Skip to content
Risk matrix templates

Risk Matrix — Information Security Risk Register (ISO 27005)

An ISO/IEC 27005 register for a fictional payroll SaaS covering nine threat scenarios, from ransomware in the build pipeline to supplier-payment fraud: controls cut exposure from 114 to 53 (−54%) and take all four Critical risks out of the top band, while the edge VPN, the build pipeline and the open-source supply chain stay High and above appetite, each with a treatment. Illustrative register.

Template previewRisk matrix
Ledgerly payroll SaaS — information security risk registerISO/IEC 27005 assessment · scored against the ISMS risk acceptance criteriaHEAT MAP · residual position, arrows from inherent11LOWLOW22LOWLOW33LOWLOW44MEDIUMMEDIUM55MEDIUMMEDIUM22LOWLOW44MEDIUMMEDIUM66MEDIUMMEDIUM88HIGHHIGH1010HIGHHIGH33LOWLOW66MEDIUMMEDIUM99HIGHHIGH1212HIGHHIGH1515CRITICALCRITICAL44MEDIUMMEDIUM88HIGHHIGH1212HIGHHIGH1616CRITICALCRITICAL2020CRITICALCRITICAL55MEDIUMMEDIUM1010HIGHHIGH1515CRITICALCRITICAL2020CRITICALCRITICAL2525CRITICALCRITICALIS-09IS-04IS-05IS-08IS-06IS-07IS-02IS-01IS-03IS-05IS-08IS-09IS-03IS-07IS-01IS-04IS-02IS-06Rare<1 in 10 yrs1Unlikely1 in 3–10 yrs2Possible1 in 1–3 yrs3Likelyabout yearly4Almost certainseveral a year51Negligibleno customer effect2Minor<4 h outage3Moderate<1 day or <10k records4Majorregulator notified5Severemass breachLIKELIHOOD →IMPACT →R1residual position (after controls)R1inherent positioneffect of existing controlsappetite boundary · red ring = above it25L×I score and rating bandRISK PROFILE BY BANDInherentResidual (current)Critical4 → 0High5 → 3Medium0 → 5Low0 → 1Low 1–3 · Medium 4–6 · High 8–12 · Critical 15–25EXPOSURE Σ L×I53residual, after current controlsfrom 114 inherent · −54%HIGHEST RESIDUAL RISKIS-02Critical vulnerability in the edge VPNexploited before patching8 · Highowner Head of InfrastructureRISK APPETITEMedium or below3 risks above: IS-02, IS-01, IS-03Risk register9 risks · sorted by residual rating, then score#IDRISK, CONTROLS AND ACTIONSOWNERINHERENTRESIDUALTARGETCHANGEVULNERABILITYCritical vulnerability in the edge VPN exploited beforepatching72-hour SLA for critical patches on internet-facing systemsContinuous external attack-surface scanning→Replace the VPN with identity-aware zero-trust access — due 2027-06 ·Head of Infrastructure1IS-02Head ofInfrastructure4 × 416 · Critical2 × 48 · HighABOVE APPETITE—−8−50%↓ fallingMALWARERansomware spreads from a corporate laptop into the buildpipelineEDR with 24×7 managed detection and responseTiered admin accounts; no standing access to CIImmutable, offline backups restore-tested monthly→Move CI runners to ephemeral, isolated cloud accounts — due 2027-Q2 ·Platform Lead2IS-01CISO3 × 515 · Critical2 × 48 · HighABOVE APPETITE1 × 44 · Medium−7−47%SUPPLY CHAINMalicious open-source dependency injected into a releaseLockfile pinning with software composition analysis in CISigned builds with SLSA level 2 provenance→Adopt SLSA level 3 and an internal package mirror — due 2027-09 · VPEngineering3IS-03VP Engineering3 × 412 · High2 × 48 · HighABOVE APPETITE—−4−33%IDENTITYCredential stuffing against customer loginsMFA enforced for all payroll administratorsBot detection, rate limiting and breached-password screening4IS-06Product SecurityLead4 × 416 · Critical2 × 36 · Medium—−10−63%AVAILABILITYDDoS against the public API during the monthly payroll runCDN and WAF with always-on DDoS protectionPayroll batch window protected by priority queueing5IS-07Head of SRE3 × 412 · High2 × 36 · Medium—−6−50%CLOUDMisconfigured cloud storage exposes payroll exportsCloud security posture management with auto-remediationPublic access blocked by organisation-wide policy6IS-04Head ofInfrastructure3 × 515 · Critical1 × 55 · Medium—−10−67%INSIDERInsider exfiltrates customer payroll dataJust-in-time production access with session recordingData-loss prevention on egress and endpointsQuarterly access recertification7IS-05CISO2 × 510 · High1 × 55 · Medium—−5−50%THIRD PARTYBreach at the support-desk SaaS leaks tickets containing PIIAnnual vendor security assessment and SOC 2 report reviewAutomatic PII redaction in support tickets8IS-08Head of CustomerSupport3 × 39 · High2 × 24 · Medium—−5−56%FRAUDBusiness email compromise diverts a supplier paymentCall-back verification for every change of bank detailsDMARC at p=reject on all sending domains9IS-09Finance Director3 × 39 · High1 × 33 · Low—−6−67%FINDINGS9 risks rated — inherent 4 Critical, 5 High; after current controls 3 High, 5 Medium, 1 Low.Total exposure Σ(L×I) falls from 114 to 53 after current controls — a 54% reduction.Controls move 8 of 9 assessed risks into a lower band; 1 keeps its inherent band.3 of 9 risks sit above the Medium appetite on residual rating — IS-02 (High 8), IS-01 (High 8), IS-03 (High 8); each has a treatment action.Highest residual risk: IS-02 Critical vulnerability in the edge VPN exploited before patching — High 8, owner Head of Infrastructure.Controls do most for IS-06: 16 → 6 (−63%).Illustrative register for a fictional payroll SaaS; threats, controls and ratings are examples, not an assessment.

