Risks

Score it, treat it,
review it.

Keep a single risk register where every risk is scored on likelihood and impact, carries an owner and a treatment strategy, and links to the controls that evidence it. Rank what matters most, drive each risk with owned treatment actions, and run reviews against the deadline you set.

Start for freeBook a conversation
++++
app.devguard.ch / risks
61 open
Average score
Average risk score
7.4
/ 10 impact
High02
Medium16
Low43
IDRiskScoreOwnerStatus
R-114Unpatched dependency9.8A. KleinTreating
R-109Weak TLS on legacy host8.6J. DoeTreating
R-097Over-broad IAM role5.4M. RossiAccepted
R-088Backup restore untested4.9T. SchmidClosed
R-072Vendor DPA missing3.1J. DoeClosed
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Score, prioritize, treat, review.

One register, scored and owned, from the day a risk is logged through every review.

01

Score and rank each risk

Rate every risk on likelihood and impact, 0 to 10 each, and the two multiply into a score out of 100 with severity computed for you. Assign an owner, and the register sorts by score so the highest-scoring risks sit at the top instead of getting lost in a flat list.

02

Treat it and track the residual

Set a treatment strategy, mitigate, accept, avoid or transfer, then drive it with owned treatment actions that each carry a due date and a status. The residual score sits next to the initial score, so the effect of the work is visible rather than assumed.

Controls as evidence

Link the controls that evidence a risk for compliance, kept separate from the treatment actions, so proof and work each sit in the right place.

03

Review against a deadline

Each risk review runs against a deadline you set and is worked to completion. The deadline shows up alongside every other due item, so a review is visible rather than slipping between audits, and you archive a risk once it is handled.

Why it’s built this way

Built to be worked, not listed.

Four choices behind how the risk register works here, each one something you can check, not an adjective.

01

Every risk carries a score

Each risk is rated on likelihood and impact, 0 to 10 each, multiplied into a score out of 100 with severity computed for you. The register ranks by score instead of treating every line the same.

02

Initial and residual, side by side

Each risk keeps an initial score and a residual score after treatment, so you can see how far the work has moved it rather than guessing.

03

A treatment strategy with owned actions

Pick a strategy per risk, mitigate, accept, avoid or transfer, then drive it with owned treatment actions that each carry a due date and a status of their own.

04

Controls evidence it, separate from the work

Link a risk to the controls that evidence it for compliance, kept distinct from the treatment actions, so proof and work each live in the right place.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Export your risk register to CSV, and your data is yours through the API, with no lock-in.

See the full feature comparison

One module of the platform

Where risks connect.

Risks are one module; each risk reaches into the rest of the workspace, from the controls that evidence it to the deadlines that keep its review on time.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Link each risk to the controls that evidence it, mapped across every framework.

1,284
assets tracked
+12 today

Assets

Tie a risk to the assets it threatens, scoped from your inventory.

EventPR merged
ActionEvidence captured

Actions

Turn a risk’s treatment into owned actions, each with an owner and a due date.

JUN
ISO review
in 3 days

Deadlines

See each risk’s review deadline alongside every other due item.

FAQ

The questions evaluators ask.

How is a risk scored?

Each risk is rated on likelihood and impact, 0 to 10 each, and the two multiply into a score out of 100. Severity is computed from that score, so the highest-scoring risks surface at the top rather than sitting in a flat, unsorted list. Each risk keeps both an initial score and a residual score after treatment.

How do I show a risk is being treated?

You set a treatment strategy, mitigate, accept, avoid or transfer, then drive it with owned treatment actions that each carry a due date and a status. The residual score shows how far that work has moved the risk, and you archive a risk once it is handled.

What keeps risk reviews from going stale?

Each risk review runs against a deadline you set and is worked to completion. The deadline sits alongside every other due item, so an upcoming review is visible rather than remembered by hand.

How is this different from a risk spreadsheet or another GRC tool?

In a spreadsheet, a risk is a row with a score nobody re-checks and a treatment column that points nowhere. Here, each risk is a scored, owned record with a treatment strategy, owned treatment actions, and controls linked as evidence, so the register reflects where every risk actually stands.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. You can export your risk register to CSV, and your data is yours through the API, so there’s no lock-in.

Work every risk from score to residual.

Keep one scored, owned register, set a treatment strategy with owned actions, and run reviews against the deadline you set. See where every open risk stands instead of rebuilding the list before each audit.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free