Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Compliance & regulations

What is a cybersecurity risk assessment, and how often should we do one?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

A cybersecurity risk assessment — often delivered as a threat and risk assessment (TRA) — identifies what information and systems you have, the threats and vulnerabilities they face, the likelihood and impact of those risks, and how to reduce them to an acceptable level. Conduct a full assessment at least once a year, and again after any significant change: a new system or product, a merger or acquisition, a major incident, or a new regulatory requirement. Between formal assessments, manage risk continuously.

On this page

What a risk assessment involves

A risk assessment is a structured process to understand and prioritize risk. It identifies your assets and the data they hold, the threats and vulnerabilities affecting them, the likelihood and potential impact of each risk, and the controls or treatments that bring risk within your tolerance.

The goal is not to eliminate every risk — that is impossible — but to make informed, documented decisions so that the controls you invest in are proportionate to the risks that actually matter.

How often to do one

  • At least annually, as a baseline cadence expected by most frameworks and customers.
  • After significant change — new systems, products, vendors, or architectures that change your risk profile.
  • After a merger, acquisition, or major business change.
  • Following a security incident or breach, to understand what happened and prevent recurrence.
  • When new regulations or customer requirements apply to you.

Beyond the annual snapshot

A point-in-time assessment is necessary but not sufficient. Threats and your environment change constantly, so pair the formal annual TRA with ongoing risk management — monitoring, a maintained risk register, and reassessment whenever something material changes. Frameworks like SOC 2 and ISO 27001 expect this continuous approach, not a once-a-year box-tick.

Frequently asked questions

No. A risk assessment is a broad evaluation of risks across people, processes, and technology. A penetration test is a focused, technical exercise that simulates attacks to find exploitable vulnerabilities. They complement each other — the assessment sets priorities; the pen test validates technical defences.

Yes. A right-sized risk assessment helps a small business focus limited resources on its highest risks instead of guessing. It is also frequently required to satisfy customers, insurers, and compliance frameworks.

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.