This template bundle gives you a ready-to-use risk register, a scoring rubric, and worked examples so your business can run a meaningful cybersecurity risk evaluation in a single day. Download the package (XLSX spreadsheet + PDF quick guide), open the spreadsheet, list your top assets, score the ten highest-risk items, and prioritise the three that need treatment this month.
Do this immediately after downloading:
- Save the XLSX to a shared drive your IT lead and business owner can both access.
- Create an “Evidence” folder in the same location for configuration exports, backup test logs, and policy documents.
- Block two hours in the calendar within the next five business days for the initial asset-listing workshop.
- Set a recurring quarterly calendar reminder to review and update the register.
Key takeaways
A structured cyber risk assessment template gives Australian SMEs a defensible, evidence-backed risk register they can complete in a single day and maintain quarterly.
| Point | Details |
|---|---|
| Download and start today | Open the XLSX, list your top assets, score the ten highest-risk items, and prioritise the three that need treatment this month. |
| Evidence folder is non-negotiable | Auditors and cyber insurers open the evidence folder first — attach config exports, patch reports, and backup test logs to every high-priority row. |
| Four controls cut the most risk | Enforcing MFA, testing backups, applying critical patches within two weeks, and enabling disk encryption address the majority of SME risk register findings. |
| Map to ACSC Essential Eight | Tagging each control row to an Essential Eight strategy gives you a compliance snapshot insurers and government panels increasingly require. |
| Escalate Critical rows promptly | Any row scoring Critical that cannot be treated internally within the required timeframe should be escalated to Techbug or another qualified provider. |
Table of Contents
- What’s in the cyber risk assessment template bundle?
- How to run a cyber risk assessment using the template
- Worked examples: completed risk register rows
- How to define likelihood and impact scores consistently
- Who should run this, and how long does it take?
- Practicalities for small businesses: mistakes, quick wins, and escalation triggers
- How the template maps to Australian frameworks and compliance
- Glossary of terms and template completion tips
- The reality of cyber risk assessments for Australian SMEs
- Techbug’s risk assessment and managed security services
- Sources
What’s in the cyber risk assessment template bundle?
The bundle contains three files: an editable spreadsheet (XLSX, compatible with Microsoft Excel and Google Sheets), a printable PDF quick guide, and a pre-filled sample register showing five completed rows. There is also an evidence-folder checklist as a separate tab in the spreadsheet.
A short, focused register is the format auditors and cyber-insurance carriers actually expect from small businesses: one to two pages of register plus an organised evidence folder, not a 60-page report nobody re-reads.
What each column means
| Column | Expected entry |
|---|---|
| Asset name | Plain-language label, e.g. “Staff email (Microsoft 365)” |
| Asset owner | Name or role of the person responsible |
| Asset category | Hardware / Software / Data / Service / People |
| Sensitivity | Public / Internal / Confidential / Restricted |
| Threat | Short description of what could go wrong |
| Vulnerability | Why the asset is exposed to that threat |
| Controls in place | What you already have (MFA, AV, backup, etc.) |
| Likelihood (1–5) | Numeric rating — see scoring section |
| Impact (1–5) | Numeric rating — see scoring section |
| Risk score | Likelihood × Impact |
| Priority | Low / Medium / High / Critical |
| Treatment | Treat / Accept / Transfer / Avoid |
| Treatment owner | Who is responsible for the action |
| Target date | When the treatment must be complete |
| Evidence reference | Filename or folder path for supporting evidence |
Pro Tip: Name evidence files with the asset name and date, e.g. “M365-MFA-config-export-2026-03.pdf”. Auditors and insurers can then match each register row to its evidence in under a minute.
The evidence folder should contain configuration exports (firewall rules, MFA settings), deployment reports (patch status, AV coverage), backup test logs, and any vendor security attestations. A cross-mapped checklist aligned to NIST CSF 2.0, ISO/IEC 27001:2022 Annex A, and CIS Controls v8 means a single completed row can satisfy multiple framework asks when you hand the register to an auditor or insurer.
