Table of Contents
What Is a Cyber Risk Assessment?
A cyber risk assessment is a structured, methodical evaluation of an organization’s information security posture across defined domains – identifying where threats exist, where controls are insufficient, how likely and severe a breach would be, and what the organization should do about it in what order. It is the foundational document of any mature security program.
A risk assessment is not a penetration test (which actively exploits vulnerabilities in a specific scope), not a compliance audit (which checks whether documented policies exist), and not a vulnerability scan (which identifies technical vulnerabilities in systems). It is a comprehensive evaluation of risk across technology, process, governance, and human factors – the full picture of how secure an organization actually is.
The output of a well-structured risk assessment is a risk register – a prioritized inventory of identified risks with severity ratings, likelihood assessments, existing control evaluations, and recommended remediation actions. This document serves as the strategic foundation for the security program: it tells leadership where to invest, what to fix first, and how to measure progress over time.
The Key Frameworks: NIST RMF, ISO 27005, and FAIR
Three established frameworks provide the methodological foundation for professional cyber risk assessments.
NIST Risk Management Framework (NIST RMF) – Published by the National Institute of Standards and Technology, the NIST RMF defines a six-step lifecycle for risk management: Categorize (define the information system and its data), Select (choose appropriate security controls), Implement (deploy controls), Assess (verify controls are implemented correctly), Authorize (make a risk-informed decision on system operation), and Monitor (continuously track control effectiveness). The NIST RMF is the most widely cited framework globally and serves as the backbone for many government and regulated-industry security programs.
ISO/IEC 27005 – The ISO standard specifically for information security risk management, designed as a companion to ISO 27001. ISO 27005 provides guidance on establishing context, risk identification, risk analysis, risk evaluation, and risk treatment. For organizations pursuing ISO 27001 certification, a risk assessment conducted under ISO 27005 methodology directly satisfies the certification requirement for risk assessment evidence.
FAIR (Factor Analysis of Information Risk) – A quantitative risk model that translates cyber risk into financial terms. Rather than categorical ratings (High/Medium/Low), FAIR produces range estimates of probable loss frequency and magnitude in monetary units. FAIR is particularly valuable for board and executive communication, cyber insurance calibration, and comparing the financial ROI of security investments. IPV Security incorporates FAIR-based financial quantification as an overlay on findings where executive financial clarity is required.
Why 18 Domains – Not 5
Standard risk assessment frameworks – including many commercially available tools and simplified questionnaire-based approaches – typically cover 5 to 7 domains. Common examples include: network security, endpoint security, data protection, access management, and incident response. These frameworks are not wrong – the domains they cover are genuinely important. But they systematically miss categories of risk that have proven, in practice, to be among the most consequential sources of breach and organizational harm.
The gaps in a 5-7 domain assessment include: the specific risks of privileged access (which is distinct from general access management and has a disproportionate risk profile), human risk beyond basic phishing (the behavioral and organizational dimensions of insider threat and error), third-party and supply chain risk (which was the attack vector in some of the most damaging breaches of the past five years), physical security (increasingly relevant as remote work policies blur the perimeter), business continuity and resilience (tested by ransomware incidents that exposed gaps in even technically sophisticated organizations), and regulatory compliance as a domain in its own right (not just an outcome of other controls).
IPV Security’s 18-domain methodology was developed over 21 years of enterprise CISO experience across 500+ client engagements. Every domain exists because IPV Security has seen it be the source of a significant security failure in real organizations. The 18-domain framework covers the full risk surface – not just the most obvious technical controls.
IPV Security’s 18-Domain Assessment: Complete Reference
Domain 1 – Identity and Access Management
What it assesses: Authentication standards (MFA, SSO, passwordless), user provisioning and deprovisioning processes, access review cadence, role-based access control design, and identity governance. Who can access what systems, how access is granted, how it is reviewed, and how it is removed when no longer needed. This is the most commonly exploited attack vector in enterprise breaches – compromised credentials or excessive access enable the majority of successful intrusions.
Domain 2 – Network Security
What it assesses: Network architecture and segmentation design, firewall rule sets, ingress and egress filtering, intrusion detection and prevention coverage, DMZ configuration, and lateral movement controls. Network security establishes the foundational boundary controls that determine how far an attacker can move once they have gained initial access to any part of the environment.
Domain 3 – Endpoint Protection
What it assesses: EDR/XDR deployment and coverage, endpoint configuration baseline (hardening, default account management, local admin controls), patch management for endpoints, mobile device management, and removable media policy. Endpoints are the most common initial compromise point – phishing and malicious attachments target users at their devices.
