Getting Started With The Risk Register
The Risk Register in CyberHQ is the central view of your organisation's risks, bringing scoring, control effectiveness and reporting together in one place.
The Risk Register is where your risks live. It shows what you are exposed to, how severe each risk is, which controls are bringing it down, and how your position is trending. It matters because it is both the view your team works from day to day and the place you read your overall risk posture, so a well-maintained register is what makes your reporting defensible.
How risk is structured
CyberHQ models risk in three tiers: Risk Categories, Risks, and Issues. Issues feed up into Risks, and Risks feed up into Risk Categories. An issue is something going wrong now; a risk is what that issue could lead to; a category is the class of consequence the risk belongs to. Your register sits in the middle tier, which is why what you log at the bottom moves the numbers at the top.
The KPI cards
Four cards sit above the register: Total Risks, Extreme/Critical, Escalation Required, and Total Exposure. Click any card to filter the table to those records, click it again or click Total to clear, and hover for a breakdown by category, owner, treatment or severity.
Total Exposure behaves slightly differently — selecting it opens a drawer showing your financial exposure broken down by reputational, financial and operational cost, following the risk impact types configured in your Risk Settings. This is the quickest way to answer "what is this actually worth to us" without building a report.
How risks are scored
Each risk carries a score from 1 to 25 on a 5x5 matrix, or up to 36 on a 6x6. A higher score means more risk.Risk is measured in Severity throughout CyberHQ, derived from impact and likelihood as configured in your risk matrix. Severity is used consistently in the Risk Register, the Issues Register and your reports, so a High in one place means a High in another.
Linking a risk to its Risk Categories
Each risk needs to be linked to the Risk Categories it relates to. This is the foundation of the assessment, and until it is done the risk cannot be scored automatically.
Linking matters because it is what tells CyberHQ which part of your control posture applies to this risk. Your controls are mapped to Risk Categories and weighted according to whether they are Key or Compensating controls; when you link a risk to a category, the scores of the controls behind that category drive the risk's likelihood. Where the controls behind a category are strongly implemented, that category contributes less to the risk; where they are weak, it contributes more.
When to set a score yourself
Every calculated value can be manually overridden. Set a score yourself when your organisation has its own residual risk assessment criteria that you would rather apply than CyberHQ's calculation - the platform is there to support your methodology, not to replace it. An override holds, and is not recalculated underneath you.
Two details are worth knowing about what CyberHQ does and does not recalculate:
-
Only likelihood is recalculated. Residual impact stays wherever you last set it. If your controls improve, your residual likelihood falls and your residual impact does not, which is intentional: controls change how often something happens more readily than how much it costs when it does.
-
Where a risk spans several categories, the worst one is reported. A risk linked to three categories takes its headline residual from the least-mitigated of the three rather than an average, so a single weak area is never hidden behind two strong ones.
Governance zones
The heat map is banded into three governance zones:
-
Green — within tolerance. Acceptable as it stands; no action required.
-
Amber — within appetite. Not where you want it, but tolerable for now. Suitable for local management rather than escalation.
-
Red — above appetite. Escalate. Depending on your organisation this means the board, the CIO, or the chief risk officer, but the point is the same: this risk is large enough to need a decision above the security team.
You configure these in Risk Settings - see How to customise your Risk Matrix for the difference between appetite and tolerance.
Linking controls to a risk
Controls associated with a risk category are taken into account automatically. You can also link specific controls to an individual risk where a control has a material effect that the category-level mapping does not capture. The score updates in real time as you link them, reflecting how fully each control is implemented.
Since Release 2.7, controls linked this way also feed risk control effectiveness, and their designation matters: key controls carry a weighting of 1.0 and compensating controls 0.5. See Risk Settings Overview.
Linking issues to a risk
Where a risk has a live instance - something going wrong right now rather than something that might — link the issue to the risk. This is the bottom tier of the model feeding the middle one.
Reporting from the register
The register carries its own reporting widgets on the same page, so the questions you ask most often - how your risk is distributed, where it is concentrated, how it is moving — are answered where you are already working rather than in a separate report. This is why there is no longer a standalone risk report: your overall position is
read here, and the Risk Category report goes deeper on individual categories.
A note for legacy customers: migrated exposure data
If your organisation used CyberHQ before Release 2.7, you may have established your baseline risk through a separate Exposure Assessment. That assessment has been retired, and the risk calculation simplified so the same exposure is not counted twice.
Your exposure data was migrated into this register as a one-time move, and any residual scores you had already set were preserved. Migrated entries are not maintained automatically, so review them as part of your normal risk review to make sure they reflect your current position. This does not affect workspaces created after Release 2.7.
Where to go next
For category-level scoring and trends, see Understanding the Risk Category Report
For how issues change these numbers, see Understanding the Impact of Issues on Risk
To configure how risk is calculated, see Risk Settings Overview