How to run a cyber risk assessment using the template
Work through these steps in order. A first run for a small business typically takes half a day; a quarterly refresh takes one to two hours.
-
Establish context and scope. Define which systems, locations, and business processes are in scope. A payroll system and customer database are almost always in scope; a staff kitchen TV is not. Write the scope in the “Notes” tab of the spreadsheet.
-
Build your asset inventory. List every asset that stores, processes, or transmits business-critical or personal data. Government guidance recommends maintaining a current asset inventory as the foundation of any risk programme. Aim for a manageable number of assets appropriate for a small business’s size and complexity.
-
Identify threats for each asset. For each asset, ask: what could an attacker or accident do to it? Common threats include phishing, ransomware, lost devices, insider misuse, and vendor compromise.
-
Assess vulnerabilities. For each threat, note why the asset is exposed. Unpatched software, absent MFA, and unencrypted laptops are the three most common answers for Australian SMEs.
-
Document existing controls. Record what you already have in place. This is not the time to be optimistic — if MFA is enabled for only half the team, note that.
-
Rate likelihood (1–5). Use the scale in the scoring section below. Be consistent: the same assessor should rate all rows in a single session.
-
Rate impact (1–5). Consider financial loss, reputational damage, regulatory exposure, and operational downtime.
-
Calculate the risk score. Multiply likelihood × impact. The scoring system categorizes risk with higher scores indicating higher priority, from low to critical.
-
Prioritise. Sort the register by score, descending. Your top three to five rows are the immediate action items.
-
Choose a treatment for each risk. Four options:
- Treat: implement or improve a control to reduce the risk.
- Accept: document the decision and the business rationale; revisit next quarter.
- Transfer: purchase or extend cyber insurance, or outsource the function.
- Avoid: stop the activity that creates the risk (e.g., discontinue an end-of-life system).
-
Assign owners and target dates. Every treatment row must have a named person and a date. Unowned actions do not get done.
-
Iterate. Calendar the next review before you close the file. NIST CSF 2.0 organises outcomes across six functions — Govern, Identify, Protect, Detect, Respond, and Recover — and is designed to be used iteratively, not completed once and filed.
Handling vendor and third-party risk rows
Add a row for each critical vendor (payroll provider, cloud storage, managed print, etc.). The asset is the vendor service; the vulnerability is your dependency on their security posture. Attach their most recent security attestation or SOC 2 report to the evidence folder. If they cannot supply one, that gap itself is a finding.
Roles and responsibilities:
- Project lead: coordinates the workshop, owns the register file.
- Technical SME: rates likelihood and vulnerability, documents controls.
- Business owner / approver: confirms scope, signs off on accepted risks.
- Evidence curator: collects and names files in the evidence folder.
Pro Tip: Keep the register to 20–30 rows for a first run. A 200-row spreadsheet that nobody maintains is worse than a 20-row register that gets reviewed every quarter.
Worked examples: completed risk register rows
Examples are provided illustrating how to convert observations into risk scores and treatments. Use them as a reference when completing your own register.
Score rationale
- Email phishing (score 16): Phishing is a common entry point for many small and medium enterprises. Without MFA on every account, a single credential theft can compromise the entire tenancy. High likelihood, high impact.
- Unpatched file server (score 20): An unpatched server with an untested backup is the textbook ransomware scenario. The backup exists but has never been restored, so its recovery value is unknown. This is the highest-priority row in the register.
- Lost laptop (score 12): Devices leave the office. Without encryption, a lost laptop is a notifiable data breach waiting to happen under Australia’s NDB scheme.
- Vendor payroll compromise (score 15): Payroll data is among the most sensitive personal information a business holds. A vendor with no attestation and no MFA requirement is an uncontrolled risk.
- Customer database (score 15): Shared admin credentials and no audit logging mean you cannot detect unauthorised access, let alone prove it did not occur to a regulator.