Domain 4 – Data Classification and Protection
What it assesses: Whether a data classification scheme exists and is applied, encryption at rest and in transit for sensitive data categories, data loss prevention controls, data retention and disposal procedures, and the security of data shared with third parties. Most organizations handle data across a spectrum from public to highly confidential without a consistent, enforced framework for how each category should be protected.
Domain 5 – Cloud Security
What it assesses: Cloud provider configuration against CIS Benchmarks (AWS, Azure, GCP), IAM policy design in cloud environments, cloud storage exposure, logging and monitoring completeness, network security group configurations, and multi-cloud governance. Cloud misconfigurations are the leading cause of enterprise data breaches – Gartner estimates 99% of cloud security failures are customer-caused.
Domain 6 – Application Security
What it assesses: Secure development lifecycle (SDLC) integration, code review and static analysis practices, dependency and third-party library management, web application penetration testing history, API security controls, and authentication and authorization implementation in applications. Vulnerabilities in custom-developed applications and third-party software are a consistent and significant breach vector.
Domain 7 – Third-Party and Supply Chain Risk
What it assesses: Vendor security assessment processes, contractual security obligations in supplier agreements, ongoing monitoring of third-party security posture, critical supplier identification and dependency mapping, and software supply chain security (SCA, SBOM). Supply chain attacks – including SolarWinds, MOVEit, and numerous others – have demonstrated that an organization’s security is only as strong as its weakest vendor with access to its environment.
Domain 8 – Security Governance
What it assesses: Security policy library completeness and review currency, board and executive security reporting, security ownership and accountability structure, security budget adequacy, security awareness culture, and whether the security program is driven by risk or by compliance alone. Without governance, technical controls operate without strategic direction, accountability, or measurable improvement.
Domain 9 – Incident Response Readiness
What it assesses: Whether a documented Incident Response Plan (IRP) exists, is current, and has been tested; whether an incident response team is defined with clear roles; whether detection and escalation procedures are documented; whether external support (legal counsel, forensics, PR) is pre-engaged; and whether post-incident review processes exist. The difference between a contained incident and a catastrophic breach is almost always determined by how prepared the organization was before the incident began.
Domain 10 – Business Continuity and Cyber Resilience
What it assesses: Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) completeness and test history; Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) defined and tested for critical systems; backup integrity and offline backup availability; and resilience against ransomware-specific scenarios. Ransomware has demonstrated that organizations with technically strong perimeter controls can still suffer catastrophic operational disruption if recovery capabilities are untested.
Domain 11 – Physical Security
What it assesses: Physical access controls to data centers, server rooms, and sensitive areas; visitor management; clean desk policy enforcement; physical security of remote work environments; and device security in shared or public spaces. Physical access to IT infrastructure bypasses almost all logical security controls – a threat actor with physical access to a server, workstation, or network port has circumvented firewall and authentication controls entirely.
Domain 12 – Human Risk Management
What it assesses: Security awareness training program design and coverage, phishing simulation frequency and metrics, insider threat controls (access monitoring, offboarding procedures, anomaly detection), and security culture assessment. The human element is present in the majority of successful breaches – either as the target of social engineering or as a source of accidental data exposure. Technical controls without a corresponding human risk program address only part of the risk.
Domain 13 – Vulnerability Management
What it assesses: Vulnerability scanning scope and frequency, patch management processes and SLAs, penetration testing history and remediation tracking, bug bounty or responsible disclosure programs, and zero-day response procedures. Known, unpatched vulnerabilities are the most preventable category of breach – and the most commonly exploited. An effective vulnerability management program requires both detection and remediation at scale.
Domain 14 – Logging, Monitoring, and Detection
What it assesses: SIEM deployment and log source coverage, Security Operations Center (SOC) capabilities (in-house, outsourced, or hybrid), alerting rules and detection logic, threat intelligence integration, mean time to detect (MTTD) and mean time to respond (MTTR) metrics, and coverage of cloud and remote environments. Security events that are not logged, alerted on, and investigated are breaches that will be discovered by attackers or journalists rather than by the security team.
Domain 15 – Privileged Access Management
What it assesses: Privileged account inventory (service accounts, administrative accounts, break-glass accounts), PAM tool deployment, just-in-time access controls, privileged session recording, password vaulting for shared privileged credentials, and separation of duties for privileged functions. Privileged accounts are the primary target in every sophisticated breach – they are the keys to the kingdom. A compromised privileged account gives an attacker capabilities that would take months to achieve through other means.
