Skip to main content

Contact

This page explains what you can reasonably ask about, and what you should never send.

What questions are in scope

IT Risk Guide is a publication. It can discuss the method used in its guides and its risk matrix tool, correct errors in the material, and take suggestions for topics. If you are working on a risk register, a scoring scale or a board report and a passage in one of the guides is unclear, wrong or missing something, that is a good reason to get in touch.

What this site cannot do

It does not provide audits, assessments, certification, legal advice, insurance advice or incident response, and it cannot review your systems. The risk matrix tool works entirely in your browser, so nothing you enter there reaches the site operator. If you are dealing with a live security incident, contact your own incident response provider, your internal security team, or the relevant authority in your country, not a publication.

What not to send

Do not send passwords, multi-factor codes, API keys, tokens, private keys, recovery codes or session cookies, even if you think a message is private. Do not send personal data about customers or staff, or detailed information about the weaknesses of a specific live system. A short description of the question, in general terms, is enough to start a conversation, and nothing here requires you to share more.

How to make contact

The direct contact channel is shown below this text when it is open. If it is not, this page will say so. Until a channel is published, please use the guides and the tool on their own: they are designed to be used without contacting anyone.

The direct contact channel is not open yet. There is no contact form and no mailbox to write to at the moment, and this page will not pretend otherwise. When a contact address is published it will appear here.