+1 (780) 800-8357 info@atgic.ca 7445 Roper Rd NW, Edmonton, AB T6B 3K9, Canada
Courses Referral Program FAQ Let's Talk+1 (780) 800-8357
$ CAD
  • $ CAD
  • $ USD
  • € EUR
  • £ GBP
  • ₹ INR
  • $ AUD
  • $ SGD
  • CHF CHF
  • RM MYR
  • ¥ JPY
  • د.إ AED
  • ؋ AFN
  • L ALL
  • AMD AMD
  • ƒ ANG
  • Kz AOA
  • ZK ZMW
  • ৳  BDT
  • $ ARS
  • Afl. AWG
  • ₼ AZN
  • KM BAM
  • $ BBD
  • лв. BGN
  • .د.ب BHD
  • Fr BIF
  • $ BMD
  • $ BND
  • Bs. BOB
  • R$ BRL
  • $ BSD
  • Nu. BTN
  • P BWP
  • Br BYN
  • Br BYR
  • $ BZD
  • Fr CDF
  • $ CLP
  • ¥ CNY
  • $ COP
  • ₡ CRC
  • $ CUP
  • $ CUC
  • $ CVE
  • Kč CZK
  • Fr DJF
  • kr. DKK
  • RD$ DOP
  • د.ج DZD
  • EGP EGP
  • Nfk ERN
  • Br ETB
  • $ FJD
  • R ZAR
  • ﷼ YER
  • T WST
  • Vt VUV
  • ₫ VND
  • Bs F VEF
  • Bs. VES
  • UZS UZS
  • £ FKP
  • ₾ GEL
  • £ GGP
  • ₵ GHS
  • £ GIP
  • D GMD
  • Fr GNF
  • Q GTQ
  • $ GYD
  • $ HKD
  • L HNL
  • kn HRK
  • G HTG
  • Ft HUF
  • Rp IDR
  • ₪ ILS
  • £ IMP
  • د.ع IQD
  • ﷼ IRR
  • kr. ISK
  • £ JEP
  • $ JMD
  • د.ا JOD
  • KSh KES
  • сом KGS
  • ៛ KHR
  • Fr KMF
  • ₩ KPW
  • ₩ KRW
  • د.ك KWD
  • $ KYD
  • ₸ KZT
  • ₭ LAK
  • ل.ل LBP
  • රු LKR
  • $ LRD
  • L LSL
  • $ UYU
  • د.ل LYD
  • د.م. MAD
  • MDL MDL
  • Ar MGA
  • ден MKD
  • Ks MMK
  • ₮ MNT
  • UM MRU
  • P MOP
  • UGX UGX
  • ₴ UAH
  • Sh TZS
  • ₨ MUR
  • .ރ MVR
  • MK MWK
  • $ MXN
  • MT MZN
  • N$ NAD
  • ₦ NGN
  • C$ NIO
  • kr NOK
  • CFA XOF
  • XPF XPF
  • $ XCD
  • CFA XAF
  • ₨ NPR
  • $ NZD
  • ر.ع. OMR
  • B/. PAB
  • S/ PEN
  • K PGK
  • ₱ PHP
  • ₨ PKR
  • zł PLN
  • ₲ PYG
  • ر.ق QAR
  • lei RON
  • рсд RSD
  • ₽ RUB
  • Fr RWF
  • ر.س SAR
  • $ SBD
  • ₨ SCR
  • ج.س. SDG
  • kr SEK
  • £ SHP
  • Le SLL
  • Sh SOS
  • $ SRD
  • £ SSP
  • Db STN
  • NT$ TWD
  • ل.س SYP
  • $ TTD
  • ₺ TRY
  • T$ TOP
  • E SZL
  • ฿ THB
  • m TMT
  • د.ت TND
  • ЅМ TJS

Threat & Risk Assessment

Find out where you actually stand. We identify the threats that matter to your business, test the controls meant to stop them, and hand you a prioritized risk register with treatment options — not a PDF that sits in a drawer.

ISO/IEC 27005 · NIST SP 800-30 methodology Financial & public sector experience Fixed scope, fixed price
The question it answers

Not "are we secure?" but "what would actually hurt us?"

