Risk Matrix — Information Security Risk Register (ISO 27005)
An ISO/IEC 27005 register for a fictional payroll SaaS covering nine threat scenarios, from ransomware in the build pipeline to supplier-payment fraud: controls cut exposure from 114 to 53 (−54%) and take all four Critical risks out of the top band, while the edge VPN, the build pipeline and the open-source supply chain stay High and above appetite, each with a treatment. Illustrative register.
Make it your own.
title "Ledgerly payroll SaaS — information security risk register"
subtitle "ISO/IEC 27005 assessment · scored against the ISMS risk acceptance criteria"
likelihood-levels: Rare (<1 in 10 yrs), Unlikely (1 in 3–10 yrs), Possible (1 in 1–3 yrs), Likely (about yearly), Almost certain (several a year)
impact-levels: Negligible (no customer effect), Minor (<4 h outage), Moderate (<1 day or <10k records), Major (regulator notified), Severe (mass breach)
bands: Low 1-3, Medium 4-6, High 8-12, Critical 15-25
appetite: Medium
note "Illustrative register for a fictional payroll SaaS; threats, controls and ratings are examples, not an assessment."
risk IS-01 "Ransomware spreads from a corporate laptop into the build pipeline"
category: Malware
owner: CISO
likelihood: 3
impact: 5
control "EDR with 24×7 managed detection and response"
control "Tiered admin accounts; no standing access to CI"
control "Immutable, offline backups restore-tested monthly"
residual: 2x4
action "Move CI runners to ephemeral, isolated cloud accounts" due: 2027-Q2 owner: "Platform Lead"
target: 1x4
risk IS-02 "Critical vulnerability in the edge VPN exploited before patching"
category: Vulnerability
owner: Head of Infrastructure
likelihood: 4
impact: 4
control "72-hour SLA for critical patches on internet-facing systems"
control "Continuous external attack-surface scanning"
residual: 2x4
action "Replace the VPN with identity-aware zero-trust access" due: 2027-06 owner: "Head of Infrastructure"
trend: falling
risk IS-03 "Malicious open-source dependency injected into a release"
category: Supply chain
owner: VP Engineering
likelihood: 3
impact: 4
control "Lockfile pinning with software composition analysis in CI"
control "Signed builds with SLSA level 2 provenance"
residual: 2x4
action "Adopt SLSA level 3 and an internal package mirror" due: 2027-09 owner: "VP Engineering"
risk IS-04 "Misconfigured cloud storage exposes payroll exports"
category: Cloud
owner: Head of Infrastructure
likelihood: 3
impact: 5
control "Cloud security posture management with auto-remediation"
control "Public access blocked by organisation-wide policy"
residual: 1x5
risk IS-05 "Insider exfiltrates customer payroll data"
category: Insider
owner: CISO
likelihood: 2
impact: 5
control "Just-in-time production access with session recording"
control "Data-loss prevention on egress and endpoints"
control "Quarterly access recertification"
residual: 1x5
risk IS-06 "Credential stuffing against customer logins"
category: Identity
owner: Product Security Lead
likelihood: 4
impact: 4
control "MFA enforced for all payroll administrators"
control "Bot detection, rate limiting and breached-password screening"
residual: 2x3
risk IS-07 "DDoS against the public API during the monthly payroll run"
category: Availability
owner: Head of SRE
likelihood: 3
impact: 4
control "CDN and WAF with always-on DDoS protection"
control "Payroll batch window protected by priority queueing"
residual: 2x3
risk IS-08 "Breach at the support-desk SaaS leaks tickets containing PII"
category: Third party
owner: Head of Customer Support
likelihood: 3
impact: 3
control "Annual vendor security assessment and SOC 2 report review"
control "Automatic PII redaction in support tickets"
residual: 2x2
risk IS-09 "Business email compromise diverts a supplier payment"
category: Fraud
owner: Finance Director
likelihood: 3
impact: 3
control "Call-back verification for every change of bank details"
control "DMARC at p=reject on all sending domains"
residual: 1x3