Phase 1 · Risk Management Basics · Lesson 2 of 3
Exercise
·
25 min
·
+15 pts
In the previous lesson, you learned what risk registers are, how to score risks, and the four response options. Now you will build one from a realistic scenario.
Read the company profile below. Identify the risks that matter most, score each one, and propose a mitigation. There is no single correct answer — risk assessment is judgment, not math. But there are risks you should not miss.
How to think about risk scoring
Likelihood (1–5) measures how often you expect the risk to materialize. Impact (1–5) measures the damage when it does. The risk score (likelihood × impact) determines priority: 1–4 is low, 5–9 is medium, 10–15 is high, 16–25 is critical. A risk with likelihood 2 and impact 5 (score 10) may be more important than one with likelihood 4 and impact 3 (score 12) — the score is a starting point, not the final word.
Exercise
~25 min
Build a risk register for this business scenario
Scenario
CloudPayroll — Series C fintech expanding to APAC
CloudPayroll is a 120-person Series C fintech based in San Francisco. They provide a cloud-based payroll and benefits platform for small and mid-size businesses. They currently serve 2,000 US customers and are preparing to expand to Australia and Singapore in Q2. The company processes employee PII including Social Security numbers, bank account numbers, and salary data for all of their customers' employees.
SOC 2 Type II certified, considering ISO 27001 for APAC market credibility
All infrastructure runs on GCP (single region us-central1)
8 engineers on platform team, 35 total in engineering
Recently acquired a small EU-based benefits startup (5 employees, separate AWS infrastructure not yet integrated)
Uses a third-party payroll tax calculation API (US-based vendor, no formal vendor risk assessment completed)
No formal third-party risk management program
Security team: 1 security engineer, 1 GRC analyst (you)
Employee laptops are MDM-enrolled via Jamf, but no conditional access policies enforced
Production database backups are daily, stored in the same GCP region
No documented business continuity or disaster recovery plan
Identify 3–6 risks. For each: name it, describe it, rate likelihood and impact (1–5), choose a category, and propose a mitigation.
Risk 1
Category
Likelihood: Possible
Impact: Moderate
Risk Score: 9
Risk 2
Category
Likelihood: Possible
Impact: Moderate
Risk Score: 9
Risk 3
Category
Likelihood: Possible
Impact: Moderate
Risk Score: 9
Risk Matrix
5
4
3
2
1
1
2
3
4
5
Likelihood
Impact