Domain 16 – Cryptography and Key Management
What it assesses: Encryption standards in use (algorithm strength, key length), key lifecycle management (generation, storage, rotation, revocation, disposal), certificate management (PKI, TLS certificates, expiry monitoring), and cryptographic controls applied to data in transit between systems. Weak cryptography or poor key management can render encryption controls ineffective – an encrypted database is only secure if the keys protecting it are adequately controlled.
Domain 17 – Regulatory Compliance
What it assesses: Mapping of applicable regulatory frameworks (ISO 27001, NIS2, DORA, GDPR, Israeli Privacy Protection Law, SOC 2, PCI-DSS, HIPAA, EU AI Act, sector-specific regulations) against existing controls; gap analysis by framework; evidence and documentation status for each applicable requirement; and audit readiness posture. Regulatory compliance is both an obligation and a board-level exposure – failing an audit or receiving a regulatory finding creates operational, financial, and reputational consequences beyond the security risk itself.
Domain 18 – Cyber Insurance
What it assesses: Whether cyber insurance coverage is in place, coverage adequacy versus assessed risk exposure, alignment of security controls with insurer requirements, claims history, and whether coverage terms are understood by the team responsible for incident response. Cyber insurance is increasingly required by regulators, enterprise customers, and boards – and increasingly conditional on demonstrating specific security controls. An organization whose security posture does not meet its insurer’s requirements may find coverage denied at precisely the moment it is needed.
The 18-Domain Summary Table
| Domain | What It Assesses | Why It Matters |
|---|---|---|
| 1. Identity & Access Management | Authentication, user provisioning, access reviews, role design | Compromised credentials are the #1 initial access vector in enterprise breaches |
| 2. Network Security | Architecture, segmentation, firewall rules, IDS/IPS | Controls how far an attacker moves after initial access |
| 3. Endpoint Protection | EDR coverage, patching, device management, hardening | Endpoints are the most common initial compromise point |
| 4. Data Classification & Protection | Data classification scheme, encryption, DLP, retention | Most breaches are ultimately data breaches — protection requires knowing what data exists and where |
| 5. Cloud Security | CIS Benchmark compliance, IAM, storage, logging | 99% of cloud failures are customer-side misconfigurations |
| 6. Application Security | SDLC practices, code review, API security, DAST/SAST | Custom and third-party application vulnerabilities are a consistent breach vector |
| 7. Third-Party & Supply Chain | Vendor assessments, contractual obligations, SBOM | Supply chain attacks have caused some of the most damaging breaches in history |
| 8. Security Governance | Policy library, board reporting, ownership, budget | Controls without governance operate without direction, accountability, or improvement |
| 9. Incident Response Readiness | IRP documentation, testing, team roles, external support | Preparation determines whether an incident is contained or catastrophic |
| 10. Business Continuity & Resilience | BCP/DRP testing, RTOs/RPOs, backup integrity | Ransomware has demonstrated that resilience gaps cause operational catastrophe even with strong perimeters |
| 11. Physical Security | Physical access controls, visitor management, device security | Physical access bypasses almost all logical controls |
| 12. Human Risk Management | Awareness training, phishing simulations, insider threat controls | The human element is present in the majority of successful breaches |
| 13. Vulnerability Management | Scanning scope, patch SLAs, pen test history | Known unpatched vulnerabilities are the most preventable breach category |
| 14. Logging & Monitoring | SIEM coverage, SOC capability, MTTD/MTTR metrics | Undetected events give attackers unlimited dwell time |
| 15. Privileged Access Management | PAM tooling, just-in-time access, session recording | Privileged accounts are the primary target in every sophisticated breach |
| 16. Cryptography & Key Management | Encryption standards, key lifecycle, certificate management | Weak keys or poor key management renders encryption ineffective |
| 17. Regulatory Compliance | Framework gap analysis, evidence status, audit readiness | Regulatory failure creates financial, operational, and reputational consequences |
| 18. Cyber Insurance | Coverage adequacy, control alignment with insurer requirements | Insurance denied at breach time is not insurance |
How a Risk Assessment Becomes a Remediation Roadmap
A risk assessment that produces a list of findings without a prioritized remediation plan is only half a deliverable. The risk register produced by IPV Security’s 18-domain assessment is the input to a structured remediation roadmap organized across three time horizons.
