Skedmia

Free kit

Cyber Security Risk Mitigation Checklist

80 controls in 10 risk areas, each with the reason it matters — plus a 5 × 5 cyber risk register template.

A plain-language checklist of the controls most organisations need to reduce cyber risk, with a one-line rationale for every control so you can explain to management why it matters — and a risk register to turn the gaps into decisions.

What is inside

Cyber Security Risk Mitigation Checklist — 80 controls in 10 risk areas: risk management programme, policy, personnel and training, operations, secure development, physical security, third-party relationships, network, platform and application layer. Mark each control In place, Partial or Missing.

Cyber Risk Register Template — likelihood and impact scales, a 5 × 5 rating method, a register with two worked examples, and a treatment plan.

Both documents as a designed, print-ready PDF and as an editable Word file.

Who it is for

IT and security managers, risk and compliance officers, business owners and consultants — especially small and medium-sized organisations building a cyber risk programme for the first time.

How to use it

Complete the checklist, move every Partial or Missing control into the risk register, rate likelihood and impact, and decide whether to reduce, avoid, share or accept each risk. Report the top risks — not the whole list — to management, with the decision you need from them.

What is in the kit

  • Cyber Security Risk Mitigation Checklist (PDF)80 controls in 10 risk areas, each with its rationale and an In place / Partial / Missing box.
  • Cyber Risk Register Template (PDF)Rating scales, 5 × 5 method, register with worked examples and a treatment plan.
  • Cyber Security Risk Mitigation Checklist (editable Word)The same 80 controls in Word, so you can adapt them and fill them in on screen.
  • Cyber Risk Register Template (editable Word)Editable register — replace the worked examples with your own risks.

A look inside

The first pages of Cyber Security Risk Mitigation Checklist (PDF). The full document downloads from the list above.

Cyber Security Risk Mitigation Checklist — preview of page 1Cyber Security Risk Mitigation Checklist — preview of page 2

Next step

Learn to use it properly — with a certificate

The documents tell you what to check. These courses teach you how to audit and implement it, online and at your own pace.

Questions people ask

Is the Cyber Security Risk Mitigation Checklist really free?

Yes. There is no payment and no trial. Tell us your name, work email and company once, and every document in the Free Zone is yours to download.

What format are the documents in?

This kit has 4 documents in PDF and DOCX format. The Word, Excel or PowerPoint files are fully editable, so you can adapt them to your organisation.

Can I use it inside my company?

Yes. The licence covers one organisation with unlimited internal use — print it, share it with colleagues and adapt it. Please do not resell it or republish it as your own.

Does this make us compliant with ISO/IEC 27005?

No document can do that on its own. It is a practical working tool to help you prepare, check and improve. Conformity with ISO/IEC 27005 is decided by an audit of your actual system, and the standard itself remains the authoritative text.

Do you offer training on this topic?

Yes. Skedmia runs online courses with certificates on the standards and topics these kits cover — the matching courses are listed on this page.

More from the Free Zone