Cyber Risk Compendium

A practical guide to cyber risk management

This is a generic tutorial for anyone who does not know where to start, written especially with small and medium-sized enterprises (SMEs) in mind. Obviously, not everyone starts from the same position. In this guide, we concentrate on getting the very basics set up for systematic continuous improvement afterwards.

So you want to establish a professional cyber risk management? This is great. Awareness that this is no longer optional for any company size is the place to start. So let’s get you started.

The topic is pretty complex and there are different angles you can use to approach the wider subject. The approach we describe in this guide is based on the following assumptions:

  • regardless of where you stand at the moment with our risk management, it is crucial to get the basics right before turning to complicated and maybe expensive special subjects. Thus, we want to make sure, we build on a solid foundation.

  • establishing security is a journey, for everyone. This is because no organisation, not even large enterprises, have the unlimited resources needed to tackle every aspect at the same time. All of us have constraints, be it financially, skill, labour or otherwise. Thus, we simply can’t “get it right” in one go. We need to improve step by step.

  • not everybody values the same things. Some need to protect money, others confidential personal information and a third group requires a close to 100% service uptime as lives may depend on it. We will prioritise what is needed in what order.

As you will see in the coming chapters, nearly every step of the process is full of tradeoffs to balance. There is no absolute security, no 100% goal to reach. Instead, it is a constant economical optimisation between the cost of implementing and maintaining countermeasures and the cost of the acceptance of residual risks.

In this short introduction, we focus on getting the basics right and reach the point, where you can start with a continuous improvement.

Phase 1: Capture the picture

In this first phase, we want to get a first overview: what needs protecting, what could realistically go wrong, and who is responsible if it does. This is deliberately a desk exercise — you don't need any budget or management buy-in yet, just an hour or two of focused thinking.

Step 1.1: Know what you need to protect most

Knowing what to protect is key for any risk management. Consider your Asset inventory to be the first villages, cities and sites on your virtual map of the world. These are the things you want to protect. Most organisations have at least hundreds to thousands of assets to protect, e.g. every employee has a notebook, PC and/or mobile. Having all in a neat list takes potentially a lot of time, especially if you have no tools to help you out on this task.

But the good news is, you don’t need to have this to start out. Let’s start by simply identifying categories of assets. Have a look at the categories under Asset, extract those you see relevant and bring them into an ordered list, ranked from most valuable to least valuable.

Step 1.2: Evaluate business impact and assign ownership

For each asset category, conduct a business impact analysis to define protection goals. If you now look at an asset category and you think “it depends, I cannot answer this for this whole asset category”, then you need to split out the individual assets that have separate characteristics.

Example: one asset category is likely “financial assets” and money sits in a bunch of different bank accounts. Money is money. It is very likely, that money sitting on individual bank accounts will need very similar protection, regardless of what bank account it is in. In this case, you can create a business impact analysis for an asset category. Counterexample: if you systematically hold the majority of your money in one single bank account, you might want to single out this bank account and perform a business impact analysis on that one plus a separate one for a whole group of other, less important accounts. Start pragmatic. You can and likely should always go into more detail to be sure to capture the whole picture, but you will not be able to tackle everything at once. Thus focus on the things of major importance at first, refine it only later.

Every asset should be assigned to an Asset owner responsible for its protection and oversight. You can either assign individual assets in the list or whole categories. The asset owner is the person that will be responsible to accept residual risks or decide to implement controls to mitigate risks, so make it somebody from senior management or at least with access to senior management.

Step 1.3: Identify primary risks

Next, select the assets with the highest need of protection, and for each, browse the Risk catalogue to identify which pre-defined risks apply to your organisation — add them to your risk directory. To keep its 57 entries manageable, they're grouped into seven areas: Identity & Access Management, Software & System Security, Network & Infrastructure, Human Factors & Social Engineering, Physical Security, Third-Party & Supply Chain, and Governance, Compliance & Continuity. Go through them one area at a time rather than all at once.

Be pragmatic at first. Yes, you should strive to get a full picture of risks, but remember, you will not be able to implement an infinite number of controls to mitigate them all at once. Start with those risks where you have the worst feeling thinking about it — often, your hunch will be right. Use the catalogue to make sure you don't forget something important elsewhere just because one risk was already on top of your mind. If your organisation's exact situation isn't covered by an existing entry, the underlying Threat catalogue can help you construct a new one from first principles.

Step 1.4: Evaluate risks and assign ownership

Evaluate probability and impact of each risk before taking action to mitigate it. This is known as the risk's inherent value — see for how this changes once controls are applied.

Every risk should be assigned a responsible Risk owner for treating it.

Step 1.5: Define first mitigations

Before diving into mitigations, keep in mind there are four standard ways to treat a risk: mitigate it (reduce likelihood or impact via a Control), accept it (the risk owner formally signs off on the residual risk), transfer it (e.g. via cyber insurance, or contractually to a supplier), or avoid it (stop doing the thing that creates the risk). Insurance in particular is often underused by SMEs — for lower-probability, high-impact risks it can be faster and cheaper than building new controls.

