Skip to main content

Risk Register

The register is the list of risks your organisation has decided to track. Each entry has a category, an owner, a score, a status and a review date, and — when it came from a scanner — a link back to the findings that justify it.

Where: Risk Management → Risk Register.

Risk Register grouped by category: Security Vulnerability (74 risks, 627 findings), Cloud Security, Privacy, Compliance, Operational, License Compliance, Third Party, Technical — each with severity, counts, owners and next due

Two views

  • By category (default) — one row per category with risk count, linked findings, affected assets, open count, owners and the earliest next due review. Expand a category to its risks.
  • All risks — every risk as a row: ID (RISK-001…), title, type, likelihood × impact score, severity, category, owner, status, next review. Search by title, description, owner or ID; filter by category, severity and status; select rows for bulk actions.

Risk Register, all risks: RISK-001 unpatched critical RCE in the internet-facing API gateway (L5 × I5 = 25, critical), RISK-017, RISK-028 … with type, score, category and owner

Create a risk

Create New Risk: assessment type (Business Risk 1–5 likelihood × impact, or System Risk 0–100 magnitude), title, category, owner and description

  1. Add New Risk and choose the assessment type: Business Risk (likelihood 1–5 × impact 1–5) or System Risk (initial and current magnitude 0–100).
  2. Title, category — Security Vulnerability, Cloud Security, Compliance, Data Privacy, Operational, Financial, Reputational, Strategic, Technical, Third Party, License Compliance — and owner.
  3. Description, the assessment values, and optionally a review frequency (monthly, quarterly, semi-annual, annual). AI can auto-fill description, category, likelihood and impact from the title.
  4. Save. The risk starts as identified.
StatusMeaning
identifiedRecorded, not yet assessed
assessedScored and owned; treatment under way
mitigated · accepted · transferredTreated, per the plan's strategy
closed · archivedNo longer active; kept for history

Open a risk for its history (every score and status change), its linkages (findings, controls, treatment plans), and velocity — how fast its score has been changing.

Import from findings

Where: Risk Management → Import from Findings.

Import from Findings: source cards (Vulnerability Management, Cloud Security), finding type and minimum severity selectors, Preview Findings / Import as Risks, and a preview of 24 candidate findings

Findings are imported as risks in two ways:

  • Automatically. After every vulnerability sync, still-open high and critical findings from any scanner that are not yet linked to a risk are minted as risks (one per vulnerability, deduplicated) and linked back to their occurrences. Cloud findings additionally import on the finding created event. This is why a freshly scanned team's register fills with a Security Vulnerability category.
  • On demand. Choose the finding type (all, vulnerabilities only, CSPM findings only) and a minimum severity (critical / high / medium), Preview Findings to see the candidates, then Import as Risks. Already-linked findings are skipped, so re-running is safe.

Imported risks show their source findings in the linkages panel, and the finding shows its linked_risk_id, so a risk's evidence is always one click away.

Bulk import and export

Where: Risk Management → More → Bulk Import/Export.

Bulk Risk Import: download the CSV/Excel template or upload your own spreadsheet, confirm the field mapping, import

Migrating an existing register? Download Template (CSV or Excel) and fill it — columns are title, description, category, likelihood, impact (required) plus owner, status, mitigation_strategy — or upload your own spreadsheet: its column headers are matched to the template fields automatically (Risk Name, Probability, Severity, Risk Owner, Mitigation Plan and similar are recognised), and you confirm or adjust the mapping before Import. Each valid row becomes a new risk with the next RISK-nnn number; rows missing a required field are skipped and listed. Import never updates or deletes existing risks. Category and status labels are normalised to the register's values — anything unknown starts as technical / identified.

Export — select rows and Export CSV, or use Full Risk Export on the Reports tab for the whole register with treatment plans and controls.

One risk, many findings

Resist importing every medium finding. The register is for what needs a business decision; keep medium/low findings in the Triage queue and let Import from Findings at high or critical be the bridge.