Free kit
Cyber Security Risk Mitigation Checklist
80 controls in 10 risk areas, each with the reason it matters — plus a 5 × 5 cyber risk register template.
A plain-language checklist of the controls most organisations need to reduce cyber risk, with a one-line rationale for every control so you can explain to management why it matters — and a risk register to turn the gaps into decisions.
What is inside
Cyber Security Risk Mitigation Checklist — 80 controls in 10 risk areas: risk management programme, policy, personnel and training, operations, secure development, physical security, third-party relationships, network, platform and application layer. Mark each control In place, Partial or Missing.
Cyber Risk Register Template — likelihood and impact scales, a 5 × 5 rating method, a register with two worked examples, and a treatment plan.
Both documents as a designed, print-ready PDF and as an editable Word file.
Who it is for
IT and security managers, risk and compliance officers, business owners and consultants — especially small and medium-sized organisations building a cyber risk programme for the first time.
How to use it
Complete the checklist, move every Partial or Missing control into the risk register, rate likelihood and impact, and decide whether to reduce, avoid, share or accept each risk. Report the top risks — not the whole list — to management, with the decision you need from them.
What is in the kit
- Cyber Security Risk Mitigation Checklist (PDF)80 controls in 10 risk areas, each with its rationale and an In place / Partial / Missing box.955 KB
- Cyber Risk Register Template (PDF)Rating scales, 5 × 5 method, register with worked examples and a treatment plan.618 KB
- Cyber Security Risk Mitigation Checklist (editable Word)The same 80 controls in Word, so you can adapt them and fill them in on screen.34 KB
- Cyber Risk Register Template (editable Word)Editable register — replace the worked examples with your own risks.28 KB
A look inside
The first pages of Cyber Security Risk Mitigation Checklist (PDF). The full document downloads from the list above.
Next step
Learn to use it properly — with a certificate
The documents tell you what to check. These courses teach you how to audit and implement it, online and at your own pace.
Questions people ask
Is the Cyber Security Risk Mitigation Checklist really free?
Yes. There is no payment and no trial. Tell us your name, work email and company once, and every document in the Free Zone is yours to download.
What format are the documents in?
This kit has 4 documents in PDF and DOCX format. The Word, Excel or PowerPoint files are fully editable, so you can adapt them to your organisation.
Can I use it inside my company?
Yes. The licence covers one organisation with unlimited internal use — print it, share it with colleagues and adapt it. Please do not resell it or republish it as your own.
Does this make us compliant with ISO/IEC 27005?
No document can do that on its own. It is a practical working tool to help you prepare, check and improve. Conformity with ISO/IEC 27005 is decided by an audit of your actual system, and the standard itself remains the authoritative text.
Do you offer training on this topic?
Yes. Skedmia runs online courses with certificates on the standards and topics these kits cover — the matching courses are listed on this page.
More from the Free Zone
FreeNewEditableAWS Security Checklist
90 checks to review an AWS account — root user, IAM, network, S3 and databases, encryption, logging, detection and recovery.
FreeNewEditableIT Security Audit Checklist
120 audit checks across 12 control areas, plus an audit plan and findings log — ready for your next internal IT audit.
FreeNewPopularISO 27001:2022 Compliance Checklist
Check that your ISMS documents, clauses 4–10 and Annex A controls are audit-ready before certification.


