---
title: How to Identify Your Security Risks & Develop a Plan You Can Afford
description: Wondering where to start with a risk assessment plan? Find out how to identify your risks and develop a risk assessment plan your business can afford.
image: https://www.truvantis.com/hubfs/how-to-identify-your-risks-develop-a-plan-you-can-afford-hero.jpg
---

[![truvantis-logo-reverse@2x](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-reverse@2x.png?width=1117&height=250&name=truvantis-logo-reverse@2x.png "truvantis-logo-reverse@2x")](https://www.truvantis.com)

[![truvantis-logo-main@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?width=1117&height=250&name=truvantis-logo-main@2x-1.png "truvantis-logo-main@2x-1")](https://www.truvantis.com/)

**

## Blog

![](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?length=200)

# How to Identify Your Security Risks & Develop a Plan You Can Afford

 March 18, 2020

When it comes to conducting security risk assessments, it can be difficult [knowing where to get started. Even after identifying your scope and assets, there are a number of vulnerabilities and threats to be considered](https://www.truvantis.com/blog/how-to-actually-use-your-risk-assessment-report).

Add some structure to your risk assessment analysis by properly outlining all your risks. Don’t just go with your gut— develop a plan for improving your security that is realistic, timely, relevant, and follows an industry standard framework and approach.

**Here are our recommendations for defining and addressing your risks in an affordable way: **

## Know Your Input Metrics

Before you can hope to produce an output and receive tangible results, you must first start by defining your inputs. 

Cybersecurity risk is the probability and magnitude of something bad happening at a future time. This risk is the product of a threat paired with a vulnerability: the likelihood of that threat occurring and its impact.

If any of these terms are unfamiliar, review our [Risk Assessment page](https://www.truvantis.com/performing-a-risk-assessment), which defines and shows examples of industry words like “threat,” “vulnerability,” “risk,” “asset,” “control,” “risk response,” “impact,” etc. In the world of risk management, there is a long list of terminology to understand before you can start identifying your risks, and this is the best place to start.

## Create a List of Your Assets

It’s not uncommon for companies to assume that the only things that need to be assessed are their physical assets like hardware (computers, mobile devices, servers, etc.), but that’s not the only assets you need to protect. 

Consider any sensitive data you have stored, including personal, patient or financial records. It could be intellectual property to your organization, brand, reputation or code you have developed. Also consider your systems software and application tools, operating systems, etc. 

Really think outside of the box and list your suppliers and vendor relationships, as well as people internally who carry knowledge about how your company operates. If these companies were hacked or leaked information that could affect your business, they are potential threats to your company.

## Use a current Threat Catalog

A threat catalog is a list of the generic threats often seen in risk assessments. They include events, actions, inactions and more that could mean bad things for your information security assets and are used to match each potential threat actor with a vulnerability and asset.

This catalog will help to map out potential threat vectors and scenarios for risk, or all the different routes that bad actors or attacks may take to threaten your business security. 

## Finalize a Risk Register

This threat catalog will enable you to produce a list of threats to pair with  vulnerabilities— which will then be placed in a [risk register](https://www.truvantis.com/blog/how-to-actually-use-your-risk-assessment-report). 

[A professional risk assessor](https://www.truvantis.com/blog/why-you-should-invest-in-a-professional-risk-assessment) or a qualified member of your staff will calculate the value and potential cost for each risk occurring, and organize them by priority with a risk score. This provides clarity around which risks are most important to address, as a result of the potential impact, and helps you to determine which risks take precedence over others. 

## Review Your Budget & Weigh Your Treatment Options

Now that you have a list of the most important and most costly risks on your report, you’ll need to consider your budget. Realistically, you may not have the financial ability to mitigate all your potential risks at once, and you’ll need to establish clear timelines and treatment plans for addressing each risk.

Fortunately, you’ll have various options for addressing the neatly detailed risks in your risk register: including the choice to [accept, transfer, mitigate, or avoid](https://www.truvantis.com/performing-a-risk-assessment) each. From here, you can use your impact projections on your risk assessment to justify which risk treatments are right for you and your budget.

## Hold Yourself Accountable for Progress

After first receiving the risk assessment results you may be inspired to take instant action and achieve a few quick wins. But many necessary security improvements don’t happen overnight, and you need measures in place to ensure you follow through on what you start.

Whether that means setting progress meetings once a month or assigning owners to each asset to be responsible for each mitigation or follow through, keep up with your changes and set goals for new ones to come. 

## Get More Out of Your Risk Assessment

Identifying your risks is only the beginning of your path to better risk management. Get real value out of your risk assessment by taking these six important steps.

Let the experts at Truvantis® deliver proactive results to set you up for success improving your cybersecurity. [Contact us](https://www.truvantis.com/contact/) for help performing or actionizing the results of your risk assessment, today.   

#### Related Articles By Topic

[Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### Subscribe Here!

