All tools › Assess

Threat and Risk Assessment

A threat and risk assessment you can hand to an auditor.

Describe one system: its assets, how they connect, and the safeguards you rely on, with the evidence behind them. You get a risk register where every risk names its threat, the safeguards it depends on and how confident the rating is, then treatment plans and a sign-off by two people.

Starting an assessment needs a RiskWoven account: sign in with your email and a one-time code. The example needs no account.

What you get

A released assessment as a PDF and a workbook, rendered from the record exactly as it was signed.

Risk register

Every risk with its asset, threat, the safeguards it relies on, the evidence for each, likelihood, impact and a confidence rating. A safeguard you state without evidence is rated claimed, never verified.

Treatment plans

Risks grouped into plans by what fixes them, with a target level for each. A target the safeguards cannot reach is marked rather than hidden.

Known exploited vulnerabilities

Named products and versions are checked against CISA's Known Exploited Vulnerabilities catalogue, and a match is raised in the register.

Challenge and sign-off

An independent challenge stage questions the result. Every flag it raises is resolved on the record, and release needs a business owner and a security reviewer who are two different people.

The example is a fictional credit union's member lending portal: 49 risks across three assets and one connection, marked SPECIMEN on every page. All examples.

What is checked, and what is not

Checked automatically

  • Release is refused while a challenge flag is open, a plan is out of date with the register, or a sign-off is missing.
  • The two sign-offs must come from two different signed-in people, and the security reviewer cannot be the person who wrote the intake.
  • Analysis does not start while a statement is vague, contradicted by your evidence or unsupported. What you cannot answer is listed in the report as a stated unknown.

Not checked: your responsibility

  • Whether your safeguards work as described. The assessment reads your statements and evidence; it does not test your systems.
  • Systems outside the scope you describe. Flows to other systems are noted and referred to their own assessment.
  • Whether the remaining risk is acceptable to your organisation. That is the sign-off's decision.

Who it is for

Teams that need a threat and risk assessment for a system before it goes live, for a customer, or for an audit, without a consultancy engagement.

$699 one-time, per assessment

  • Includes up to 20 assets, 3 third parties, 10 evidence documents, 20 connections and 20 assurance inputs. Larger systems cost extra credits, shown before you start.
  • Above 60 assets, Professional Review applies.

Prices in US dollars, exclusive of tax. Full detail on pricing.

Related tools

See all tools