← Back to GRC Projects

PROJECT 01 / RISK MANAGEMENT

Enterprise Cybersecurity Risk Assessment

A simulated enterprise cybersecurity risk assessment demonstrating how assets, threats, vulnerabilities, business impact, existing controls, inherent risk, residual risk, and risk treatment decisions can be documented and communicated.

FRAMEWORK NIST CSF / NIST RMF
ASSESSMENT TYPE Enterprise Cyber Risk
METHODOLOGY 5 × 5 Risk Matrix
STATUS Complete

01 / EXECUTIVE SUMMARY

Assessment overview.

The fictional organization used in this assessment relies on cloud services, employee endpoints, enterprise identity, business applications, third-party providers, and centralized security infrastructure.

The objective is to identify cybersecurity scenarios that could negatively affect the confidentiality, integrity, or availability of critical business services and information.

Each scenario is evaluated for likelihood and business impact. Existing safeguards are then considered to estimate residual risk and determine an appropriate treatment strategy.

This project uses simulated organizational information and does not contain confidential information from a current or former employer.

02 / METHODOLOGY

Risk assessment methodology.

A simplified qualitative 5 × 5 methodology is used for this portfolio exercise. Likelihood and impact are scored from 1 through 5 and multiplied to produce a risk score.

01

Identify

Identify business processes, systems, information, users, infrastructure, and third-party dependencies.

02

Analyze

Identify credible threats, vulnerabilities, and risk scenarios affecting organizational assets.

03

Evaluate

Estimate likelihood and business impact to determine inherent risk before considering controls.

04

Assess Controls

Review preventive, detective, and corrective safeguards that reduce likelihood or impact.

05

Residual Risk

Estimate the remaining exposure after existing safeguards and compensating controls are considered.

06

Treat

Determine whether the risk should be mitigated, accepted, transferred, or avoided.

03 / RISK MATRIX

5 × 5 risk matrix.

Risk Score = Likelihood × Impact. The matrix provides a consistent method for prioritizing risk scenarios for treatment and escalation.

LIKELIHOOD
5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5
IMPACT →
Low Medium High Critical

04 / IDENTIFIED RISKS

Risk register.

The register translates technical cybersecurity scenarios into business risks that can be prioritized, assigned, treated, and monitored.

ID Risk Scenario L I Score Inherent Key Controls Residual Treatment
R-001 Privileged account compromise 4 5 20 Critical MFA, RBAC, PAM, logging Medium Mitigate
R-002 Exploitation of an unpatched internet-facing system 4 4 16 Critical Scanning, patching, configuration management Medium Mitigate
R-003 Successful phishing attack leading to account compromise 4 4 16 Critical Email filtering, MFA, awareness training Medium Mitigate
R-004 Sensitive information exposed through a third-party provider 3 5 15 Critical Vendor assessment, contractual requirements, monitoring High Mitigate / Transfer
R-005 Excessive employee access to sensitive business systems 3 4 12 High RBAC, least privilege, periodic access reviews Medium Mitigate
R-006 Insufficient security logging delays detection and response 3 3 9 High SIEM, centralized logging, alerting Medium Mitigate

05 / SAMPLE FINDING

Detailed risk analysis.

R-001

Privileged Account Compromise

CRITICAL
ASSET

Enterprise identity and privileged administration environment

THREAT

Credential theft, phishing, session theft, or account takeover

VULNERABILITY

Excessive privileged access, weak authentication controls, or insufficient monitoring

BUSINESS IMPACT

Unauthorized system access, sensitive data exposure, service disruption, and compliance impact

INHERENT RISK

Likelihood 4 × Impact 5 = Score 20 / Critical

TREATMENT

Mitigate

RECOMMENDED CONTROLS
  • Require strong MFA for privileged accounts.
  • Implement privileged access management and just-in-time administrative access.
  • Enforce role-based access and least privilege.
  • Perform recurring privileged access reviews.
  • Forward privileged authentication and administrative activity to centralized logging.
  • Alert on unusual privileged authentication and administrative behavior.
ESTIMATED RESIDUAL RISK MEDIUM

With stronger authentication, privileged access management, least privilege, recurring reviews, and centralized monitoring, the likelihood of successful misuse is reduced. The potential impact remains significant because of the sensitivity of privileged access.

06 / CONTROL MAPPING

Framework mapping.

The sample privileged-access finding can be connected to established cybersecurity control families and risk-management outcomes.

CSF NIST CSF 2.0

Protect outcomes involving identity management, authentication, and access control.

AC NIST SP 800-53

AC-2 Account Management and AC-6 Least Privilege.

IA NIST SP 800-53

IA-2 Identification and Authentication.

CIS CIS Control 6

Access Control Management.

PROJECT CONCLUSION

Risk translated into action.

This portfolio project demonstrates how cybersecurity issues can be converted into structured business risks, evaluated using consistent criteria, mapped to security controls, and communicated through actionable remediation recommendations.