Whenever an organisation works with information, risks will always be lurking somewhere. This applies to every organisation, think of personal data, process information or manuals for a particular product or service. As an organisation, you want to limit these risks. But how do you know which risks exist? For that, you can carry out an information security risk analysis.

Do you want to carry out a risk analysis around your information security but don't know where to start? With the help of this blog you can carry out a thorough risk analysis.


In this blog article, we discuss:


Interested in taking yout information security a step further? With Base27, you can easily carry out and manage your own risk analysis, all within one platform. Try Base27 for free and discover for yourself how straightforward it can be.


What should a risk analysis include?

A risk analysis provides a detailed overview of the threats that can occur within the chosen scope, an assessment of the likelihood and impact of these threats, and an evaluation of the existing security measures. The analysis also includes an assessment of which risks are acceptable and which require additional countermeasures.

A risk analysis needs to include several elements to be effective. The core components are:

  • Scope: This involves defining exactly what will be examined within the risk analysis, such as specific systems, processes, departments or suppliers.
  • Identification of threats: This part describes the possible threats that can occur within the scope. These threats can range from technical failures to human error and external attacks.
  • Risk assessment: Here, you assess the likelihood that a given threat leads to an incident, as well as the possible impact of that incident. This is often done using a risk matrix.
  • Current security measures: It's important to document the security measures already in place that can influence the likelihood or impact of threats.
  • Risk evaluation: Based on the likelihood and impact, you assess which risks are acceptable and which are not. This helps prioritise further action.
  • Recommended countermeasures: For risks that are not acceptable, suitable control measures should be proposed to reduce the likelihood and/or impact.
  • Responsibilities: This part assigns who within the organisation is responsible for managing the identified risks.
  • Follow up action and monitoring: A risk analysis should also include a plan for how the identified risks will be monitored and how the effectiveness of the countermeasures taken will be evaluated.

A good risk analysis is systematic, thorough and based on input from various people within the organisation. The process should begin with a clear definition of the scope. Involve all relevant parties to ensure that all potential threats and vulnerabilities are identified. Use a risk matrix to objectively evaluate the likelihood and impact of each risk. Make sure there's consensus on what acceptable risks are and which control measures are needed.

Document everything clearly and ensure regular updates and monitoring to keep the risk analysis up to date.

1. Determining the scope of the risk analysis

You base a risk analysis on a particular scope, such as:

  • an information system;
  • a (part of an) organisation;
  • a process;
  • a supplier;
  • et cetera.

For a large or extensive scope (think of a large process or a large organisation, for example), the risk analysis can be divided up, for instance into the different sub processes. In this case, the shared or overarching risks still need to be combined again at the end.


2. Identifying threats during the risk analysis

In an information security risk analysis, you determine which threats exist (for the given scope) that could lead to an incident: a disruption in service delivery, loss or damage of data, unauthorised access to confidential information for people who shouldn't have it, et cetera.

Threat Dreiging


Threat models

You can draw on your own knowledge and experience to identify threats, but you can also look at certain threat models. Depending on the scope, there are various options here. For information security,RAVIB, MAPGOOD and theOWASP Top Ten are all useful tools.

The advantage of a threat model is that it significantly reduces the chance of overlooking threats. It also often makes discussions easier, since it creates a clear distinction between different threats, and therefore risks.


3. Likelihood and impact in a risk analysis

Every relevant threat forms a risk, which you need to assess in terms of the likelihood and impact of the incidents mentioned. So not the likelihood of the threat itself, but of the incidents that result from it. 

Example: You could get a virus on your computer almost continuously, every day. But how often does this actually lead to incidents (loss of data or worse), and what's the impact when it does?


Clear criteria

It's important to have clear criteria about likelihood and, in particular, impact. After all, what's disastrous for one organisation might just be a significant loss for another, nothing more. You should therefore do this before starting the risk analysis, otherwise the outcome will be quite vague, since the risk assessments won't be comparable with each other.


