Skip to content

Lab 01 — Build an Enterprise Risk Register

Item Details
Lab Lab 01 — Build an Enterprise Risk Register
Module 01 — GRC Fundamentals
Difficulty Beginner → Intermediate
Estimated Time 90–120 Minutes
Role GRC Analyst / Cybersecurity Risk Analyst
Primary Deliverable Enterprise Cybersecurity Risk Register
Environment Spreadsheet / GRC Workspace
Lab Type Governance, Risk & Compliance

You have recently joined NorthStar Digital Services, a fictional enterprise providing cloud-based services to business customers.

The organization has grown rapidly.

Over the last several years, new:

  • Cloud platforms.

  • SaaS applications.

  • Remote-working technologies.

  • Vendors.

  • Business applications.

  • Customer-facing services.

have been introduced.

However, cybersecurity risks are currently tracked inconsistently.

Some teams maintain spreadsheets.

Others track security issues through tickets.

Several risks are discussed during meetings but are never formally documented.

Leadership has therefore asked the GRC team to establish a centralized:

Enterprise Cybersecurity Risk Register

Your responsibility is to build the first version of this register.

You must identify meaningful risk scenarios, assess their severity, identify existing controls, determine residual risk, assign ownership, recommend treatment strategies, and create a summary suitable for senior management.

By completing this lab, you will learn how to:

  • Build an enterprise risk register.

  • Identify cybersecurity risk scenarios.

  • Write clear risk statements.

  • Identify threats and vulnerabilities.

  • Identify affected assets.

  • Determine business impact.

  • Assign risk owners.

  • Define likelihood and impact scales.

  • Calculate inherent risk.

  • Identify existing controls.

  • Evaluate control effectiveness.

  • Calculate residual risk.

  • Select risk-treatment strategies.

  • Develop remediation plans.

  • Establish target dates.

  • Track risk status.

  • Identify risks requiring escalation.

  • Build executive risk reporting.

Before beginning this lab, you should understand:

  • Security governance.

  • Enterprise Risk Management.

  • Risk assessment methodology.

  • Likelihood and impact.

  • Inherent risk.

  • Residual risk.

  • Risk treatment.

  • Security controls.

  • Control effectiveness.

Recommended lessons:

02 Security Governance
03 Enterprise Risk Management
04 Risk Assessment Methodology
07 Control Design & Implementation
08 Control Testing & Effectiveness

You will build the following workflow:

Business Environment
Assets & Processes
Threats
Vulnerabilities
Risk Scenarios
Likelihood × Impact
Inherent Risk
Existing Controls
Control Effectiveness
Residual Risk
Risk Treatment
Remediation Plan
Risk Owner
Monitoring & Reporting

Before assessing risk, understand the business.

NorthStar Digital Services operates the following environment.

The organization provides:

  • Customer SaaS applications.

  • Online customer portals.

  • Managed cloud services.

  • Technical consulting.

  • Customer support.

Approximately:

Employees: 2,500
Customers: 1,200+
Primary Cloud Platform: AWS
Secondary Cloud Platform: Azure
Corporate Identity: Microsoft Entra ID
Endpoint Fleet: Windows and macOS
Remote Workforce: 65%

The organization processes:

  • Customer information.

  • Employee information.

  • Financial information.

  • Authentication information.

  • Application logs.

  • Business-confidential information.

Your first task is to identify important assets.

Create an Asset Inventory worksheet.

Use the following columns:

Asset ID Asset Type Business Owner Criticality

Start with:

Asset ID Asset Type Business Owner Criticality
AST-001 Customer SaaS Platform Application Product Critical
AST-002 AWS Production Environment Cloud Cloud Engineering Critical
AST-003 Microsoft Entra ID Identity IT Critical
AST-004 Customer Database Data Product Critical
AST-005 Employee Endpoints Endpoint IT High
AST-006 Corporate Email SaaS IT High
AST-007 Source Code Repositories Development Engineering High
AST-008 Backup Platform Infrastructure IT Critical

Add at least five additional assets that you believe should be included.

Consider:

  • Network infrastructure.

  • CI/CD platforms.

  • HR systems.

  • Finance systems.

  • Security platforms.

  • Vendor services.

  • Customer-support systems.

Risk cannot be properly evaluated without understanding what the organization is trying to protect.

Before assigning scores, define consistent criteria.

You will use a 5 × 5 risk matrix.

Risk score:

Risk Score = Likelihood × Impact

Create the following scale.

