Skip to content

Create your first risk assessment

A risk assessment collects risk scenarios for a perimeter, rates each one for probability and impact, and lets a risk matrix compute the resulting risk level. Before you can create one, the matrix — and ideally a threat catalog and reference controls — must be imported from the library catalog.

This walkthrough assumes you already have a domain and perimeter.

  1. Open Governance → Libraries.

  2. Import a risk matrix — one of the built-in matrices is fine to start with. This is the only hard prerequisite.

  3. While you are there, also import a threats library and a reference controls library. They are optional, but they give you a vocabulary to build scenarios from instead of starting blank.

  1. Open Risk → Risk assessments and select Add risk assessment.

  2. Give it a Name, pick your Domain and optionally your Perimeter, and select the Risk matrix.

  3. Save and open the assessment. The view has three parts: the assessment details, the list of associated risk scenarios (empty for now), and the risk matrix view.

  1. From the assessment, select Add risk scenario and describe an unwanted event — for example, ransomware encrypting a file server.

  2. Link the relevant threats from the imported catalog. If the threat you need is missing, create a custom one with Add threat.

  3. Do the current assessment: rate the scenario’s Probability and Impact as things stand today, with existing measures in place. The matrix computes the current risk level automatically.

  4. Decide the treatment. To mitigate, create the measure with Add applied control — for instance an offline backup policy — and attach it to the scenario as a planned control. Depending on the scenario you may instead accept, avoid or transfer the risk.

  5. Back in the scenario, do the residual assessment: rate the probability and impact you expect once the planned controls are implemented, and set the Strength of knowledge to record how confident you are in the rating.

Back in the risk assessment view, the scenario now appears in both the current and residual matrix views, with a diamond marker indicating the strength of knowledge. Repeat for each scenario worth tracking — and once management decides to tolerate a residual risk, formalize it as a risk acceptance.

Congratulations — you have created your first assessments in CyberGuard. Explore the feature sections to go further.