Risk matrix

When carrying out a risk analysis, it's essential to assess the likelihood and impact of potential incidents. An important tool for this is the risk matrix, also known as the risk impact matrix. This is a visual tool that helps categorise and prioritise risks based on their probability (likelihood) and the severity of their consequences (impact). Once you've taken these steps, you'll typically end up with something similar to the risk matrix below:

Risk matrix


What is a risk matrix and how does it work?

A risk matrix plots risks along two axes: the likelihood of a risk occurring, and the impact it would have if it did occur. This matrix helps you quickly identify which risks need immediate attention (usually in the red area of the matrix) and which can be considered acceptable (green area). To fill in the matrix, you assess each risk based on how often it's likely to happen and how much damage it would cause if it did. This is often done using a scale of 1 to 5, where 1 represents a low likelihood or impact and 5 a high one. At Base27, however, we work with a scale that better reflects the actual likelihood/impact rating.


How do you create a risk matrix and what should it include?

Creating a risk matrix starts with identifying all the possible risks that could affect your organisation. Next, you assess the likelihood and impact for each risk. These assessments are then placed in the matrix, giving you an overview of the severity of each risk. A well populated risk matrix gives a clear picture of which risks should be prioritised for control measures and which risks can be accepted without further action.


Risk acceptance and mitigation

Not all risks in the risk matrix will require the same approach. Risk acceptance is an important consideration. This means deciding to accept certain risks without taking additional measures, because the cost or effort of mitigating them doesn't outweigh the potential damage. Mitigating a risk, on the other hand, means taking countermeasures to reduce the likelihood of the risk occurring or to reduce its impact. This can range from improving security measures to training staff or adjusting procedures.


How do you determine the likelihood of a risk?

The likelihood of a risk occurring can be determined using both historical data and expert judgement. This involves evaluating how often similar incidents have occurred in the past and estimating how likely they are to occur again in the future. An accurate estimate of this likelihood is crucial for a reliable risk matrix.

Tip: Use an ISMS tool, such as Base27, to partly automate this process.


4. Carrying out the risk analysis

It's important to carry out a risk analysis with a group of involved and experienced people, rather than just one or two individuals.

This gives a sharper picture of the risks, allows discussion to take place, and usually results in a more complete and reliable outcome. It also provides a good starting point for taking measures against the risks, since there's more understanding and support for them.

If the group is large or widely spread out (in time or location), you can use a kind of risk collection form on which participants can assess likelihood and impact in advance. These can then be reviewed and combined at a later point.


5. Formulating identified risks

Formulating a risk starts with clearly identifying the threat and its potential negative consequence. A well formulated risk should be explicit about the cause, the possible incident, and the impact of that incident. The structure of a risk description generally includes three elements:

  1. Cause: What could cause the risk? This could be a specific threat, such as a technical failure, human error, or an external attack.
  2. Incident: What's the possible consequence of that cause? This describes what could happen if the threat becomes reality, for example loss of data, disruption of a service, or unauthorised access to sensitive information.
  3. Impact: What are the consequences of the incident? This describes the negative effects on the organisation, such as financial damage, reputational damage, legal consequences, or operational disruptions.

For example: "Due to insufficient patch management (cause), a malware infection could lead to data loss (incident), resulting in financial damage and reputational damage for the organisation (impact)."


6. Next steps for your information security risk analysis

It's equally important to appoint someone responsible for the risks. This is often the person responsible for the scope. After all, if a manager is responsible for a particular process, then risks that disrupt that process are also their responsibility. It's wise to have roles and responsibilities clearly defined within an organisation.

Once the risks have been identified and assessed, the next step is to determine which measures or actions need to be taken. These measures should, of course, reduce the likelihood and/or impact. These are set out in a risk treatment plan.


Risk analysis checklist:

  • Make agreements about likelihood and impact for the organisation in relation to risks;
  • Determine the scope for a risk analysis;
  • Appoint someone responsible (based on the scope);
  • Involve people who are involved or experienced in the analysis;
  • Choose a suitable threat model, if desired;
  • Identify risks for relevant threats and determine the likelihood and impact;
  • Take countermeasures for the risks that aren't acceptable.

Want to put your information security knowledge into practice right away? Try Base27 for free and see for yourself how easy it is to strengthen your organisation's information security.

We help companies with their digital security.