Score Rating Description
1 Rare Highly unlikely
2 Unlikely Could occur but not expected
3 Possible Could reasonably occur
4 Likely Expected to occur
5 Almost Certain Expected frequently

Use:

Score Rating Description
1 Insignificant Minimal business impact
2 Minor Limited disruption
3 Moderate Material operational or financial impact
4 Major Significant business/customer impact
5 Severe Enterprise-level or regulatory impact

When assigning impact, consider:

Confidentiality
Integrity
Availability
Financial Loss
Regulatory Exposure
Customer Impact
Operational Disruption
Reputation

Use:

Score Rating
1–4 Low
5–9 Moderate
10–16 High
17–25 Critical

Your methodology should be documented before assessing risks.

This prevents teams from changing scoring rules to produce preferred results.

Create a worksheet named:

Enterprise Risk Register

Use these columns:

Field
Risk ID
Risk Title
Risk Statement
Asset / Process
Threat
Vulnerability
Business Impact
Likelihood
Impact
Inherent Risk Score
Inherent Rating
Existing Controls
Control Effectiveness
Residual Likelihood
Residual Impact
Residual Risk Score
Residual Rating
Risk Owner
Risk Treatment
Remediation Action
Target Date
Status

A useful structure is:

There is a risk that [threat/event] may exploit [condition/vulnerability], resulting in [business impact].

Avoid weak entries such as:

Phishing Risk

Instead write:

There is a risk that threat actors may successfully compromise employee credentials through phishing because employees rely on phishing-susceptible authentication methods, resulting in unauthorized access to corporate systems and sensitive information.

The second statement explains:

Threat
+
Weakness
+
Event
+
Impact

Create:

Risk ID:
RISK-001
Risk Title:
Employee Credential Compromise Through Phishing

Risk statement:

There is a risk that threat actors may compromise employee credentials through phishing attacks, resulting in unauthorized access to corporate systems, sensitive information, and cloud resources.

Affected assets:

Corporate Email
Microsoft Entra ID
SaaS Applications

Threat:

External Threat Actor

Vulnerability:

Phishing-susceptible authentication
and employee susceptibility

Assume there are no controls.

Assign:

Likelihood = 5
Impact = 4

Calculate:

5 × 4 = 20

Therefore:

Inherent Risk = 20 — Critical

Record this in your register.

NorthStar currently uses:

  • MFA.

  • Email filtering.

  • Security awareness training.

  • Endpoint protection.

  • Conditional Access.

  • Security monitoring.

Record these under:

Existing Controls

Part 12 — Evaluate Control Effectiveness

Section titled “Part 12 — Evaluate Control Effectiveness”

Use:

Rating Description
Effective Control consistently reduces risk
Partially Effective Some weaknesses exist
Ineffective Control provides little meaningful reduction
Not Tested Effectiveness has not been validated

For this scenario assume:

Control Effectiveness:
Partially Effective

Why?

Because standard MFA remains susceptible to some advanced phishing techniques.

After considering controls:

Residual Likelihood = 3
Residual Impact = 4

Calculate:

3 × 4 = 12

Therefore:

Residual Risk = 12 — High

Your register now demonstrates:

Inherent Risk
20 — Critical
↓ Controls
Residual Risk
12 — High

Use four common strategies:

Mitigate
Avoid
Transfer
Accept

For RISK-001 choose:

Treatment:
Mitigate

Recommended action:

Implement phishing-resistant authentication for privileged and high-risk users and progressively expand deployment across the workforce.

Possible technology approaches include:

  • FIDO2 security keys.

  • Passkeys.

  • Certificate-based authentication.

Add:

Risk Owner:
Chief Information Security Officer
Target:
90 Days
Status:
Open

Part 16 — Risk Scenario 02: Cloud Misconfiguration

Section titled “Part 16 — Risk Scenario 02: Cloud Misconfiguration”

Create:

Risk ID:
RISK-002
Risk Title:
Exposure of Sensitive Data Through Cloud Misconfiguration

Risk statement:

There is a risk that cloud resources may be incorrectly configured, resulting in unauthorized public exposure of customer or business-sensitive information.

Threat:

External Threat Actor

Vulnerability:

Cloud configuration errors

Affected assets:

AWS Production Environment
Customer Database
Cloud Storage

Assign:

Likelihood = 4
Impact = 5

Therefore:

Inherent Risk = 20 — Critical

Assume NorthStar uses:

  • Infrastructure as Code.

