Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Risk

Cyber risk register

A cyber risk register is the structured inventory of the cybersecurity risks an organization has identified, each described by a scenario, an owner, an inherent and a residual score on a shared scale, the controls that reduce it, its treatment decision and the actions that follow. It is the single place where risks can be compared with each other and with the risk appetite, and the source the board’s reporting draws from.

What a usable entry contains

A scenario written as “a threat exploits a vulnerability on an asset, causing an impact” rather than a category name; the business activities affected; the likelihood and impact on the organization’s method, giving an inherent score; the controls that apply and their verified status, giving a residual score; the target score once the treatment plan lands; the owner; the treatment decision (reduce, transfer, avoid, accept); and the dated actions. Anything less is a list of worries, not a register.

Why registers die, and how they survive

Registers built in spreadsheets die of three causes: scores that are opinions with no link to controls, an annual review nobody has time for, and a group structure that produces one register per entity with incompatible scales. A living register links each risk to the controls and evidence that justify its residual score, re-evaluates when a control fails or a supplier degrades, and imposes one method across entities so that a group-level picture can be consolidated rather than reconciled.

The register the regulator reads

NIS2 requires policies on risk analysis and a management body that approves the measures they lead to; DORA requires financial entities to identify, classify and document ICT-supported functions and the risks to them, and to review the risk framework at least yearly. A register with owners, dated decisions and evidence-backed scores is the artifact both supervisors expect to see, and the one a board can defend line by line.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.