Skip to main content

About IT Risk Guide

IT Risk Guide is an independent reference publication about IT risk assessment, security governance and audit readiness. It is written for people who have to make IT risk decisions and then explain them to a board, an auditor or an insurer: CIOs, CTOs, security managers and owner-operators.

What is published here

The site has two kinds of material. The first is a set of long-form guides on the practical parts of IT risk work: keeping a risk register, scoring risk and its limits, managing supplier risk, reviewing who has access, deciding what to do about a risk, preparing for an audit and reporting to a board. The second is a risk matrix tool, a worksheet that scores and ranks risks you enter and produces a summary for your own register.

How the material is written

Each guide explains one task from the point of view of the person doing it, with worked examples and a section on how the task commonly goes wrong. The scoring method is stated in full, including its weaknesses, so that you can disagree with it precisely. Where a figure or a fact depends on a vendor, a jurisdiction or a version, the guides say how to check it instead of asserting it.

Examples in the guides are illustrative. They are not case studies, they do not describe real organisations, and the numbers in them are chosen to show a method, not to report a measurement.

What this site is not

  • It is not an auditor, assessor, certification body, insurer or consultancy, and it does not audit, test, scan or certify anyone’s systems.
  • A score from the risk matrix tool is not a certification, a formal audit, an attestation or evidence of compliance. It is a working estimate built from the likelihood and impact values you enter.
  • It has no affiliation with, and no accreditation from, any standards body or framework owner. Frameworks and standards are referred to by name where it helps you find the originals; their text is not republished here, and you should obtain them from their owners.
  • It does not publish testimonials, ratings or claims about other organisations’ performance.

Corrections and contact

If you find an error, the most useful thing you can send is the passage, what you believe is wrong, and a source you would trust to settle it. Contact details, when a channel is available, are on the contact page. The resources index lists everything published, with a note on who each piece is for.