Risk Assessment

Quantify threats. Justify controls. Communicate risk clearly.

The Risk Assessment module takes you from raw threat identification through structured scoring to residual risk — producing a defensible, exportable risk register your stakeholders can act on.

presydo Risk Assessment — inherent risk matrix with threat cards

Six steps from threat to residual risk.

A complete, structured workflow — from identifying threat actors to communicating residual risk after controls are applied.

Threat Scoring (Capability × Intentions)

Score each threat by the actor's capability and intentions to produce a consistent, comparable threat level across your risk register.

Multi-Category Impact Assessment

Assess impact across physical, reputational, operational, financial, and legal dimensions — configurable to your organisation's framework.

Inherent Risk Matrix

Compute inherent risk from the threat level and impact score on a visual 5×5 matrix before any controls are applied.

Controls Library

Maintain a reusable library of security controls, each rated for effectiveness, and apply them to individual threats with per-threat tracking.

Residual Risk Calculation

Automatically compute residual risk after controls are applied, giving decision-makers a clear before/after picture.

Link Threats to Sitrep Events

Connect risks directly to live Situation Report events, keeping your risk register grounded in observed ground truth.

Apply controls. Show what's left.

The controls library lets you build and reuse a catalogue of security measures. Apply controls to specific threats and watch residual risk recalculate automatically — giving you a clear, auditable before/after view for every risk in your register.

Reusable controls library with effectiveness ratings Per-threat control application and tracking Automatic residual risk recalculation Exportable risk register for stakeholder briefings
presydo Risk Assessment — controls library and residual risk output panel

For those who own the risk register.

Risk Assessment is built for practitioners who need to quantify, justify, and communicate security risk to decision-makers.

Risk Managers

Building and maintaining a defensible, audit-ready organisational risk register.

Security Consultants

Producing structured risk assessments for clients across multiple engagements.

Operations Directors

Needing clear residual risk outputs to prioritise security investment decisions.

Ready to get started?

Build your first risk assessment in minutes — no installation required.