Core
Performing a Cyber Security Risk Assessment
Risk assessment training in Toronto for the person who was handed the job and a spreadsheet. Over six weeks you run one method end to end: scoping, evidence collection, control evaluation, scoring and reporting.
The emphasis is on findings that move. You practise writing risk statements a business owner can act on, defending a score under challenge, and tracking remediation after the report is delivered.
- Duration
- 6 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Scope an assessment so the boundary and rules of engagement are agreed in writing
- Choose between qualitative, semi-quantitative and quantitative methods for a given brief
- Run interviews and document reviews that surface how a control actually operates
- Test design effectiveness and operating effectiveness separately
- Score inherent and residual risk on a scale that survives challenge
- Write a risk statement naming asset, threat, weakness and business consequence
- Present findings to a steering committee and hold your position under pushback
- Track treatment plans through to closure with evidence
Course outline
6 modules
- Deciding what you are assessing and, more importantly, why
- Defining threat, vulnerability, likelihood and impact consistently
- Selecting a method that matches the data you can actually get
- Agreeing scope, access and rules of engagement with stakeholders
- Establishing risk appetite context before anything is scored
What you need before you start
- Familiarity with common security controls such as patching, access control and logging
- Comfort working in a spreadsheet and writing in plain business English
- Access to a workplace scenario or willingness to use the supplied sample organization
- About five hours a week outside class for the assessment exercise
Who this course is for
- Analysts and consultants asked to run their first formal risk assessment
- IT managers who own risk reporting without a risk background
- Internal auditors extending into technology and security
- Governance, risk and compliance staff who want more technical depth
Where this leads
Prepares you for
CRISC
Awarded by ISACA
The method taught here lines up with the risk identification and assessment domains of ISACA CRISC. Examination, experience verification and the certificate itself are handled by ISACA, not by this academy.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