  • Cloud configuration monitoring.

  • IAM policies.

  • Security groups.

  • Encryption.

  • Cloud logging.

Control effectiveness:

Partially Effective

Residual assessment:

Likelihood = 3
Impact = 5

Therefore:

Residual Risk = 15 — High

Treatment:

Mitigate

Recommended remediation:

Implement automated policy-as-code validation within CI/CD pipelines to prevent insecure cloud configurations before deployment.

Create:

RISK-003
Enterprise Ransomware Attack

Risk statement:

There is a risk that ransomware may compromise enterprise endpoints and infrastructure, causing system outages, data loss, business disruption, and financial impact.

Consider:

Threat:
Cybercriminal Group
Vulnerability:
Endpoint compromise or credential theft
Assets:
Endpoints
Servers
File Systems
Backups

Assign your own:

  • Likelihood.

  • Impact.

  • Controls.

  • Residual score.

  • Treatment.

Document your reasoning.

Part 19 — Risk Scenario 04: Privileged Account Compromise

Section titled “Part 19 — Risk Scenario 04: Privileged Account Compromise”

Create:

RISK-004
Privileged Account Compromise

Potential threats:

Credential Theft
Insider Threat
Session Hijacking

Possible weaknesses:

Excessive Privilege
Weak MFA
Standing Administrative Access
Poor Monitoring

Potential controls:

PAM
MFA
Conditional Access
Privileged Activity Monitoring
Access Reviews

Perform the complete assessment yourself.

Part 20 — Risk Scenario 05: Third-Party SaaS Breach

Section titled “Part 20 — Risk Scenario 05: Third-Party SaaS Breach”

Create:

RISK-005
Sensitive Data Exposure Through SaaS Vendor Breach

Potential impact:

  • Customer data exposure.

  • Regulatory impact.

  • Customer notification.

  • Contractual impact.

  • Reputation damage.

Possible controls:

  • Vendor security assessment.

  • SOC report review.

  • Contractual security requirements.

  • Encryption.

  • Data minimization.

  • Vendor monitoring.

Complete the scoring.

Part 21 — Risk Scenario 06: Unpatched Critical Vulnerability

Section titled “Part 21 — Risk Scenario 06: Unpatched Critical Vulnerability”

Create:

RISK-006
Exploitation of Critical Internet-Facing Vulnerability

Potential weakness:

Delayed patching

Potential threat:

External attacker

Possible controls:

Vulnerability Scanning
Patch Management
WAF
EDR
Threat Intelligence
Attack Surface Monitoring

Assess inherent and residual risk.

Part 22 — Risk Scenario 07: Cloud Service Outage

Section titled “Part 22 — Risk Scenario 07: Cloud Service Outage”

Create:

RISK-007
Business Disruption Due to Cloud Service Outage

Consider:

  • Cloud region dependency.

  • Single-region architecture.

  • Recovery capabilities.

  • Backups.

  • Availability requirements.

Possible treatments:

Mitigate
Transfer
Accept

Select and justify one.

Part 23 — Risk Scenario 08: Insider Data Theft

Section titled “Part 23 — Risk Scenario 08: Insider Data Theft”

Create:

RISK-008
Unauthorized Data Exfiltration by Insider

Consider:

Privileged Access
Data Access
DLP
Logging
User Behavior Monitoring
Access Reviews
Least Privilege

Perform the full assessment.

Now identify at least five additional enterprise risks.

Possible areas include:

Software Supply Chain
CI/CD Compromise
API Security
Backup Failure
Business Email Compromise
Secrets Exposure
Third-Party Dependency
Data Retention
Shadow SaaS
AI Data Leakage

Do not simply copy the names.

Write complete risk statements.

Your final register should contain at least:

13 Risks

Every risk needs an accountable owner.

Examples:

Risk Possible Owner
Cloud Misconfiguration Head of Cloud Engineering
Phishing CISO
Vendor Risk Procurement / Business Owner
Application Vulnerability Head of Engineering
Availability Risk CIO
Privacy Risk Privacy Officer

The risk owner should have sufficient authority to make treatment decisions.

Do not confuse these roles.

Risk Owner
Accountable for Risk
Control Owner
Accountable for Control

Example:

Risk:
Privileged Account Compromise
Risk Owner:
CISO
Controls:
PAM
MFA
Access Reviews
Monitoring
Control Owners:
IAM Team
SOC Team
IT Operations

One risk may depend on several controls.

