What it actually covers
A proper risk assessment looks past a single system or checklist item and builds a picture of risk across the organisation as a whole. At RETIS, that typically spans governance and accountability, identity and access controls, application and data security, third-party and vendor exposure, and how prepared the organisation is to detect and respond to an incident.
The output isn't a raw list of technical findings — it's a scored, prioritised view that connects each finding to actual business impact, so a non-technical board member and a technical IT lead can both understand what matters most.
Why it matters
Most organisations don't actually lack security tools — they lack a clear, prioritised understanding of where their real exposure sits. Without that, security spending tends to chase whatever incident made headlines most recently, rather than the risks most likely to actually hit the business. A risk assessment replaces that guesswork with evidence leadership can act on.
How RETIS approaches it
Every RETIS risk assessment follows the same structured methodology: Discover, Assess, Score, Prioritise, Remediate, Test, Validate, Monitor. This isn't a marketing framework — it's the literal sequence of the engagement, from the first discovery conversation through to how findings get tracked over time.
The Kenyan context
Kenyan organisations — particularly in financial services — face a specific mix of risk: rapid digital adoption, a dense fintech and payments ecosystem, and often lean internal security teams relative to the systems they're responsible for. A risk assessment built for this context looks different from one imported wholesale from a global template — it weighs third-party and transaction risk more heavily, for instance, given how interconnected Kenyan financial infrastructure has become.
Common mistakes organisations make
A handful of patterns show up repeatedly in early conversations, before an assessment has even started:
- Treating a past penetration test as if it covered governance and third-party risk too — it doesn't, and wasn't scoped to
- Assuming risk ownership sits with IT by default, with no board-level sign-off on record
- Running an assessment once and treating the resulting report as a permanent, static picture
- Scoping the assessment around systems the organisation controls directly, while vendor and partner access goes unexamined
A practical checklist
- Do you have a documented owner for cybersecurity risk at leadership level?
- Has a formal risk or gap assessment been conducted in the last 12 months?
- Is multi-factor authentication enforced on critical systems?
- Is there a documented, tested incident response plan?
- Do you have visibility into third-party and vendor access to your systems?
- Is there a maintained risk register that findings feed into?
Not sure where your organisation stands? Get a preliminary, educational score in under five minutes.
Take the Free Cyber Risk Check