# Cyber Risk Assessment Tool — Implementation Workbook

Version: 1.0
Published: 2026-07-27
Last updated: 2026-07-27
Owner: Rusaka Research
Review frequency: Every 6 months

## Decision statement

What decision must this workbook support?

________________________________________________________________________________

## Scope and exclusions

In scope:

________________________________________________________________________________

Out of scope:

________________________________________________________________________________

## Baseline evidence register

| Evidence item | Source | Date | Owner | Verified by | Status |
|---|---|---|---|---|---|
| | | | | | |
| | | | | | |
| | | | | | |

## Assumption register

| Assumption | Rationale | Decision affected | Downside case | Test | Owner | Review date |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |

## Options and decision criteria

| Option | Outcome | Feasibility | Cost | Time | Risk | Reversibility | Recommendation |
|---|---:|---:|---:|---:|---:|---:|---|
| | | | | | | | |
| | | | | | | | |

## Implementation plan

| Phase | Entry evidence | Actions | Owner | Control | Exit evidence | Due date |
|---|---|---|---|---|---|---|
| 1. Discovery — Cyber Risk Assessment Tool | | During discovery, use Cyber Risk Assessment Tool to turn an ambiguous question into a scored and prioritised action plan. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed assessment, evidence notes, and prioritised actions. | |
| 2. Design — Cyber Risk Assessment Tool | | During design, use Cyber Risk Assessment Tool to turn an ambiguous question into a scored and prioritised action plan. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed assessment, evidence notes, and prioritised actions. | |
| 3. Pilot — Cyber Risk Assessment Tool | | During pilot, use Cyber Risk Assessment Tool to turn an ambiguous question into a scored and prioritised action plan. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed assessment, evidence notes, and prioritised actions. | |
| 4. Scale — Cyber Risk Assessment Tool | | During scale, use Cyber Risk Assessment Tool to turn an ambiguous question into a scored and prioritised action plan. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed assessment, evidence notes, and prioritised actions. | |
| 5. Operations — Cyber Risk Assessment Tool | | During operations, use Cyber Risk Assessment Tool to turn an ambiguous question into a scored and prioritised action plan. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed assessment, evidence notes, and prioritised actions. | |

## Measures and thresholds

| Measure | Definition | Source | Baseline | Target | Threshold | Owner | Frequency |
|---|---|---|---:|---:|---:|---|---|
| | | | | | | | |
| | | | | | | | |

## Risk and control register

| Risk | Cause | Impact | Preventive control | Detective control | Owner | Residual risk |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |

## Review checklist

- [ ] 1. Decision boundary: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 2. Stakeholder map: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 3. Current-state baseline: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 4. Evidence design: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 5. Operating model: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 6. Architecture and integration: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 7. Risk and compliance: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 8. Economics and value: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 9. Delivery sequencing: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 10. Vendor and partner assessment: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 11. Measurement system: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 12. Quality assurance: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 13. Change management: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 14. Documentation: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.

## Approval record

| Role | Name | Decision | Conditions | Date |
|---|---|---|---|---|
| Accountable owner | | | | |
| Subject-matter reviewer | | | | |
| Risk or control reviewer | | | | |

## Authoritative references

- https://www.nist.gov/cyberframework — Authoritative reference 1 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.
- https://owasp.org/www-project-top-ten/ — Authoritative reference 2 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.
- https://www.cisa.gov/resources-tools — Authoritative reference 3 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.

## Related Rusaka resources

- https://www.rusaka.com/resources/tools
- https://www.rusaka.com/resources/playbooks/incident-response-playbook
- https://www.rusaka.com/resources/glossary/security-controls-library
- https://www.rusaka.com/resources/tools/ai-readiness-assessment
- https://www.rusaka.com/resources/tools/product-manager-skills-assessment
- https://www.rusaka.com/resources/guides/cybersecurity-strategy-guide

## Important limitation

This educational workbook does not replace legal, investment, tax, accounting,
security, clinical, regulatory, or other qualified professional advice. Confirm
current requirements and obtain formal organisational approval where applicable.