Risk matrix position: The file server row (score 20) sits in the Critical zone. Email, vendor payroll, and customer database (scores 15–16) sit in High. The laptop row (score 12) is High. None of these five examples fall below High, which is typical for a first-run assessment of an SME that has not previously formalised its controls.
CISA’s guidance for small businesses identifies MFA, patching, and tested backups as the three controls that reduce the most risk per dollar spent — which is exactly what the top two rows above are targeting.

How to define likelihood and impact scores consistently
Inconsistent scoring is the most common reason a risk register loses credibility with auditors. Define the scales once, document them in the “Scoring” tab, and use them every time.
Likelihood scale (1–5)
| Score | Label | Criteria |
|---|---|---|
| 1 | Rare | No known incidents; threat requires significant capability |
| 2 | Unlikely | Occasional incidents in the industry; controls largely effective |
| 3 | Possible | Incidents occur in similar organisations; controls partially effective |
| 4 | Likely | Incidents occur regularly; controls are weak or absent |
| 5 | Almost certain | Active exploitation known; no effective control in place |
Impact scale (1–5)
Score-to-priority mapping
| Score range | Priority | Recommended action |
|---|---|---|
| 1–4 | Low | Accept or schedule treatment in next annual review |
| 5–9 | Medium | Treat within 90 days; assign owner |
| — | High | Treat within 30–—; escalate to business owner |
| — | Critical | Treat within —; consider external support |
Tolerance threshold guidance: Most Australian SMEs should set their tolerance at Medium. Any row scoring High or Critical that cannot be treated internally within the timeframe above is a trigger to escalate to an external provider. A Critical row involving personal data is also a potential NDB reporting obligation if a breach has already occurred.
Pro Tip: Run all rows in a single session with the same assessor. If two people score the same row independently and get different results, use the higher score and document the rationale. Auditors prefer conservative scoring with clear reasoning over optimistic scoring with none.
Who should run this, and how long does it take?
Recommended roles
- Project lead (0.5–1 day): coordinates the workshop, owns the register, chases evidence.
- Technical SME (0.5 day): rates likelihood and vulnerability, documents controls.
- Business owner / approver (1–2 hours): confirms scope, signs off on accepted risks.
- Evidence curator (1–2 hours): collects, names, and files supporting documents.
Typical timelines
A first-run assessment for a small business typically takes a few hours to half a day including workshop and follow-up. A quarterly refresh, once the register exists, takes one to two hours.
For a mid-market business (50–250 staff), expect a full-day workshop, two to three days of evidence gathering, and a half-day review session with the approver.
When to bring in external help
- Your business holds sensitive personal data (health, financial, legal) and has no dedicated IT security resource.
- A Critical-scored row involves a system you cannot patch or replace internally.
- You have an imminent compliance deadline (cyber insurance renewal, contract requirement, NDB investigation).
- You have experienced an incident and need forensic-quality documentation.
CISA’s role-based checklists are worth printing for the CEO, IT lead, and security manager before the workshop. They take five minutes to read and sharpen the conversation considerably.
Practicalities for small businesses: mistakes, quick wins, and escalation triggers
Common mistakes to avoid
- Making the register too long. A 100-row spreadsheet produced in a single day is almost certainly padded with low-value rows. Focus on assets that hold personal data or are critical to operations.
- Skipping the evidence folder. The register without evidence is an opinion document. Auditors and insurers expect configuration exports, test logs, and deployment reports — not just a spreadsheet.
- Scoring inconsistently. Different assessors using different mental models produce a register that cannot be compared quarter to quarter. Lock the scales before you start.
- Treating it as a one-off exercise. A risk register that is never updated is a liability, not an asset. It can be used against you in a regulatory investigation if it shows you knew about a risk and did nothing.
Quick wins that reduce the most risk
These four controls appear consistently across CISA guidance and ACSC Essential Eight recommendations as the highest-impact, lowest-cost actions for SMEs:
- Enable MFA on every account — email, cloud storage, payroll, banking. This single control blocks the majority of credential-based attacks.
