Risk assessment
A risk assessment that does not end in a spreadsheet nobody opens for a year. I build the register of assets, threats and risks, score impact and likelihood with your process owners, propose a treatment plan and hand it over in a form you can maintain — in Qzila or your own tool.
What you get
- Register of assets, threats and vulnerabilities with impact and likelihood scoring
- Business-impact analysis (BIA) and recovery objectives for critical processes
- Vendor and third-party risk assessment including contractual requirements
- Risk-treatment plan with owners, deadlines and cost estimates; statement of applicability
- Methodology and templates so your team can run the next round itself
When to get in touch
- ISO/IEC 27001, NIS2 or DORA require a documented risk assessment
- A risk register exists but nobody trusts it and it has not been updated in a year
- You are adopting a new system, vendor or cloud and want to know what you are risking
- The board wants a clear answer on what security costs and what it buys
How it works
- 01
Scope & method
Boundaries, scoring criteria, roles
Duration: 1 h - 02
Workshops & analysis
Interviews with process owners, asset inventory, scoring
Duration: 4–8 d - 03
Treatment plan
Measures, priorities, costs; management approval
Duration: 2 d - 04
Handover
Register in Qzila or your tool, methodology, training
Duration: 1 d
Other services
All services →Audit and regulatory readiness
Gap analysis, internal audit and certification readiness for ISO/IEC 27001 and ISO 22301, audits under NIS2 and the Czech Cybersecurity Act, DORA compliance assessment — including preparation of the documentation the regulation requires.
Read more →AWS audit
A review of your AWS environment against the AWS Well-Architected Framework and security benchmarks: identity and access, network, encryption, logging, backups, resilience and cost — with a prioritised remediation plan.
Read more →Technical due diligence
An independent assessment of the technology, security, operations and team of a company you are buying, funding or depending on — in days, with a report for the investment committee.
Read more →Thirty minutes that save you months
Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.
- You talk directly to the auditor who does the work
- Fixed scope and price before anything starts
- NDA on request, deliverables in Czech or English