Review every risk and assign:

Mitigate
Avoid
Transfer
Accept

Implement additional controls.

Stop the activity creating the risk.

Shift some financial or operational exposure through mechanisms such as insurance or contractual arrangements.

Management formally accepts the residual exposure.

Suppose:

Residual Risk:
Moderate
Remediation Cost:
₹50,00,000
Expected Business Exposure:
Low

Management may decide to accept the risk.

Document:

Risk Acceptance
Business Justification
Approver
Approval Date
Expiration Date
Review Date

Risk acceptance should be a governance decision.

Avoid vague actions such as:

Improve Security

Instead use measurable actions.

Example:

Deploy phishing-resistant MFA for all privileged identities and high-risk administrative roles.

Another:

Configure CI/CD policy checks preventing deployment of publicly accessible storage resources.

Good remediation should answer:

What?
Who?
When?
How will completion be proven?

Create another worksheet:

Risk Remediation Tracker

Use:

Action ID Risk ID Remediation Owner Target Status Evidence

Example:

Action ID Risk ID Remediation Owner Target Status Evidence
ACT-001 RISK-001 Deploy phishing-resistant MFA IAM 90 Days Open Deployment report

Use standardized statuses:

Open
Treatment Planned
In Progress
Risk Accepted
Monitoring
Closed

Avoid inconsistent statuses such as:

Working
Nearly Done
Looking Good
Pending Maybe

Standardization enables reporting.

Create a 5 × 5 risk matrix.

Use:

Likelihood
Impact

Conceptually:

Likelihood ↓ / Impact → 1 2 3 4 5
5 5 10 15 20 25
4 4 8 12 16 20
3 3 6 9 12 15
2 2 4 6 8 10
1 1 2 3 4 5

This visually represents risk severity.

Sort your register by:

Residual Risk Score

highest to lowest.

Your highest risks should receive management attention first.

Example:

RISK-002 15 High
RISK-001 12 High
RISK-004 12 High
RISK-003 10 High

Create a filter for:

Residual Rating = Critical

Ask:

  • Why is the risk still critical?

  • Are controls ineffective?

  • Is remediation underway?

  • Does leadership know?

  • Does immediate escalation make sense?

Critical residual risk should not quietly remain in a spreadsheet.

Add:

Target Date

and identify:

Target Date < Today
AND
Status ≠ Closed

These are overdue remediation actions.

GRC should monitor and escalate them.

Add:

Risk Created Date

and optionally calculate:

Risk Age =
Today - Risk Created Date

Long-running high risks may indicate remediation problems.

Define review frequency based on risk.

Example:

Residual Risk Review
Critical Monthly
High Quarterly
Moderate Semiannual
Low Annual

This creates risk-based monitoring.

Define escalation rules.

Example:

Critical Risk
CISO / Executive Risk Committee
High Risk Overdue
Security Leadership
Repeated Missed Remediation
Executive Escalation

Escalation rules strengthen governance.

Create a worksheet:

Risk Dashboard

Include:

Total Risks
Critical Risks
High Risks
Moderate Risks
Low Risks
Overdue Risks
Accepted Risks
Risks Under Treatment

Example:

Metric Result
Total Risks 13
Critical 2
High 5
Moderate 4
Low 2
Overdue 3

Categorize risks into domains such as:

Identity
Cloud
Endpoint
Application
Third Party
Data Protection
Resilience
Governance

Create:

Domain Risks
Cloud 4
Identity 3
Third Party 2
Application 2
Resilience 2

This helps identify concentrations.

Summarize:

Treatment Count
Mitigate 8
Accept 2
Transfer 2
Avoid 1

Leadership can see how risks are being managed.

Write a short executive summary.

Example:

The enterprise cybersecurity risk assessment identified 13 material risks across cloud security, identity, endpoint security, third-party services, application security, and operational resilience. Two risks currently remain at Critical residual severity and require immediate management attention. Five risks remain High and have active remediation plans. Priority actions include strengthening privileged identity protection, preventing insecure cloud configurations, improving ransomware resilience, and reducing critical third-party exposure.

Keep executive reporting focused on:

What is the risk?
Why does it matter?
What are we doing?
Who owns it?
When will exposure reduce?

Before completing the lab, review every risk.

Verify:

  • Risk statement is clear.

  • Asset or process is identified.

  • Threat is documented.

