Know exactly where your cyber risk actually sits.
A structured cybersecurity risk assessment identifies, scores and prioritises risk across governance, controls, third-party exposure and incident readiness — evidence, not guesswork, for deciding what to fix first.
A risk assessment is not:
- A statutory audit or certification
- A generic checklist imported from elsewhere
- A one-time report with no follow-through
A risk assessment is:
- A scored, prioritised view of real business risk
- Built on the same 8-stage RETIS methodology every time
- A natural first step toward CyberGuard™ ongoing advisory
A full picture, not a single system
The same eight stages, every engagement
Questions about the risk assessment
A structured review that identifies, scores and prioritises the cyber risks facing an organisation — across governance, technical controls, third-party exposure and incident readiness — so leadership can make informed decisions about where to act first.
A risk assessment is advisory in nature — it identifies and prioritises risk. A statutory audit is a formal, regulated process with legal standing. RETIS delivers risk assessments, not statutory audits, unless the relevant licensing is explicitly in place.
Typically two to four weeks depending on organisational size and scope, agreed upfront during scoping.
At minimum annually, and additionally after major changes such as a new core system, a significant incident, or entry into a new regulatory environment.
For banks, SACCOs, fintechs and PSPs, FINSEC 360™ is the purpose-built version of this assessment — this general risk assessment suits other sectors or organisations not yet ready for that depth.
Talk to RETIS about assessing your risk
Tell us about your organisation and we'll follow up — no obligation.
