Templates / Cybersecurity risk register template
Cybersecurity risk register template
A cybersecurity risk register records the security risks facing your organisation — phishing, ransomware, insider misuse, exposed cloud storage — each rated and matched to controls. The worked example below is drawn from recognised control frameworks and is free to download or open live.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: cybersecurity risk register template
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Phishing and credential theftAn attacker tricks a staff member into revealing a password or approving a login, or steals a session, and gains access to email, files or business systems. | security | high | high | Enforce phishing-resistant multi-factor authentication (passkeys or hardware security keys) on email and any account that reaches sensitive data. | |
| Supplier or third-party compromiseA vulnerability, breach or malicious update at a vendor, hosting provider or software dependency reaches your systems or data through the trusted connection. | security | medium | high | Keep an inventory of suppliers and the systems and data each can reach, and set security expectations in the contract before onboarding. | |
| Insider threat or misuse of accessA current or former staff member, contractor or privileged user misuses their access — to steal data, cause damage, or act carelessly — and the activity blends into normal work. | security | medium | high | Grant least-privilege access and review it regularly, especially after a role change; revoke everything promptly when someone leaves. | |
| Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in. | security | high | high | Build systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it. | |
| Unpatched or end-of-life systemsA known vulnerability in software, a device or a dependency is left unpatched — or the product is past end of support — and an attacker exploits it. | security | high | high | Keep a live inventory of software and versions and scan for known vulnerabilities, prioritising internet-facing and critical systems. | |
| Prompt injection of a deployed AI featureMalicious instructions hidden in user input or in content the model retrieves override its intended behaviour — leaking data, calling tools, or producing harmful output. | security | medium | high | Red-team the feature for prompt injection and jailbreaking before launch and periodically after. | |
| Insecure AI-assisted developmentStaff use AI coding assistants to build or change software and ship the output without review, introducing vulnerabilities, insecure dependencies, hardcoded secrets or unmanaged systems. | security | high | medium | Require human security review and testing of AI-generated code before it reaches production, the same as any other code. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
What is a cybersecurity risk register?
It's the security-focused view of your risk register: the specific threats to your systems and data, each scored for likelihood and impact and mapped to the controls that reduce it. It's core evidence for ISO 27001 and SOC 2.
What are the most common cybersecurity risks?
Phishing and credential theft, ransomware, supplier compromise, insider misuse, cloud misconfiguration, and unpatched systems — all included with recommended controls in the example below.
Do you offer a free cybersecurity risk register tool?
Yes — download the CSV with no sign-up, or open it live in Urna to build your own, score it, and get a suggested remediation for every risk. Free, no card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.