Basics

Risk analysis

How do you carry out a risk analysis?

A risk analysis answers three questions. What can happen, how likely is it, and what does it cost. From that follows where you invest first.

The starting point is a list of what you protect. Customer data, the accounts, production, being reachable by email. Without that list you assess into thin air, because you do not know what is at stake.

Then for each point you consider what can go wrong and what that would mean. An outage of the inventory system for three days can be put in figures. The loss of patient records or client files additionally touches your professional duties and your reputation.

The result is an order of work. A high risk that is cheap to remedy is tackled first. Record the analysis in writing. Under section 32 NISG 2026 the risk analysis is one of the requirements, and Article 32 GDPR likewise calls for measures appropriate to the risk.

All terms in the knowledge base

From the term to practice

Where does your business actually stand?

The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.

Book a first call

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.