A cyber security risk assessment is a documented exercise that identifies the threats your organisation faces. It scores each threat by likelihood and impact. Then it produces a short, prioritised list of what to fix, insure against or accept. Almost every UK compliance framework relies on this step, and it is usually the first thing an auditor, insurer or regulator asks to see.

Despite that, it remains one of the most skipped basics in UK cyber security. Only 30% of businesses carried out a risk assessment covering cyber security in the past year, according to the government’s Cyber Security Breaches Survey 2025/2026. The share of small businesses doing so actually fell too, from 48% to 41%. For a task that costs little more than time, that is a striking gap.
Table of Contents
Why bother with a cyber security risk assessment?
Without one, security spending tends to chase whatever feels most urgent that week. That usually means reacting to headlines, not the risks that would genuinely hurt the business. A risk assessment forces a clearer answer instead. It asks what assets matter, what threatens them, and what happens if the worst case, such as a data breach, actually plays out.
That structure pays off in three ways. It gives you a defensible basis for where security budget goes. It gives an insurer or auditor proof that decisions were not arbitrary. And it gives leadership a plain summary of exposure that anyone can follow, technical or not.
What goes into the assessment
The National Cyber Security Centre’s framework breaks a cyber security risk assessment into five parts. Most UK methodologies use some version of the same building blocks:
- Assets – the systems, data and processes the business depends on
- Threats – who or what could target those assets, from criminal gangs to simple human error
- Vulnerabilities – the specific weaknesses a threat could exploit
- Likelihood – a realistic estimate of how probable each scenario is
- Impact – the financial, operational and reputational cost if it happens
Likelihood and impact combine into a risk score. Most teams plot that score on a simple matrix, so the highest-priority items stand out at a glance instead of getting buried in a long spreadsheet.
Which compliance frameworks expect one?
UK GDPR is the law that catches most businesses. Its rules say firms must use measures “appropriate to the risk”. The Information Commissioner’s Office adds that “before deciding what measures are appropriate, you need to assess your information risk” first. So if you hold personal data, a written risk assessment is close to a must.
ISO 27001 goes further still. It builds a whole certification around a formal risk assessment method. Cyber Essentials does not ask for a written assessment. But its checks are far easier to plan once you know where your real risk sits. Rules for card payments, banks and supplier contracts often point to risk assessment too, even when they use different words.
How often should it be repeated?
Once a year is a sensible baseline for most small and mid-sized organisations. Repeat it sooner after any material change: new software going live, an office move, a merger, new suppliers, or a serious incident at a similar business. The NCSC frames this as continuous improvement, not a document you file once and forget.
Who actually needs one?
In practice, most businesses that hold customer data or rely on IT gain from a cyber security risk assessment. So does anyone who answers to a regulator, insurer or bigger client. A few cases make it close to essential:
- You process personal data under UK GDPR
- You are pursuing ISO 27001 certification or a similar standard
- You hold, or want to renew, cyber insurance
- You supply larger organisations that ask security questions before signing contracts
- You have never formally reviewed where your security budget actually goes
Doing it yourself versus bringing in outside expertise
A basic version can be run in-house. Use free NCSC templates and an honest workshop with the people who actually run the systems. That is a genuinely useful first pass, and far better than doing nothing.
Its main weakness is perspective. People who use a system daily tend to trust it more than an outsider would, simply through familiarity. They may also miss attack techniques that only became common recently. An external reviewer brings a fresh eye and current knowledge of how incidents actually unfold. That usually reshapes the priority list once the highest-scoring risks get checked against real attacker behaviour.
Once the register names your highest-priority systems, a vulnerability assessment or a scoped penetration test is usually the next step. It confirms which of those risks can actually be exploited. Aardwolf Security runs both, and is happy to talk through a proportionate scope if you get in touch.
How the risk matrix works in practice
Every risk gets a likelihood score and an impact score. Plot them on a simple grid and a long, overwhelming list turns into something a board can act on in one meeting. A risk that is both likely and severe sits in the top corner and gets a deadline. A risk that is unlikely and minor can often be accepted outright, with a short note explaining why.
The matrix does not need to be clever to work. A basic four-by-four grid with low, medium, high and critical bands is enough for most small and mid-sized organisations. It beats an unranked list where every item looks equally urgent.
What to avoid when running a cyber security risk assessment
A handful of habits undermine an otherwise sound process:
- Writing it once and filing it away. Risk changes as systems, staff and suppliers change, so an assessment left untouched for years stops reflecting reality.
- Scoring every risk as high. If nothing ranks below “critical”, the exercise has not actually prioritised anything.
- Leaving risks without an owner. A risk nobody is accountable for tends to stay unresolved, however well it was scored.
- Focusing only on IT systems. People, suppliers and physical premises carry risk too. A purely technical view misses much of what actually causes incidents.
None of these mistakes cost much to fix. Mostly, they come down to treating the register as a living document that someone actually owns, not a compliance artefact produced once and forgotten.
Frequently asked questions
Is a cyber security risk assessment a legal requirement in the UK?
Not by that exact name. But UK GDPR effectively requires one wherever personal data is processed, since you cannot show “appropriate” security without first assessing the risk. Certain regulated sectors add explicit requirements on top.
What is the output of a risk assessment?
Typically a register of identified risks, each scored for likelihood and impact, together with a treatment plan. That plan says whether each risk will be fixed, reduced, transferred through insurance or formally accepted.
How much does a cyber security risk assessment cost?
A basic internal exercise can cost very little beyond staff time. Outside expertise costs more, but it usually pays for itself by pointing later security spending, such as testing, at the risks that matter most rather than the ones that feel most alarming.
Does Cyber Essentials require a risk assessment?
Not formally. But understanding your risk makes it far easier to scope the technical controls Cyber Essentials certifies, and to explain why particular systems were prioritised.
What is the difference between a risk assessment and a penetration test?
A risk assessment is broad and largely non-technical. It ranks business risk. A penetration test is hands-on and technical. It proves whether specific weaknesses can genuinely be exploited. The risk assessment usually comes first, and it helps decide what the penetration test should focus on.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.