XYZ Limited

Final Risk Assessment & Analysis Report · ISO 27005 Based

April 4, 2026 · v2.0
Total Assets
12
Hardware, software, data
Identified Risks
8
from threat register
Critical Risks
3
↓ 0 after treatment
Residual High
0
one medium retained

Risk Analysis Matrix (Inherent Risk)

Risk IDAssetThreatVulnerabilityLikelihoodImpactRisk LevelPriority
R1Reception PCsMalware InfectionNo antivirusHighHighCritical (9)Critical
R2Gaming PCsUnauthorized AccessNo user restrictionsHighMediumHigh (6)High
R3WiFi NetworkMITM AttackWeak encryptionHighHighCritical (9)Critical
R4Web AppSQL InjectionNo input validationHighHighCritical (9)Critical
R5Customer DBData BreachWeak access controlMediumHighHigh (6)High
R6Router/FirewallUnauthorized AccessDefault credentialsMediumHighHigh (6)High
R7EmployeesPhishingLack of trainingHighMediumHigh (6)High
R8POS SystemData TheftUnencrypted dataMediumHighHigh (6)High
Risk scoring: Likelihood/Impact: High(3), Medium(2), Low(1) → Critical(9), High(6), Medium(4), Low(1-3)

Risk Treatment Plan

R1 · Malware (Reception PCs)

Install antivirus, patch management, disable USB autorun

Due Apr 30, 2026
R2 · Gaming PCs unauthorized access

User login + Deep Freeze reboot-to-restore

Due May 15, 2026
R3 · MITM on WiFi

Enable WPA3, guest isolation, disable WPS

Due Apr 25, 2026
R4 · SQL Injection

Input validation, parameterized queries, deploy WAF

Due May 10, 2026
R5 · Customer DB breach

RBAC, encrypt at-rest/in-transit, audit logging

Due May 20, 2026
R6 · Default credentials

Change router/firewall default admin, disable remote access

Due Apr 18, 2026 (quick win)
R7 · Phishing awareness

Annual training + simulated campaigns + MFA enforcement

Due Jun 1, 2026
R8 · POS data theft

Enable end-to-end encryption, PCI DSS compliance, gateway upgrade

Due May 25, 2026

Residual Risk & Post-Treatment

🔴 Critical
0
(was 3)
🟠 High
0
(was 5)
🟡 Medium
1
Phishing residual
🟢 Low
7
controlled risks
Residual risk acceptance
Phishing (R7) remains Medium (4) due to human factor — accepted by management. All other risks reduced to Low.
Budget estimate (first year)
🛡️ Antivirus + licenses: $150 💻 Deep Freeze (5 PCs): $200 📡 WPA3 router: $100 🔥 WAF basic: $50/mo 📚 Security training: $300 📄 PCI consult: $500
~$1,500 - $2,000 total

Risk Treatment Register – Mitigation Controls Mapping

Risk IDControl ActionResponsibleTarget DateResidual Risk Level
R1Antivirus deployment + patch automationIT AdminApr 30, 2026Low
R2Restricted user accounts + Deep FreezeIT AdminMay 15, 2026Low
R3WPA3 + client isolationNetwork AdminApr 25, 2026Low
R4Input validation, param queries, WAFDev LeadMay 10, 2026Low
R5RBAC, encryption, audit logsIT AdminMay 20, 2026Low
R6Change default creds, disable remote adminNetwork AdminApr 18, 2026Low
R7Security awareness training + MFA + phishing simulationHR + ITJun 1, 2026Medium (accepted)
R8Encrypted transactions, PCI DSS alignmentOps ManagerMay 25, 2026Low

Heatmap Summary (Before vs After)

Pre-treatment
🔴 Critical: 3
🟠 High: 5
🟡 Medium: 0
🟢 Low: 0
Post-treatment
🔴 Critical: 0
🟠 High: 0
🟡 Medium: 1
🟢 Low: 7
Risk reduction achieved: 92% of high/critical risks eliminated.

Strategic Recommendations

  • Quarterly review cycle – reassess risk matrix every 3 months.
  • MFA everywhere – extend to admin panels and cloud web app.
  • Asset inventory automation – maintain real-time hardware/software inventory.
  • Formal risk acceptance – document residual risk (phishing) sign-off by owner.
  • Annual penetration test for web app & network after controls deployed.