RISK REGISTER · 10 MIN

A Cyber Risk Register the Board Will Actually Read

Most cyber risk registers are spreadsheets the board never opens. This is the structure CISOs use to make it the single most-cited artefact in the boardroom.

Run your first mission free

The minimum columns

Register columns

  • Risk ID & title. Unique, stable identifier and a one-line plain-English title — no acronyms.
  • Inherent impact / likelihood. Pre-control assessment, 1–5 each, with rationale.
  • Current controls. What is in place today, mapped to ISO 27001 Annex A or Essential Eight.
  • Residual impact / likelihood. Post-control assessment with rationale — the number the board sees.
  • Treatment plan. Accept / mitigate / transfer / avoid, with target residual rating and due date.
  • Owner + reviewer. Business owner, technical owner, last review and next review.

Mapping risks to Australian frameworks

Every active risk should reference the controls that mitigate it. For most Australian organisations that means ISO 27001:2022 Annex A, the ACSC Essential Eight and — where applicable — APRA CPS 230 / 234 and the SOCI Act. The mapping has two purposes: it lets the auditor walk from risk to control evidence in one click, and it surfaces controls that are doing no work.

Scoring scales the board can read

A 5×5 impact / likelihood grid is the regulator-recognised default. Define each level in plain English: "$10–50m loss or major regulator action" is more useful than "high". Boards consistently say the worst risk reports they receive use a 3×3 grid because everything ends up in the middle.

FOR CISOS

Generate your top-10 cyber risks with treatment plans tonight.

FORTE/CYBERx runs a structured risk identification mission against your context and produces a defensible top-10 with control mapping and recommended treatments.

Try a Risk mission

Quarterly cadence

  • Weekly — risk owners update treatment progress.
  • Monthly — CISO walks the top 10 with risk and audit leads.
  • Quarterly — full register review with the executive risk committee; movements flagged for the board.
  • Annually — methodology review against ISO 31000 and the ISO 27001 risk treatment process.

FAQ

What is a cyber risk register?

A live record of identified cyber risks, their impact and likelihood, current and target treatments, owners and review dates. It is the single source of truth between the CISO, the audit committee and the auditor.

How many risks should it contain?

For most Australian mid-market organisations, 25–60 active risks is realistic. Smaller registers under-state the picture; larger registers become unreadable. Aggregate at the right level — "ransomware via supplier" not "supplier X patched late on day 17".

Should we use qualitative or quantitative scoring?

Both. Qualitative (1–5 impact / likelihood) for the everyday register; quantitative (FAIR-style dollar ranges) for the top 5–10 risks the board cares about most.

Who owns each risk?

A named business owner (not the CISO) accountable for the residual risk acceptance, plus a named technical owner accountable for the treatment. Two named humans, every row.

Related

A risk register the board re-reads, not re-formats.

Two free missions. No credit card. Generate your defensible top-10.