Compliance & regulations
What is a cybersecurity risk assessment, and how often should we do one?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
A cybersecurity risk assessment — often delivered as a threat and risk assessment (TRA) — identifies what information and systems you have, the threats and vulnerabilities they face, the likelihood and impact of those risks, and how to reduce them to an acceptable level. Conduct a full assessment at least once a year, and again after any significant change: a new system or product, a merger or acquisition, a major incident, or a new regulatory requirement. Between formal assessments, manage risk continuously.
On this page
What a risk assessment involves
A risk assessment is a structured process to understand and prioritize risk. It identifies your assets and the data they hold, the threats and vulnerabilities affecting them, the likelihood and potential impact of each risk, and the controls or treatments that bring risk within your tolerance.
The goal is not to eliminate every risk — that is impossible — but to make informed, documented decisions so that the controls you invest in are proportionate to the risks that actually matter.
How often to do one
- At least annually, as a baseline cadence expected by most frameworks and customers.
- After significant change — new systems, products, vendors, or architectures that change your risk profile.
- After a merger, acquisition, or major business change.
- Following a security incident or breach, to understand what happened and prevent recurrence.
- When new regulations or customer requirements apply to you.
Beyond the annual snapshot
A point-in-time assessment is necessary but not sufficient. Threats and your environment change constantly, so pair the formal annual TRA with ongoing risk management — monitoring, a maintained risk register, and reassessment whenever something material changes. Frameworks like SOC 2 and ISO 27001 expect this continuous approach, not a once-a-year box-tick.
Frequently asked questions
No. A risk assessment is a broad evaluation of risks across people, processes, and technology. A penetration test is a focused, technical exercise that simulates attacks to find exploitable vulnerabilities. They complement each other — the assessment sets priorities; the pen test validates technical defences.
Yes. A right-sized risk assessment helps a small business focus limited resources on its highest risks instead of guessing. It is also frequently required to satisfy customers, insurers, and compliance frameworks.
Keep exploring
All Compliance & regulationsHow can I protect my personal and business information from cyberattacks?
A practical, layered approach to protecting personal and business information from cyberattacks: MFA, patching, backups, training, and a tested incident plan.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadCompliance & regulationsWhat is a HIPAA security risk assessment, and do you need one?
What is a HIPAA security risk assessment, and do you need one? Learn what the assessment covers, who must do it, what's involved, and how to scope it.
ReadCompliance & regulationsWhat is PIPEDA, and does it apply to my business?
What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do.
ReadCompliance & regulationsDoes HIPAA apply to my software or business?
HIPAA applies to covered entities and the business associates that handle protected health information (PHI) on their behalf. Find out whether that includes your business.
ReadCompliance & regulationsDoes GDPR apply to my business if we're outside Europe?
The GDPR can apply to organizations anywhere if they offer goods or services to, or monitor, people in the EU/EEA. Learn when it reaches your business and what to do.
Read