Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityPublished: 10 July 2026

ISO 27001 Risk Assessment: Method, Example and Template

ISO 27001 risk assessment for SMEs: define criteria, analyse and treat risks, and connect decisions with controls and evidence.

An ISO 27001 risk assessment makes information risks comparable and actionable. A sound method defines scope, criteria, owners and review triggers. It does not jump from a threat to an arbitrary control; it links a justified treatment decision to specific measures and evidence.

What is assessed

The starting point can be information assets, business processes or scenarios. A scenario-based approach is often easier for SMEs: what could happen, which information or service would be affected, what cause is credible and what would the impact be on confidentiality, integrity or availability?

A practical six-step method

  1. Define scope and unit of assessment
  2. Describe scenarios using cause, event and impact
  3. Assess likelihood and impact against defined scales
  4. Consider existing controls and their effectiveness
  5. Choose treatment: avoid, reduce, transfer or accept
  6. Record residual risk, owner, measures, dates and evidence

Example risk-register entry

Table 1: ISO 27001 Risk Assessment: Method, Example and Template
FieldExample
ScenarioUnauthorised access to customer files after a role change
ImpactConfidentiality breach and customer notification
Existing controlOffboarding checklist
AssessmentElevated because access reviews are not performed regularly
TreatmentQuarterly access reviews and automated deprovisioning
Owner / dateHead of IT / Q3
Residual riskAcceptable after effectiveness review

Turning assessment into control

A risk register is useful only when actions are tracked and effectiveness is tested. Link each treated risk to the treatment plan, Statement of Applicability and verifiable evidence.

The method should be repeatable. New systems, material supplier changes, incidents or scope changes are common triggers for an additional review.

How Sternberg Consulting supports you

We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.

Discuss your project

Frequently asked questions

Does every asset need a separate risk?

No. Granularity must remain manageable, and one scenario may affect several assets or processes.

Can management accept risks?

Yes, when acceptance criteria are defined, the decision is authorised and legal or contractual duties are not breached.

Is a spreadsheet enough?

Often yes for an SME, provided version control, ownership, follow-up and access protection work.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.