Immediate (0-30 days): Critical and high-severity findings that represent active, exploitable exposure with available remediation actions. These are the items where a breach could occur before the next review cycle, and where the remediation effort is proportionate to the urgency. Typical examples: disabling public storage access, enforcing MFA on administrative accounts, patching critical CVEs, revoking orphaned privileged accounts.
Near-term (30-90 days): High and medium-severity findings that require more significant remediation effort – policy development, tool deployment, architecture changes, or process redesign. Examples: deploying a PAM solution, implementing security awareness training, establishing a vulnerability management program, or completing a cloud security configuration baseline.
Program-level (90 days-12 months): Findings that require governance initiatives, organizational change, or significant technology investment. Examples: achieving ISO 27001 certification, implementing a formal third-party risk management program, deploying a SIEM with full log source coverage, or establishing a documented and tested business continuity program.
The roadmap is presented to executive leadership with resource requirements, ownership assignments, and measurable success criteria for each initiative. For clients using CISOteria, the roadmap is loaded directly into the platform – enabling real-time progress tracking, evidence upload against each item, and live risk register updates as findings are remediated.
Cyber Risk Assessments and Regulatory Compliance
A comprehensive cyber risk assessment is not just good security practice – it is an explicit obligation under every major regulatory framework applicable to mid-market enterprises.
ISO 27001 requires a documented information security risk assessment as a foundational requirement of the standard (Clause 6.1). Without a formal risk assessment, ISO 27001 certification cannot be achieved or maintained.
NIS2 requires essential and important entities to implement risk management measures, which must include systematic assessment of risks to network and information systems. NIS2 also requires documented security measures proportionate to the identified risk – a statement that requires documented risk assessment to be meaningful.
DORA requires financial sector entities to maintain a comprehensive ICT risk management framework, including periodic risk assessments with documented findings. DORA Article 6 specifically mandates ICT risk assessment as a continuous obligation, not a one-time event.
GDPR and the Israeli Privacy Protection Law both require that data protection be implemented using a risk-based approach – which in practice means that a documented risk assessment is the foundation of defensible compliance.
For organizations working toward any of these frameworks, commissioning a comprehensive 18-domain risk assessment is the most efficient starting point – it simultaneously satisfies the risk assessment requirement and produces the gap analysis needed to plan the full compliance program.
How IPV Security Conducts Its 18-Domain Assessment
IPV Security’s 18-domain cyber risk survey is the structured baseline assessment that anchors every IPV Security engagement. It is conducted across a 4-6 week engagement, combining structured stakeholder interviews, documentation review, and where applicable, technical evidence review.
The methodology draws on NIST RMF, ISO 27005, and FAIR quantitative risk modelling to produce a risk register that is both technically rigorous and executive-readable. Each finding includes: domain classification, risk description, current control effectiveness, likelihood and impact ratings, financial exposure estimate (where quantifiable), recommended remediation action, and implementation priority.
The output includes an executive risk dashboard, the full 18-domain risk register, a prioritized remediation roadmap, and a regulatory compliance gap analysis against all applicable frameworks. For clients on IPV Security’s vCISO program, the risk register is loaded directly into CISOteria — where it becomes the live backbone of the security program, updated quarterly and available to leadership at any time.
IPV Security’s 18-domain approach is broader than the 5-7 domain assessments typically offered by general IT consultants and tool-based questionnaire platforms. The additional domains – particularly privileged access, human risk, cyber insurance, and physical security — consistently surface material risks that narrower assessments leave invisible.
Explore IPV Security’s Cyber Risk Survey service →
Learn about the CISOteria Cyber OS™ platform →
Compliance Guide: ISO 27001, NIS2, and DORA →
About the Author
Ido Ganor is the Founder and CEO of IPV Security, an Israeli enterprise cybersecurity advisory firm serving mid-market and enterprise clients across Israel and the EU. With 21+ years of experience as an enterprise CISO and security advisor across 500+ organizations – including Leumi Bank, the State Comptroller of Israel, and Tel Aviv Municipality – Ido developed IPV Security’s 18-domain risk assessment methodology from direct observation of where security programs succeed and fail. He is the creator of CISOteria Cyber OS™, the world’s only client-facing CISO management platform, which turns risk assessment findings into continuously tracked, board-visible security program outcomes.