A threat and risk assessment starts from what your organization would lose — revenue, data, licence to operate, client trust — and works backwards to the scenarios that could cause it. Only then do we look at controls, because a control matters exactly as much as the loss it prevents.

The output is a ranked list of risks in business terms, each with a likelihood, an impact, an owner, and a set of treatment options priced by effort. Leadership can then make the call that's theirs to make: fix it, transfer it, or accept it on the record.

  • Threat modelling against your realityRansomware, insider misuse, supply chain, business email compromise — weighted to your sector
  • Controls tested, not assumedWe verify that the control exists, is configured correctly, and is actually operating
  • Risk stated in business language"Four days of order processing lost" reads better to a board than a CVSS score
  • Findings that feed certificationMapped to ISO/IEC 27001 and NIST so remediation counts twice
Methodology

A method that stands up to scrutiny

We follow established risk methodology rather than an in-house scoring invention, so your results are comparable, repeatable and defensible to auditors, insurers and regulators alike:

  • ISO/IEC 27005 — information security risk management process
  • NIST SP 800-30 — threat source, event and vulnerability analysis
  • ISO 31000 — where enterprise risk integration is required
  • EBIOS Risk Manager — for scenario-driven, attacker-path analysis

Scope is agreed in writing before work starts. A typical assessment covers:

  • Critical business processes and the systems they depend on
  • Information assets — where sensitive data lives, moves and is retained
  • Infrastructure — network, endpoint, cloud tenancy and remote access
  • Identity and access — privileged accounts, joiner/mover/leaver, MFA coverage
  • Third parties with access to your data or environment
  • Detection and response capability, including tested recovery

You receive documents built to be used, by the people who have to use them:

  • Executive summary — the risk picture in two pages, no jargon
  • Risk register — scored, owned, with treatment options and residual risk
  • Technical findings — evidence, reproduction detail and specific remediation
  • Remediation roadmap — sequenced by risk reduction per unit of effort
  • Walkthrough session — with your technical team and separately with leadership
"Every risk we raise comes with the evidence behind it and the decision it needs from you. Nothing is flagged just to fill a page." — A & T Global assessment team

Threat identification

Realistic threat sources and scenarios for your sector, size and exposure

Vulnerability analysis

Where those scenarios would find a way through your current controls

Impact & likelihood

Scored consistently so risks can be ranked against each other honestly

Treatment options

Mitigate, transfer, avoid or accept — each priced by effort and residual risk

How we work

From first call to measurable risk reduction

  1. 01 Discovery call We learn your environment, obligations, and what's driving the work — a client requirement, an audit, or an incident.
  2. 02 Scope & proposal A written scope with deliverables, timeline and fixed price. No open-ended hourly engagements.
  3. 03 Assessment Document review, interviews and technical verification against the relevant standard or framework.
  4. 04 Report & roadmap Prioritized findings, remediation plan, and a walkthrough session with your team and leadership.
Common questions

Threat & risk assessment FAQ

No. A penetration test proves a specific technical weakness is exploitable. A threat and risk assessment is broader and business-led — it covers process, people, third parties and governance as well as technology, and it prices consequences rather than just demonstrating access. They complement each other; a TRA will often tell you where a pen test is worth commissioning.

Three to six weeks for most mid-sized organizations. The load on your team is roughly one hour each from six to twelve people, plus document access. We work around production systems and agree any technical verification in advance — nothing is touched without written authorization.

Usually, yes — send us their requirement wording before we scope and we'll confirm. Because we assess against recognized methodology and map findings to ISO/IEC 27001 and NIST, the output speaks the language most client security teams and procurement functions expect to see.

That's your call. Some clients take the roadmap and run it internally, some ask us to stay on as advisors through remediation, and some fold it into a broader GRC program. We don't make the report contingent on further work — a re-assessment twelve months later is the only follow-up we'd normally recommend.

Know your exposure before someone else finds it

Tell us what triggered the requirement and we'll scope an assessment with a fixed price and a firm date. We respond within one business day.