Make it your own.

title "Ledgerly payroll SaaS — information security risk register"
subtitle "ISO/IEC 27005 assessment · scored against the ISMS risk acceptance criteria"
likelihood-levels: Rare (<1 in 10 yrs), Unlikely (1 in 3–10 yrs), Possible (1 in 1–3 yrs), Likely (about yearly), Almost certain (several a year)
impact-levels: Negligible (no customer effect), Minor (<4 h outage), Moderate (<1 day or <10k records), Major (regulator notified), Severe (mass breach)
bands: Low 1-3, Medium 4-6, High 8-12, Critical 15-25
appetite: Medium
note "Illustrative register for a fictional payroll SaaS; threats, controls and ratings are examples, not an assessment."

risk IS-01 "Ransomware spreads from a corporate laptop into the build pipeline"
  category: Malware
  owner: CISO
  likelihood: 3
  impact: 5
  control "EDR with 24×7 managed detection and response"
  control "Tiered admin accounts; no standing access to CI"
  control "Immutable, offline backups restore-tested monthly"
  residual: 2x4
  action "Move CI runners to ephemeral, isolated cloud accounts" due: 2027-Q2 owner: "Platform Lead"
  target: 1x4

risk IS-02 "Critical vulnerability in the edge VPN exploited before patching"
  category: Vulnerability
  owner: Head of Infrastructure
  likelihood: 4
  impact: 4
  control "72-hour SLA for critical patches on internet-facing systems"
  control "Continuous external attack-surface scanning"
  residual: 2x4
  action "Replace the VPN with identity-aware zero-trust access" due: 2027-06 owner: "Head of Infrastructure"
  trend: falling

risk IS-03 "Malicious open-source dependency injected into a release"
  category: Supply chain
  owner: VP Engineering
  likelihood: 3
  impact: 4
  control "Lockfile pinning with software composition analysis in CI"
  control "Signed builds with SLSA level 2 provenance"
  residual: 2x4
  action "Adopt SLSA level 3 and an internal package mirror" due: 2027-09 owner: "VP Engineering"

risk IS-04 "Misconfigured cloud storage exposes payroll exports"
  category: Cloud
  owner: Head of Infrastructure
  likelihood: 3
  impact: 5
  control "Cloud security posture management with auto-remediation"
  control "Public access blocked by organisation-wide policy"
  residual: 1x5

risk IS-05 "Insider exfiltrates customer payroll data"
  category: Insider
  owner: CISO
  likelihood: 2
  impact: 5
  control "Just-in-time production access with session recording"
  control "Data-loss prevention on egress and endpoints"
  control "Quarterly access recertification"
  residual: 1x5

risk IS-06 "Credential stuffing against customer logins"
  category: Identity
  owner: Product Security Lead
  likelihood: 4
  impact: 4
  control "MFA enforced for all payroll administrators"
  control "Bot detection, rate limiting and breached-password screening"
  residual: 2x3

risk IS-07 "DDoS against the public API during the monthly payroll run"
  category: Availability
  owner: Head of SRE
  likelihood: 3
  impact: 4
  control "CDN and WAF with always-on DDoS protection"
  control "Payroll batch window protected by priority queueing"
  residual: 2x3

risk IS-08 "Breach at the support-desk SaaS leaks tickets containing PII"
  category: Third party
  owner: Head of Customer Support
  likelihood: 3
  impact: 3
  control "Annual vendor security assessment and SOC 2 report review"
  control "Automatic PII redaction in support tickets"
  residual: 2x2

risk IS-09 "Business email compromise diverts a supplier payment"
  category: Fraud
  owner: Finance Director
  likelihood: 3
  impact: 3
  control "Call-back verification for every change of bank details"
  control "DMARC at p=reject on all sending domains"
  residual: 1x3