You're Not Ready for Risk Assessments
practices·

You're Not Ready for Risk Assessments

Most companies run a risk assessment as a checkbox exercise — and get a document nobody uses. Here's what actually needs to be in place first for it to mean anything.

You're Not Ready for Risk Assessments

A risk assessment doesn't fail because the template was wrong. It fails because nobody in the room actually knew the answers.


The Assessment Everyone Has Done Once

Almost every company has a risk assessment sitting in a shared drive somewhere — usually built the week before an audit, filled out by whoever was available, and never opened again.

It's not that the exercise is pointless. It's that most companies attempt it before they have the raw material a real risk assessment actually requires.


What "Ready" Actually Means

1. You Know What You're Protecting

A risk assessment without an asset inventory is just a list of fears with no anchor. Before ranking risk, you need to know:

  • Where sensitive data actually lives — not where it's supposed to live
  • Which systems touch that data, including the ones nobody remembers connecting
  • Who has access, and whether that access still makes sense

2. You Have Someone Who Can Answer for Each Risk

A risk assessment is only as good as the people answering the questions. If "likelihood" and "impact" are being guessed by one person in security with no input from engineering, finance, or ops, the scores are fiction dressed up as data.

Real readiness means every major risk area has an owner who can speak to it with specifics, not assumptions.

3. You Can Tell the Difference Between a Risk and a Symptom

"We had a phishing click last quarter" is an event. "Our email filtering and training program isn't catching what it should" is the risk. Companies that aren't ready tend to list events. Companies that are ready trace events back to the gap that allowed them.

4. You're Willing to Write Down Uncomfortable Answers

The most common failure mode isn't a bad framework — it's a team that quietly softens every answer because the real answer looks bad. A risk assessment that reads as "everything is mostly fine" usually means the exercise wasn't done honestly, not that the company is actually low-risk.


What Happens When You Skip Ahead Anyway

Running the assessment before you're ready doesn't just waste time — it creates a document that actively misleads:

  • Auditors and customers treat it as evidence of a mature program, when it isn't
  • Leadership makes budget and priority decisions based on scores that don't reflect reality
  • The next assessment inherits all the same blind spots, because nothing was actually mapped the first time

At episki, the first conversation is rarely about frameworks or scoring methodology. It's about whether the basics — asset visibility, clear ownership, honest reporting — are in place yet. Everything after that gets easier once those exist.


Build the Foundation First

A risk assessment isn't the starting point of a security program. It's a checkpoint that only tells you something useful once there's a program underneath it to measure.

Skipping to the assessment doesn't save time. It just moves the real work to after you've already told everyone it was done.

Let's talk →

episki. Compliance, simplified.

Justin Leapline

About the author

Justin Leapline

episki's founder. Two decades running security and compliance programs — at BNY Mellon, GiftCards.com, and Diebold — and leading the GRC practice at TrustedSec. Fractional CISO, IANS Research faculty, board member of the CSA Pittsburgh chapter, and co-host of the Distilled Security Podcast.

Put your compliance program on autopilot

episki's agents draft policies, pull evidence, and answer questionnaires — you review and approve. 14-day free trial, no credit card required.

Continue exploring