  • Vulnerability is documented.

  • Business impact is meaningful.

  • Inherent likelihood is assigned.

  • Inherent impact is assigned.

  • Inherent score is correct.

  • Existing controls are documented.

  • Control effectiveness is evaluated.

  • Residual likelihood is assigned.

  • Residual impact is assigned.

  • Residual score is correct.

  • Risk owner is identified.

  • Treatment is selected.

  • Remediation is measurable.

  • Target date exists.

  • Status is current.

Mistake 1 — Writing Issues Instead of Risks

Section titled “Mistake 1 — Writing Issues Instead of Risks”

Weak:

MFA Missing

Better:

There is a risk that attackers may compromise administrative accounts due to the absence of strong MFA, resulting in unauthorized privileged access.

Mistake 2 — Scoring Before Defining Criteria

Section titled “Mistake 2 — Scoring Before Defining Criteria”

Do not assign numbers without a documented methodology.

Mistake 3 — Treating Every Risk as Critical

Section titled “Mistake 3 — Treating Every Risk as Critical”

If everything is critical:

Nothing is prioritized.

Inherent and residual risk should not be identical automatically.

A risk without an owner often becomes a risk without action.

Avoid:

Improve cloud security.

Use:

Implement policy-as-code validation preventing public cloud storage deployments by Q4.

Mistake 7 — Confusing Risk Acceptance With Ignoring Risk

Section titled “Mistake 7 — Confusing Risk Acceptance With Ignoring Risk”

Accepted risks still require:

Documentation
Approval
Monitoring
Periodic Review

At the end of the lab, your workbook should contain at least:

01 — Asset Inventory
02 — Risk Methodology
03 — Enterprise Risk Register
04 — Risk Remediation Tracker
05 — Risk Matrix
06 — Risk Dashboard

Your Enterprise Risk Register should contain:

13+ Risk Scenarios
Inherent Risk Scores
Existing Controls
Control Effectiveness
Residual Risk Scores
Risk Owners
Treatment Decisions
Remediation Actions
Target Dates
Current Status

Before marking the lab complete:

  • Created asset inventory.

  • Identified critical assets.

  • Defined likelihood scale.

  • Defined impact scale.

  • Defined risk-rating thresholds.

  • Created 5 × 5 risk matrix.

  • Created enterprise risk register.

  • Documented at least 13 risks.

  • Used structured risk statements.

  • Calculated inherent risk.

  • Identified existing controls.

  • Evaluated control effectiveness.

  • Calculated residual risk.

  • Assigned risk owners.

  • Selected risk treatments.

  • Created remediation actions.

  • Defined target dates.

  • Created remediation tracker.

  • Identified overdue risks.

  • Created executive dashboard.

  • Prepared executive risk summary.

After completing this exercise, you should be comfortable performing the workflow:

Understand Business
Identify Assets
Identify Risk
Write Risk Scenario
Assess Inherent Risk
Identify Controls
Evaluate Controls
Assess Residual Risk
Select Treatment
Assign Owner
Plan Remediation
Monitor
Report

This workflow represents one of the foundational responsibilities of an enterprise GRC Analyst.

In a real organization, your risk register may contain hundreds or thousands of risks.

The register may also connect to:

Business Assets
Risks
Controls
Policies
Compliance Requirements
Findings
Remediation
Evidence

This is why the risk register is more than a spreadsheet.

It becomes part of the organization’s broader GRC system of record.

You have built the foundation of an Enterprise Cybersecurity Risk Register.

You have practiced how GRC teams move from:

Technical Problem
Risk Scenario
Business Impact
Risk Score
Controls
Residual Risk
Management Decision
Remediation

This is the transition from simply identifying security problems to managing cybersecurity as enterprise risk.

➡️ Lab 02 — Perform a Third-Party Security Risk Assessment

In the next lab, you will take the role of a Third-Party Risk / GRC Analyst and assess a fictional SaaS provider before the organization approves it for enterprise use.

You will perform the complete vendor assessment lifecycle:

Vendor Request
Business Intake
Inherent Risk Assessment
Vendor Tiering
Security Due Diligence
Evidence Review
SOC 2 Review
ISO Certification Review
Control Gap Analysis
Residual Risk
Vendor Findings
Remediation Requirements
Risk Recommendation

Your final deliverable will be a professional Third-Party Security Risk Assessment Report containing the vendor’s risk classification, security findings, residual risk, remediation requirements, and approval recommendation.