Related Articles
- Compliance Guide: ISO 27001, NIS2, and DORA for Mid-Market Enterprises →
- Cloud Security Review: What to Assess and Why →
- AI Architecture Security: Complete Guide for CTOs in 2026 →
Ready for a comprehensive risk assessment? IPV Security’s 18-domain cyber risk survey gives you the complete, evidence-based picture of your security posture and the prioritized roadmap your leadership team needs to act. Available as a standalone engagement or as the foundation of an IPV Security vCISO program.
Frequently Asked Questions
What is a cyber risk assessment and why does my organization need one?
A cyber risk assessment is a structured evaluation of your organization’s security posture across defined domains – identifying threats, control gaps, and priorities for remediation. Your organization needs one because security investment without a risk baseline is guesswork: you cannot prioritize remediation, justify security budget, demonstrate compliance, or report meaningfully to the board without knowing where your actual risks are. IBM’s 2024 data puts the average cost of a data breach at $4.45 million. A comprehensive risk assessment costs a fraction of that – and the organizations most likely to suffer a costly breach are those that have never formally assessed their risk. For organizations subject to ISO 27001, NIS2, DORA, or GDPR, a documented risk assessment is also a mandatory compliance requirement.
How long does a cyber risk assessment take?
A comprehensive 18-domain cyber risk assessment typically takes 4-6 weeks from kickoff to final report delivery. This includes structured stakeholder interviews across the organization (IT, security, legal, compliance, operations, and executive leadership), documentation review, technical evidence review where applicable, risk analysis and scoring, report writing, and executive readout. Compressed timelines – driven by certification deadlines or incident response requirements – can be accommodated with additional resource allocation. Questionnaire-based self-assessments take less time but produce significantly less reliable results – the findings in a structured, interview-led assessment consistently surface material risks that self-assessments miss.
What is the difference between a risk assessment and a penetration test?
A risk assessment and a penetration test are fundamentally different in scope and purpose. A risk assessment is a broad evaluation of security posture across governance, process, technology, and human factors – it answers the question “what is our overall risk profile and where should we invest?” A penetration test is a targeted, technical assessment that actively exploits vulnerabilities in a defined scope – it answers the question “can an attacker exploit these specific systems, and how?” Both are necessary components of a mature security program, but they serve different purposes. Most organizations should complete a risk assessment before commissioning a penetration test – the risk assessment identifies where the highest risks are, which informs where penetration testing effort is most valuable.
How is IPV Security’s 18-domain assessment different from standard approaches?
Standard commercial risk assessments and questionnaire-based tools typically cover 5-7 domains: network security, endpoint protection, access management, data protection, and incident response. IPV Security’s 18-domain methodology covers these and adds: privileged access management (a distinct and disproportionately high-risk domain), physical security, human risk management beyond basic phishing, third-party and supply chain risk, cryptography and key management, business continuity and resilience, regulatory compliance as an independent domain, and cyber insurance adequacy. These additional domains consistently surface material risks that 5-7 domain assessments miss. The methodology was developed over 21 years of enterprise CISO engagements across 500+ organizations — every domain exists because IPV Security has seen it be the source of a significant security failure in real client environments.
What frameworks does IPV Security’s risk assessment align with?
IPV Security’s 18-domain risk assessment methodology aligns with NIST RMF (providing the risk management lifecycle structure), ISO/IEC 27005 (providing the risk assessment methodology for ISO 27001 alignment), FAIR (Factor Analysis of Information Risk, used for financial quantification of findings), and CIS Controls v8 (used as a technical control benchmark). The assessment output is mapped to applicable regulatory frameworks – ISO 27001, NIS2, DORA, GDPR, Israeli Privacy Protection Law, SOC 2, and others as applicable – so that the risk register serves simultaneously as the technical remediation roadmap and the compliance gap analysis. Organizations do not need to commission separate assessments for each framework.
How does the risk assessment integrate with CISOteria?
For clients using CISOteria Cyber OS™, the 18-domain risk assessment is the foundation on which the CISOteria deployment is built. The risk register from the assessment is loaded directly into CISOteria’s Risk Management module – each finding becomes a tracked item with an owner, a severity rating, a remediation plan, and a status indicator. As findings are remediated, evidence is uploaded against each item in CISOteria and the risk register is updated in real time. This means that six months after the initial assessment, the board and leadership team are not looking at a stale PDF – they are looking at a live dashboard that reflects the current state of risk, which findings have been remediated, and where the program is investing its effort. The risk register is reviewed and updated quarterly as part of IPV Security’s vCISO program.