Ctrl + K
CM
Compliance ManagerAdministrator
Risk Register
Information Security › Risk Management › Risk Register
Last updated: 24 May 2025 09:32 AM
Total Risks
142
8 vs last month
High Risks
28
3 vs last month
Risks Under Treatment
64
6 vs last month
Accepted Risks
15
2 vs last month
Overdue Actions
9
2 vs last month
Residual Risk Score
3.8 / 5
Moderate vs last month
Risk Heat Map (Inherent Risk)
Likelihood
Very High01245
High13676
Medium24863
Low13421
Very Low01100
Very LowLowMediumHighVery High
Impact
- Extreme (15)
- High (20)
- Medium (28)
- Low (51)
- Very Low (28)
Total Risks: 142
Risk Treatment Progress
- In Treatment64 (45%)
- Planned32 (23%)
- Monitoring18 (13%)
- Completed22 (15%)
- Not Started6 (4%)
Total: 142 Risks
Top Risk Categories
Information Security
48 (34%)
Technology & Infrastructure
32 (23%)
People & Training
24 (17%)
Third Party / Supplier
18 (13%)
Physical Security
12 (8%)
Total: 142 Risks
Trend: Risks Opened vs Closed
- Opened
- Closed
Last 5 Months
Quick Actions
| Risk ID | Asset / Process | Threat | Vulnerability | Likelihood | Impact | Risk Level | Owner | Treatment Plan | Due Date | Status | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| RISK-2025-001 | Customer Database | Unauthorized access | Weak access controls | High | Very High | Extreme | AR A. Rahman IT Security Manager | Implement MFA and role-based access | 30 Jun 2025 | In Treatment | |
| RISK-2025-002 | Email System | Phishing Attack | User susceptibility | High | High | High | SP S. Patel Head of IT | Security awareness training & phishing sim | 15 Jun 2025 | In Treatment | |
| RISK-2025-003 | Cloud Infrastructure | Service Outage | No multi-region dependency | Medium | High | High | MJ M. Johnson Cloud Architect | Implement multi-region failover | 31 Jul 2025 | Planned | |
| RISK-2025-004 | HR Onboarding Process | Insider Threat | Excessive access privileges | Medium | High | High | LC L. Chen HR Manager | Implement joiner-mover-leaver process | 10 Jun 2025 | Overdue | |
| RISK-2025-005 | Vendor Management | Third-party breach | Incomplete vendor assessments | Medium | Medium | Medium | DW D. Williams Vendor Manager | Update vendor risk assessments | 20 Jun 2025 | In Treatment | |
| RISK-2025-006 | Backup Systems | Ransomware | Backups not tested regularly | Low | High | Medium | PS P. Singh IT Operations | Quarterly backup restoration testing | 05 Jul 2025 | Monitoring | |
| RISK-2025-007 | Physical Access | Tailgating | No visitor control in some areas | Low | Medium | Low | KB K. Brown Facilities Manager | Install access control system | 30 Aug 2025 | Planned | |
| RISK-2025-008 | Data Encryption | Data Exposure | Unencrypted data at rest | Low | High | Medium | AR A. Rahman IT Security Manager | Encrypt sensitive data at rest | 15 Jul 2025 | In Treatment |