glacierr
get in touch
typical engagement
scoped to you · fixed fee

service · 02risk · controls · gaps · roadmap

cyber risk assessment

know which risks matter most.

We assess your cyber risk exposure and how well your existing controls hold up, then connect what we find to business impact — so decision-makers know which risks matter, why they matter, and what to do next.

risk register control gaps business impact roadmap with owners fixed fee
▼
risk

technical and non-technical, tied to business impact

gaps

control weaknesses against an agreed scope and framework

plan

a prioritised roadmap with owners and timeframes

01what changes for you

what changes for you.

Risk in business terms, controls checked against evidence, and priorities you can defend in front of the board.

01

risk in business terms

Risks tied to the critical assets and services they put at stake.

02

controls checked against evidence

Policies, processes and controls assessed on evidence, not assumption.

03

gaps made visible

Control deficiencies and emerging threats your current measures miss.

04

priorities you can defend

Findings rated by likelihood, impact, existing controls and residual exposure.

05

a roadmap with owners

Recommendations with owners, timeframes, dependencies and next steps.

06

decisions for leadership

Material risks summarised for the board and senior stakeholders.

02what we typically find

a register and a stack of controls. rarely a line between them.

Most organisations have a risk register and a stack of controls. Far fewer can say which risks would actually hurt the business, or whether the controls address them. This is a structured consultancy engagement — not a penetration test, managed security service or automated vulnerability scan.

43%
of UK businesses reported a breach or attack in the last 12 months
31%
have a board member responsible for cybersecurity
15%
formally review risks from immediate suppliers

03our approach

five stages, one risk picture.

Five stages, each with a gate you sign — from understanding the risk to a roadmap with owners. Senior consultants only.

01

understand the risk

02

assess the controls

03

identify the gaps

04

prioritise the risks

05

define the roadmap

04what you get

what you get.

Tailored to the agreed scope, frameworks and priorities.

05who it's for

who it's for.

ciso & security

An independent view of control effectiveness.

cio & it directors

Priorities that fit the technology plan.

chief risk officer

Cyber risk in the enterprise risk language.

senior stakeholders

Which risks matter, and what to decide.

Sources: DSIT, Cyber Security Breaches Survey 2025/26 (30 April 2026).

shall we get on with it?

Scoped to your organisation, frameworks and priorities — fixed scope, fixed fee. We've sat inside breach rooms; we know which risks actually get used.

also from glacierr.