### Recent Posts

### Related Articles By Topic

- [Security Program (76)](https://www.truvantis.com/blog/tag/security-program)
- [vCISO (38)](https://www.truvantis.com/blog/tag/vciso)
- [CISO (35)](https://www.truvantis.com/blog/tag/ciso)
- [PCI DSS (28)](https://www.truvantis.com/blog/tag/pci-dss)
- [SOC2 (28)](https://www.truvantis.com/blog/tag/soc2)
- [Penetration Testing (27)](https://www.truvantis.com/blog/tag/penetration-testing)
- [Privacy (26)](https://www.truvantis.com/blog/tag/privacy)
- [Risk Assessment (19)](https://www.truvantis.com/blog/tag/risk-assessment)
- [CIS Controls (12)](https://www.truvantis.com/blog/tag/cis-controls)
- [Red Teaming (8)](https://www.truvantis.com/blog/tag/red-teaming)
- [HIPAA (7)](https://www.truvantis.com/blog/tag/hipaa)
- [Threat Intelligence (7)](https://www.truvantis.com/blog/tag/threat-intelligence)
- [ISO27001 (6)](https://www.truvantis.com/blog/tag/iso27001)
- [CCPA (5)](https://www.truvantis.com/blog/tag/ccpa)
- [CPRA (2)](https://www.truvantis.com/blog/tag/cpra)
- [GDPR (2)](https://www.truvantis.com/blog/tag/gdpr)
- [Ransomware (2)](https://www.truvantis.com/blog/tag/ransomware)
- [Red Team (2)](https://www.truvantis.com/blog/tag/red-team)
- [HITRUST (1)](https://www.truvantis.com/blog/tag/hitrust)

[See all](https://www.truvantis.com/blog/how-to-identify-your-risks-develop-a-plan-you-can-afford#)

Contact Us

Chat with one of our specialists about our Risk Assessment service.

[![Schedule a call](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/1957d0c0-9fb7-490a-a8f3-d95b9085a3c6.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/1957d0c0-9fb7-490a-a8f3-d95b9085a3c6)

[![Contact Us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/ccf084a3-d095-4418-80d6-891f8fdade46.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/ccf084a3-d095-4418-80d6-891f8fdade46)

### Recent Articles

![Truvantis - Cybersecurity Maturity - One Size Does Not Fit All ](https://www.truvantis.com/hubfs/Blogs/Cybersecurity%20Maturity%20-%20One%20Size%20Does%20Not%20Fit%20All.png)

 PCI DSS, CIS Controls, Security Program, Privacy, ISO27001 

[ Cybersecurity Maturity - One Size Does Not Fit All – Rick Folkerts ](https://www.truvantis.com/blog/cybersecurity-maturity-one-size-does-not-fit-all-rick-folkert)

 It's common knowledge that enterprise organizations need effective security, privacy and compliance programs to survive and grow. There are a handful of generic best practices but beyond that, cybersecurity programs must be tailored to...

[Read more **](https://www.truvantis.com/blog/cybersecurity-maturity-one-size-does-not-fit-all-rick-folkert)

![The Silver Bullet Defense to Ransomware – by Andy Cottrell](https://www.truvantis.com/hubfs/Blogs/The%20Silver%20Bullet%20Defense%20to%20Ransomware%20%E2%80%93%20by%20Andy%20Cottrell.png)

 Ransomware 

[ The Silver Bullet Defense to Ransomware – by Andy Cottrell ](https://www.truvantis.com/blog/the-silver-bullet-defense-to-ransomware-by-andy-cottrell)

 In an era of cost-cutting, downsizing and generally insufficient budgets for everything, we are often asked, what is the one, main thing to do to protect against a ransomware attack? According to Statista, in 2022, there were 493.33 mi...

[Read more **](https://www.truvantis.com/blog/the-silver-bullet-defense-to-ransomware-by-andy-cottrell)

![Cryptographic Agility – by Jeff Hall (the ’PCI Guru’)](https://www.truvantis.com/hubfs/Blogs/Cryptographic%20Agility%20%E2%80%93%20by%20Jeff%20Hall%20(the%20%E2%80%99PCI%20Guru%E2%80%99).png)

 Security Program 

[ Cryptographic Agility – by Jeff Hall (the ’PCI Guru’) ](https://www.truvantis.com/blog/cryptographic-agility)

 With the advent of quantum computing, a new threat has been added to the information security mix. The threat is today’s secure cryptography may not be secure once quantum computers reach their potential. The threat to cryptography has...

[Read more **](https://www.truvantis.com/blog/cryptographic-agility)

[![truvantis-logo-white@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-white@2x-1.png?width=1117&height=250&name=truvantis-logo-white@2x-1.png "truvantis-logo-white@2x-1")](https://www.truvantis.com/)

[info@truvantis.com](mailto:info@truvantis.com)

+1 (415) 422-9844

<https://www.facebook.com/truvantis> <https://www.linkedin.com/company/truvantis> <https://twitter.com/truvantis?lang=en>

© 2024 Truvantis, Inc All Rights Reserved.

[Privacy Policy](https://www.truvantis.com/privacy-policy)    [Terms of Service ](https://www.truvantis.com/terms-of-service)

![](https://px.ads.linkedin.com/collect/?pid=2614233&fmt=gif) ![](https://ws.zoominfo.com/pixel/dnjpprEKcMtv41HRInFR)