Threat & Risk Assessment
Find out where you actually stand. We identify the threats that matter to your business, test the controls meant to stop them, and hand you a prioritized risk register with treatment options — not a PDF that sits in a drawer.
Not "are we secure?" but "what would actually hurt us?"
A threat and risk assessment starts from what your organization would lose — revenue, data, licence to operate, client trust — and works backwards to the scenarios that could cause it. Only then do we look at controls, because a control matters exactly as much as the loss it prevents.
The output is a ranked list of risks in business terms, each with a likelihood, an impact, an owner, and a set of treatment options priced by effort. Leadership can then make the call that's theirs to make: fix it, transfer it, or accept it on the record.
-
Threat modelling against your realityRansomware, insider misuse, supply chain, business email compromise — weighted to your sector
-
Controls tested, not assumedWe verify that the control exists, is configured correctly, and is actually operating
-
Risk stated in business language"Four days of order processing lost" reads better to a board than a CVSS score
-
Findings that feed certificationMapped to ISO/IEC 27001 and NIST so remediation counts twice
A method that stands up to scrutiny
We follow established risk methodology rather than an in-house scoring invention, so your results are comparable, repeatable and defensible to auditors, insurers and regulators alike:
- ISO/IEC 27005 — information security risk management process
- NIST SP 800-30 — threat source, event and vulnerability analysis
- ISO 31000 — where enterprise risk integration is required
- EBIOS Risk Manager — for scenario-driven, attacker-path analysis
Scope is agreed in writing before work starts. A typical assessment covers:
- Critical business processes and the systems they depend on
- Information assets — where sensitive data lives, moves and is retained
- Infrastructure — network, endpoint, cloud tenancy and remote access
- Identity and access — privileged accounts, joiner/mover/leaver, MFA coverage
- Third parties with access to your data or environment
- Detection and response capability, including tested recovery
You receive documents built to be used, by the people who have to use them:
- Executive summary — the risk picture in two pages, no jargon
- Risk register — scored, owned, with treatment options and residual risk
- Technical findings — evidence, reproduction detail and specific remediation
- Remediation roadmap — sequenced by risk reduction per unit of effort
- Walkthrough session — with your technical team and separately with leadership
"Every risk we raise comes with the evidence behind it and the decision it needs from you. Nothing is flagged just to fill a page." — A & T Global assessment team
Threat identification
Realistic threat sources and scenarios for your sector, size and exposure
Vulnerability analysis
Where those scenarios would find a way through your current controls
Impact & likelihood
Scored consistently so risks can be ranked against each other honestly
Treatment options
Mitigate, transfer, avoid or accept — each priced by effort and residual risk
From first call to measurable risk reduction
- 01 Discovery call We learn your environment, obligations, and what's driving the work — a client requirement, an audit, or an incident.
- 02 Scope & proposal A written scope with deliverables, timeline and fixed price. No open-ended hourly engagements.
- 03 Assessment Document review, interviews and technical verification against the relevant standard or framework.
- 04 Report & roadmap Prioritized findings, remediation plan, and a walkthrough session with your team and leadership.
Threat & risk assessment FAQ
No. A penetration test proves a specific technical weakness is exploitable. A threat and risk assessment is broader and business-led — it covers process, people, third parties and governance as well as technology, and it prices consequences rather than just demonstrating access. They complement each other; a TRA will often tell you where a pen test is worth commissioning.
Three to six weeks for most mid-sized organizations. The load on your team is roughly one hour each from six to twelve people, plus document access. We work around production systems and agree any technical verification in advance — nothing is touched without written authorization.
Usually, yes — send us their requirement wording before we scope and we'll confirm. Because we assess against recognized methodology and map findings to ISO/IEC 27001 and NIST, the output speaks the language most client security teams and procurement functions expect to see.
That's your call. Some clients take the roadmap and run it internally, some ask us to stay on as advisors through remediation, and some fold it into a broader GRC program. We don't make the report contingent on further work — a re-assessment twelve months later is the only follow-up we'd normally recommend.
Know your exposure before someone else finds it
Tell us what triggered the requirement and we'll scope an assessment with a fixed price and a firm date. We respond within one business day.