- Test your backups. A backup that has never been restored is not a backup. Run a restore test quarterly and log the result in the evidence folder. Techbug’s cloud backup solutions for Queensland businesses include automated restore testing.
- Applying critical patches promptly is recommended to reduce risk. Operating system and application patches rated Critical or High should be applied within two weeks of release. Track patch status in the register.
- Enable full-disk encryption on all laptops. BitLocker (Windows) and FileVault (macOS) are built-in and free. A lost encrypted laptop is not a notifiable data breach.
What you can handle internally vs. what needs external help
Handle internally:
- Enabling MFA and disk encryption.
- Running and documenting a backup restore test.
- Applying OS and application patches.
- Completing the risk register for well-understood assets.
Escalate to an MSSP or consultant:
- Penetration testing or vulnerability scanning of production systems.
- Incident response when a breach is suspected.
- Compliance gap analysis against ISO/IEC 27001 or ACSC Essential Eight.
- Any row scored Critical that you cannot remediate with internal resources.
Escalation triggers requiring immediate external or legal help
- A ransomware message appears on any system.
- You confirm data has been exfiltrated (logs show unusual outbound transfers).
- You receive a regulatory notice or a demand related to a data breach.
- A vendor notifies you of a compromise affecting your data.
Pro Tip: Keep the contact details of your IT security provider and a cyber-insurance claims line in the evidence folder. In a ransomware event, you will not have time to search for them.
How the template maps to Australian frameworks and compliance
ACSC Essential Eight
The Essential Eight is the baseline mitigation set recommended for Australian organisations. Each control in the register maps directly to one or more Essential Eight strategies:
- Application control → controls column; maps to Essential Eight Strategy 1.
- Patch applications / patch OS → target date column; maps to Strategies 2 and 4.
- Configure Microsoft Office macro settings → controls column; maps to Strategy 3.
- User application hardening → controls column; maps to Strategy 5.
- Restrict admin privileges → controls column; maps to Strategy 6.
- MFA → controls column; maps to Strategy 7.
- Regular backups → controls column; maps to Strategy 8.
Mapping your register rows to Essential Eight maturity levels (ML1–ML3) gives you a compliance snapshot that cyber insurers and government procurement panels increasingly request.
ISO/IEC 27001:2026
The risk register structure in the template directly supports ISO/IEC 27001 Clause 6.1 (risk assessment and treatment) and Annex A controls. The asset inventory satisfies Annex A 5.9; the treatment plan satisfies Clause 6.1.3; the evidence folder supports Clause 7.5 (documented information). A cross-mapped checklist aligned to ISO/IEC 27001:2022 Annex A and CIS Controls v8 means a single completed register row can satisfy multiple framework asks simultaneously.
NIST CSF 2.0
NIST CSF 2.0 organises outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The template covers Identify (asset inventory, risk assessment) and Protect (controls, treatment plan) most directly. The evidence folder supports Detect (logging, monitoring records) and Respond (incident response plan reference).
Notifiable Data Breaches (NDB) scheme
Under Australia’s NDB scheme, organisations covered by the Privacy Act 1988 must notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach is likely to cause serious harm. A current risk register supports faster detection (you know which assets hold personal data), faster impact assessment (you have sensitivity classifications), and faster regulatory reporting (you have evidence of the controls in place at the time of the breach). For IT compliance obligations specific to Australian SMEs, the register is also the starting point for any insurer or regulator review.
Minimum evidence regulators and insurers typically request
- Current asset inventory with sensitivity classifications.
- Risk register dated within the last 12 months.
- Evidence of MFA deployment (configuration export or screenshot).
- Patch status report dated within 30 days.
- Backup test log dated within 90 days.
- Incident response plan (even a one-page version).
Glossary of terms and template completion tips
Asset: anything that has value to the business and needs protection — a server, a cloud service, a database, a staff member’s laptop, or a business process.