Next, risk owners should find mitigations. Often this is best done in a team as brainstorming can help you identify more options.

Pretty often, the option considered technically the “best” or most elegant can also require significant investment to implement. Thus, try to come up with different ways of mitigating the problem as everyone always has finite resources and in the end, you will have to choose what you can actually achieve in the coming weeks and months. You might think of less elegant organisational measures as poor workarounds, but they are often quicker and cheaper to implement, giving you at least some immediate relief, until you can come up with a better solution.

But always be aware, that organisational measures are often much less reliable than technical measures and often generate additional complexity and effort for people doing the work that is sometimes hard to capture in financial cost.

If a control genuinely can't be implemented right now — technically or economically — don't just let the risk sit undocumented. Have the risk owner formally approve an instead, with a review date attached. That turns an invisible gap into a tracked, time-boxed decision that someone is accountable for revisiting.

Wrap up phase 1

Great, you made it through phase 1 — many organisations get here in a single half-day workshop. You have identified the most crucial asset categories, the most important risks, and first ideas for countermeasures. Consider this the theoretical groundwork — next, phase 2 turns it into action.

Phase 2: Operationalise risk management

Phase 1 was the easy part. If nobody else cares, you can easily do it yourself, it does not require much investment, basically it is a theoretical mind experiment with little outcome yet. The difficult next step is to initiate action, request funding and ensuring management buy-in. This is where many initiatives fail.

Step 2.1: Communicate risk and the urgency for action

Of course, ideally you are already backed in your endeavour by management and peers from the start in phase 1, but we treat this step in this second phase as this is when it becomes crucial for success.

This is essentially a communication task. In order to get a change process rolling, people need to understand the need to change. With your results from phase 1, you should have a solid basis to communicate risk now.

Note that being an alarmist can be self-sabotaging in this step. Instead, what usually works is a very matter-of-fact approach, based on the following steps:

  1. Legally, overall responsibility for risk management resides with upper management and cannot be delegated away. For private companies, this follows from the board's duty of care and diligence under Swiss company law (Art. 717 OR); for public organisations, equivalent responsibility usually sits with the cantonal or municipal executive board. In case of negligence, members of these boards may even be personally liable with their private assets. Pointing out these legal provisions as a starting point will usually capture the attention of senior management. See also Senior management / Board of Directors and Regulator / supervisory authority.

  2. When communicating risk, you should present them in a self-descriptive manner that allows management to understand the consequences. For every risk, you should then recommend an action. This is either a countermeasure and its price tag, or you might recommend a risk to be accepted, making the management responsible for the decision of inaction.

Sometimes, you may find that senior management does not follow your recommendation and you might feel, they take the wrong decision on some points. Always be aware, that in step 1 you established that it is senior management that is responsible and senior management thus has the last word. This is okay. Communicating risk is not about winning an argument, it is about establishing transparency and providing the foundations for a decision. If decisions are taken based on solid and objective evaluations, you have succeeded.

Step 2.2: Establish roles and processes

Most organisations already have a risk process and roles established. Many times, the only thing missing is that IT risks were not considered important enough yet to be an integrated part of risk management at the highest level. Ideally, you can integrate IT risks in an already existing risk management process.

If not, you will have to set up roles and processes now that will allow you to operate risk management for an indefinite time into the future — think Risk owners, Control owners, and, once you have enough scale, a dedicated CISO / Information Security Officer. Cyber risks develop over time, thus it is an error to think you can take a one-time measure and then sit still for the next decade.

There are many good ways to set up this organisation, there is no single way that is right. Include the following properties in your organisation and you will likely succeed:

  • Build a team: get a couple of key persons to carry the process with you.

  • Set up a meeting series where you track implementation progress and reevaluate risks from time to time

  • Establish a reporting interval with senior management where you can present updates and request sponsorship for recommended actions

For a small organisation, this doesn't need to be elaborate — “the team” might just be you and one colleague meeting for an hour every quarter. What matters is that it happens regularly, not how formal it looks.

Step 2.3: Get to work

Now you know what measures to work on and with whom.

Wrap up phase 2 — and what comes next

You now have assets identified and owned, priority risks logged and assigned, first mitigations decided, management bought in, and roles and a cadence established. That's the foundation this guide promised — from here on, cyber risk management is no longer a one-off project but a recurring cycle.

Continuous improvement means returning to phase 1 on a regular basis rather than treating it as done: re-run the asset review whenever your organisation changes meaningfully (new systems, new offices, growth in headcount), re-evaluate risks at least annually or after any significant incident, and check whether your mitigations and Exceptions are still valid or need to be revisited.

As your practice matures, you can layer in more advanced topics covered elsewhere in this compendium — for example reducing your , building an for your highest-value assets, or running exercises with a or . But none of that is necessary to get started — the point of this guide was simply to get the basics right first.