Information Security Risk Assessment
You can't defend everything equally — and you shouldn't try. We help you find what truly matters, understand how an attacker would reach it, and decide where every rupee of security effort is best spent.
Veteran researchers. CERT-In empaneled. Risk grounded in how systems actually get breached.
Risk is the decision that governs every other one
Performing a comprehensive risk assessment on your critical information assets is what lets you select the right mitigation controls — instead of buying tools and hoping.
Our methodology is a multi-fold activity: we assign value to the information assets that matter most, assess the threats against them, and analyse the gap between the protection they need and the protection they have today.
Most risk assessments drift into the abstract — a spreadsheet of generic threats scored on a feeling. We work the other way. Because we spend our days breaking into systems, we ground every rating in the paths an attacker would actually take: which asset is reachable, from where, with what effort, and what it would cost you if they got there. The result is not a compliance artefact that ages in a drawer. It is a clear, defensible picture of where your real exposure lives and what to do about it first.
"A risk rating is only as honest as the attack path behind it. We start from how the breach would actually happen."
What's worth protecting — and what an adversary is after
Risk begins with value. Before we rate a single threat, we identify and value the assets that, if compromised, would hurt you the most — across seven classes.
Information
The data itself: customer records, financial data, intellectual records and regulated information whose loss or exposure carries direct consequence.
Intangibles
Intellectual property, brand and reputation — the assets that take years to build and a single incident to damage.
People
Employees, contractors and temporary staff: both the holders of access and the most-targeted route into an organization.
Hardware
Servers, workstations, network devices and the physical estate that runs and reaches your data.
Software
Purchased and in-house applications, the code and platforms that process and govern your information.
Services
The actual services you deliver to end users, and the dependencies that keep them available.
Locations & Buildings
Sites, offices and facilities — because physical access is still one of the most reliable attack paths.
A disciplined, multi-phase methodology
We follow a structured lifecycle aligned with recognized standards — NIST SP 800-30 for conducting the assessment and ISO/IEC 27005 for managing the risk it surfaces — so the work is repeatable and defensible. The threat reasoning inside it stays adversarial: every likelihood is argued from a real attack path, not assumed. The engagement moves through six phases.
Reassess — risk management is continual (ISO/IEC 27005), not a one-time report.
How we rate a risk
Risk is a function of two things: how likely a threat event is to succeed, and how much it would cost you if it did. We assess each independently and combine them — so a low-likelihood, catastrophic-impact risk gets the attention it deserves, and a noisy-but-trivial one doesn't crowd it out.
Most engagements use a qualitative scale — a likelihood-by-impact matrix that ranks risks clearly and is fast to communicate to leadership. Where the stakes and the data justify it, we can apply a quantitative model in the style of FAIR, expressing exposure as a probable frequency and probable magnitude of loss — so risk can be discussed in the same financial terms as the rest of the business. We recommend the approach that fits your decision, never a heavier method than the question requires.
Then: what you actually do about it
An assessment that ends at a rating is half a job. For every significant risk, we frame the decision — and the four ways you can take it.
Apply or strengthen controls to reduce the likelihood or the impact. The most common path, and where our remediation guidance is most specific.
Knowingly retain a risk that sits within tolerance — documented and signed off, so the decision is deliberate rather than accidental.
Shift part of the exposure to a third party, such as insurance or a contractual arrangement, where that is the rational move.
Remove the exposure entirely by stepping away from the activity, asset or configuration that creates it.
What we can assess
A risk assessment is only as good as its scope. We assess across the full estate — the same seven asset classes we value in Phase 1 — and map each to the standards that govern it, so the output slots straight into your compliance and audit work.
Information assets
Classification, sensitivity, exposure and the confidentiality, integrity and availability requirements of the data itself.
Intangible assets
IP, brand and reputational exposure, and the incidents that would erode them.
People & access
Access concentrations, privileged accounts, third-party access and the human attack surface (the focus of our social-engineering work).
Hardware & infrastructure
Servers, endpoints, network devices and the physical and network exposure of each.
Software & applications
Purchased and in-house applications, their configuration, and the technical risk we surface through our VAPT and secure-code-review practices.
Services & continuity
Service availability, single points of failure and the business-continuity risk of disruption.
Locations & buildings
Sites, offices and facilities, and the physical-access paths that bypass digital controls entirely.
What a clear risk picture earns you
Done well, a risk assessment is leverage. It changes how you spend, how you report, and how you sleep.
What you receive
Every engagement ends in artefacts your team and your auditors can use directly — written for the engineers who will act and the leaders who must decide.
Risk register
Every identified risk with its assets, threats, vulnerabilities, likelihood, impact, rating and owner — the living record of your risk posture.
Risk treatment plan
A prioritized set of recommendations (mitigate / accept / transfer / avoid) with specific, actionable controls — not generic advice.
Executive narrative
Your risk posture and its business impact in plain language for leadership and the board.
Standards mapping
Risks and controls mapped to ISO/IEC 27001 Annex A, with the assessment grounded in NIST SP 800-30 and ISO/IEC 27005.
Residual-risk statement
A clear view of what remains after treatment, ready for formal sign-off.
Direct researcher access
A debrief with the people who did the work, not a handoff to a call centre.
Supports ISO 27001, SOC 2 and RBI/SEBI assessment requirements
Frequently asked questions
How is a risk assessment different from a penetration test?
A penetration test answers "can this specific system be broken into, and how?" A risk assessment answers "across everything we own, where is our exposure greatest and what should we do first?" The two are complementary — and because the same researchers run both, our risk ratings are informed by what we genuinely find exploitable, not by guesswork.
Qualitative or quantitative — which will you use?
Most decisions are served well by a qualitative likelihood-by-impact rating: fast, clear and easy to communicate. Where the stakes and the available data justify it, we can apply a quantitative model in the style of FAIR to express exposure in financial terms. We recommend the lightest approach that answers your question honestly.
Do we need this if we're already pursuing ISO 27001?
Yes — a risk assessment is a core requirement of ISO 27001, not an optional extra. Its output drives your Statement of Applicability and the Annex A controls you choose to implement. We produce it in a form your certification work can use directly.
How often should we reassess?
At minimum annually, and after any significant change — a new system or platform, a merger or acquisition, a major regulatory shift, or a material incident. Risk is not static, and a register that isn't maintained quietly stops being true.
What do we walk away with?
A maintained risk register, a prioritized treatment plan, an executive narrative for leadership, a residual-risk statement for sign-off, and a debrief with the researchers who did the work.
Know your real exposure — before someone else maps it for you.
Tell us what you're protecting and we'll scope an assessment that fits — or connect you directly with a researcher.