Threat: a potential event or action that could harm an asset. Threats are external (phishing, ransomware, physical theft) or internal (accidental deletion, misconfiguration).
Vulnerability: a weakness that makes an asset susceptible to a threat. Absent MFA is a vulnerability; unencrypted storage is a vulnerability; an unpatched OS is a vulnerability.
Control: a safeguard already in place that reduces likelihood or impact. MFA, antivirus, backups, and staff training are all controls.
Likelihood: how probable it is that a threat will exploit a vulnerability given the controls in place. Rate it on the 1–5 scale defined in the scoring section.
Impact: the consequence to the business if the threat is realised. Consider financial loss, reputational damage, operational downtime, and regulatory exposure.
Residual risk: the risk that remains after controls are applied. A score of 15 before controls might drop to 8 after MFA and patching are in place. The register should reflect residual risk, not inherent risk, once controls are documented.
Residual risk owner: the person who accepts responsibility for the residual risk. This is usually the business owner or a senior manager, not the IT lead.
Practical completion tips
- Classifying assets: start with data assets (customer records, financial data, HR files), then systems that process them, then the infrastructure those systems run on.
- Assigning owners: the owner is the person who would be most affected if the asset were compromised — usually a department head or the business owner, not IT.
- Minimal evidence examples: a screenshot of the MFA settings page, a patch report exported from Windows Update or your RMM tool, a backup restore test result saved as a PDF.
Pro Tip: Add a “Notes” column to the register for audit-friendly context — e.g., “MFA enforced via Conditional Access policy, config export attached as M365-CA-2026-03.pdf”. One sentence per row saves hours of explanation during an audit.
The reality of cyber risk assessments for Australian SMEs
Most small businesses that complete a risk assessment for the first time are surprised by two things: how quickly the high-priority rows emerge, and how achievable the top three treatments actually are. Enabling MFA, testing a backup restore, and patching a server are not complex projects. They are afternoon tasks that most businesses have simply never scheduled.
The harder truth is that the template has limits. It is a structured thinking tool, not a forensic investigation. It will not detect a compromise that has already occurred, and it will not replace legal advice if you are facing a regulatory notice. What it will do is give you a defensible, evidence-backed record of your risk posture — which is exactly what an insurer, a regulator, or a prospective enterprise client will ask for.
Techbug has worked with Australian SMEs across a range of industries, and the pattern is consistent: the businesses that fare best after an incident are the ones that had a current register, a tested backup, and a clear escalation path. The template here is designed around that pattern. It is intentionally short, because short and maintained beats long and ignored. It maps to ACSC Essential Eight and ISO/IEC 27001 because those are the frameworks Australian insurers and regulators actually reference. And it includes an evidence folder structure because that is what auditors open first.
Techbug’s team brings over 30 years of combined experience, a vendor-agnostic approach, and direct Essential Eight implementation capability. The template gets you started. The team gets you across the line when the findings are bigger than an afternoon’s work.

Techbug’s risk assessment and managed security services
Running the template yourself is the right first step. When the findings reveal gaps that need specialist remediation, or when a compliance deadline is approaching, Techbug’s IT security services for Australian businesses pick up where the template leaves off.

A Techbug risk-assessment engagement typically includes a facilitated workshop to complete the register, a prioritised remediation plan, an organised evidence folder, and optional ongoing managed IT security to close the gaps and keep the register current. The team is vendor-agnostic, Brisbane-based, and experienced with ACSC Essential Eight implementation across Australian SMEs. There are no lock-in contracts for consulting engagements.
This guide is general information only and does not constitute legal or compliance advice. Contact Techbug to discuss a tailored assessment for your business.
Sources
The following primary sources informed the template structure, scoring guidance, and framework mappings. Save these URLs in your evidence folder for audit traceability.
- How to do a cybersecurity risk assessment for a small business.
- Free Cyber Security Risk Assessment Checklist | RiskWatch
- NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide
- Cybersecurity for Small Business | Federal Trade Commission
- Cyber Guidance for Small Businesses | CISA
