the same exercise in slightly different packaging. See also IT compliance.

Template: likelihood × impact

Score every risk from 1-4 on both axes and multiply the numbers:

Likelihood / ImpactNegligible (1)Noticeable (2)Serious (3)Critical (4)
Very likely (4)481216
Likely (3)36912
Possible (2)2468
Unlikely (1)1234

Rule of thumb: 12-16 requires action now, 6-9 needs a plan and an owner, 1-4 is monitored. Define impact in business terms (money, downtime, fines, reputation), so management can prioritise without being technicians. The highest-scoring risks are also the scenarios your IT contingency plan must cover.

How MI Support IT can help

MI Support IT carries out IT risk assessments together with you, from mapping to a prioritised action plan, as part of IT advisory and the work on IT contingency plans. If you want a quick, concrete starting point, contact us directly.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.