RRA
Risk Management
Rapid Cyber Risk Assessment Workbook
A focused worksheet for identifying important assets, credible threats, existing safeguards and the risks requiring action first.
Designed for: Owners, executives, security teams, consultants and department leaders
RRA Tech Zone LLC · Proprietary educational resource · Version 1.0 · September 2026
Define the assessment
- Business unit, system or process in scope
- Assessment owner and participating stakeholders
- Critical services and operational dependencies
- Applicable obligations and risk criteria
Identify risk
- List critical information, systems, people and suppliers.
- Identify credible threat events and likely attack paths.
- Record vulnerabilities and control weaknesses.
- Describe business, financial, legal, safety and reputational impacts.
Score consistently
- Likelihood: 1 Rare to 5 Almost Certain
- Impact: 1 Negligible to 5 Severe
- Inherent risk: likelihood multiplied by impact before additional treatment
- Residual risk: risk remaining after current controls
- Document rationale so scores can be reviewed and repeated.
Treat and track
- Avoid, reduce, transfer or accept each risk.
- Assign one accountable owner.
- Define actions, resources and due dates.
- Specify the evidence that will prove completion.
- Escalate overdue high and critical risks to leadership.
Recommended next steps
- 1Begin with the five services the organization cannot operate without.
- 2Validate assumptions with technical and business owners.
- 3Address exposed access, untested backups and unsupported systems first.
- 4Record formally accepted risks and approval authority.
- 5Repeat after major changes and on a scheduled basis.