risk analysis · BIA · vendors

Risk assessment

A risk assessment that does not end in a spreadsheet nobody opens for a year. I build the register of assets, threats and risks, score impact and likelihood with your process owners, propose a treatment plan and hand it over in a form you can maintain — in Qzila or your own tool.

What you get

  • Register of assets, threats and vulnerabilities with impact and likelihood scoring
  • Business-impact analysis (BIA) and recovery objectives for critical processes
  • Vendor and third-party risk assessment including contractual requirements
  • Risk-treatment plan with owners, deadlines and cost estimates; statement of applicability
  • Methodology and templates so your team can run the next round itself

When to get in touch

  • ISO/IEC 27001, NIS2 or DORA require a documented risk assessment
  • A risk register exists but nobody trusts it and it has not been updated in a year
  • You are adopting a new system, vendor or cloud and want to know what you are risking
  • The board wants a clear answer on what security costs and what it buys

How it works

  1. 01

    Scope & method

    Boundaries, scoring criteria, roles

    Duration: 1 h
  2. 02

    Workshops & analysis

    Interviews with process owners, asset inventory, scoring

    Duration: 4–8 d
  3. 03

    Treatment plan

    Measures, priorities, costs; management approval

    Duration: 2 d
  4. 04

    Handover

    Register in Qzila or your tool, methodology, training

    Duration: 1 d
Contact

Thirty minutes that save you months

Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.

  • You talk directly to the auditor who does the work
  • Fixed scope and price before anything starts
  • NDA on request, deliverables in Czech or English