Cyber risk assessments
A cyber risk assessment is a structured evaluation that scores your organization's cyber risks based on the assets, threats, and vulnerabilities in scope. The assessment workflow guides you through four steps — Details, Scope, Scoring, and Results — and produces a scored picture of inherent or residual risk across your asset portfolio.
Assessments can only be edited before they are approved. Once approved, an assessment is read-only.
Cyber risk assessments list
The Cyber risk assessments page shows all assessments in your organization and their current status.
Assessment statuses
| Status | Description |
|---|---|
| Draft | The assessment has been created but not yet progressed to scoping. |
| Scoping | The assessment is in the scoping step. |
| Scoring | The assessment is in the scoring step. |
| Overdue | The assessment has passed its due date without being approved. |
| Approved | The assessment has been approved and is read-only. |
Creating a cyber risk assessment
To create a cyber risk assessment, perform the following steps:
-
From the Platform home page (www.diligentoneplatform.com), select the Asset Manager app to open it.
If you are already in Diligent One, you can use the left-hand navigation menu to switch to the Asset Manager app.
- In the left navigation, select Cyber Risk Management > Cyber risk assessments.
- Select Create new cyber risk assessment.
- Complete each step of the assessment workflow using the tabs at the top of the page. See the sections below for details on each step.
Step 1: Details
The Details tab captures the assessment metadata and configuration.
| Field | Description |
|---|---|
| Assessment method | Qualitative assessment. Risks are scored using Impact × Likelihood, where Impact is determined by asset criticality and Likelihood by Vulnerability severity × Threat severity. This produces a score from 1 to 125, which is mapped to risk bands (Very low, Low, Medium, High, Very high). This field is read-only. |
| Assessment type | Select whether the assessment scores contribute to the Inherent or Residual risk score. Inherent scores reflect risk before controls are applied; residual scores reflect risk after controls. |
| Assessment instructions | Required. Enter the background and scope for this assessment. Use this field to describe the purpose, boundaries, or any special context for reviewers. The AI scoring agent also uses these instructions when scoring scenarios. |
| Attachments | Optional. Upload supporting documents such as penetration test results, breach reports, or other security documents. Supported formats: PNG, JPG, PDF, XLS. Maximum file size: 17 MB. |
Select Move to scoping to advance to the next step, or select the Scope tab directly.
Step 2: Scope
The Scope tab is where you select the assets to include in this assessment. All related data — cyber risks, threats, vulnerabilities, controls, and org units — is pre-populated based on the relationships of your selected assets.
- Select the assets to include using the Assets tab. Use Filter and Columns to refine the asset list.
- Review the pre-populated items on the Cyber risks, Threats, Vulnerabilities, and Controls tabs. These items are automatically included based on your selected assets' relationships.
The summary card at the top of the Scope tab shows how many items are included in this assessment out of the total available, for example 10 / 20 Cyber risks.
Note
After the initial release, you will be able to exclude individual cyber risks, threats, vulnerability categories, and controls from the scope without removing the associated assets.
Select Move to scoring to advance to the next step, or select the Scoring tab directly.
Step 3: Scoring
The Scoring tab is where you score the cyber risk scenarios in this assessment. Each cyber risk can have multiple scenarios, and each scenario is scored individually.
Scoring formula
The cyber risk score for each scenario is calculated as follows:
- Cyber risk score = Impact × Likelihood
- Impact = Asset criticality
- Likelihood = Threat severity × Vulnerability severity
Scores range from 1 to 125 and are mapped to risk bands. Select View scoring scales to see the full scoring scale reference.
AI scoring
Select Start AI scoring to have the Diligent Scoring AI automatically score all scenarios in the assessment. The AI uses the assessment instructions and uploaded files, and analyzes the following to determine threat severity and vulnerability severity for each scenario:
- Threat category and vulnerability category
- Controls linked to the asset
- Findings and CVEs
Once AI scoring is complete, each scenario displays a Confidence score indicating how confident the AI is in its assessment. Review any low-confidence scenarios and override the AI scores if needed.
Overriding AI scores
To review or override an AI score for a specific scenario:
- Select the scenario name to open it.
- Review the scoring rationale generated by the AI.
- Adjust the Threat severity, Vulnerability severity, or Impact values as needed. The cyber risk score updates automatically.
- Select Save changes.
Aggregation method
Select how the scores for multiple scenarios under a single cyber risk are aggregated:
- Highest: The highest scenario score is used as the cyber risk score.
- Average: The average of all scenario scores is used.
Select Review results to advance to the final step, or select the Results tab directly.
Step 4: Results
The Results tab shows the scored output of the assessment.
- Cyber risks heat map: Shows all in-scope cyber risks plotted by Impact vs Likelihood. Toggle between Inherent and Residual views.
- Assets by cyber risk score: Donut chart showing the distribution of in-scope assets by risk score range.
- Cyber risks table: Lists each cyber risk with its Impact, Threat severity, Vulnerability severity, Likelihood, Cyber risk score, and a link to start a mitigation plan.
- Assets table: Lists each in-scope asset with its Cyber risk score, Criticality level, Confidentiality, Integrity, and Availability ratings.
Approving an assessment
When you are satisfied with the scoring results, select Approve assessment to finalize the assessment. Once approved:
- The assessment status changes to Approved.
- The assessment becomes read-only and cannot be edited.
- The scores contribute to the overall cyber risk posture shown on the Overview page.
Starting mitigation plans from results
From the Results tab, select + Mitigation plan next to any cyber risk to create a mitigation plan for that risk. See Mitigation plans for more information.