Skip to content
ISMS

Risk Management in the ISMS: Evaluation, Treatment, Residual Risk – Without Excel Hell

|
|
6 min read

Most ISMS projects stumble on risk management. The idea is not hard. The trouble is that the method gets lost in Excel sheets. Nobody can track what was decided for each risk. And top management signs off on the residual risk with a PowerPoint slide, not a logged decision.

The ISO 27005 Method in Four Steps

  1. Identification: find threats, weak spots, and the assets they hit.
  2. Analysis: likelihood + impact = risk score.
  3. Evaluation: check the score against your risk acceptance criteria.
  4. Treatment: avoid, reduce, transfer, or accept.

It sounds like a straight line. It never is. In real life you go back and forth between the steps. That is just where Excel fails.

What Built-In Risk Management Gives You

  • A risk list per asset: each asset gets a risk matrix with the threat cases that matter. The BSI threat catalog backs it.
  • Scoring that follows the method: you rate likelihood and impact on a fixed scale (for example 5Γ—5). Each rating needs a reason. A "gut feeling" is marked plainly as a "qualitative evaluation".
  • A treatment plan with an owner: each risk gets a plan with measures, an owner, and a deadline. Status tracking is built in.
  • Residual risk math: once the measures are in place, the tool shows the risk that is left. Top management signs off on it digitally with eIDAS signatures, and that sign-off is on record.
  • Audit trail: each change to a risk's status and each sign-off is stored with who did it and when.

Why "Let AI Rate the Risk" Does Not Work Here

In 2026 there is a loud market for "AI-based risk scoring". We use AI in several places. But we chose not to use it to score risks. There are three reasons:

  1. Who signs off: legal and ethical duty for accepting a risk lies with top management. An LLM can't take on that duty.
  2. Context: the same tech risk has a different impact in a regulated field than in one that is not. An LLM does not know enough about that context.
  3. Same input, same result: a risk must get the same rating today, tomorrow, and next year. LLM output shifts from run to run.

Where AI does help: it fills in typical threats per asset (for DB servers, web apps, and endpoints). It suggests templates for measures. And it writes risk text for reports.

Three Common Pain Points and How We Solve Them

1. "We Have 200 Risks in Excel and Nobody Looks at Them Anymore"

Our answer: bulk import from Excel with a mapping wizard. Then each risk gets an owner, who gets reminder mails. You filter by severity, status, or owner. No more scrolling through 200 rows of Excel.

2. "We Don't Know If the Risk Is Really Smaller After the Measures"

Our answer: residual risk math with a clear formula. Risk before the measures Γ— how well the measures work = residual risk. How well they work is checked when the measures are reviewed.

3. "Top Management Never Signed Off on the Residual Risk"

Our answer: a digital sign-off flow with an eIDAS-compliant signature. The audit trail holds the proof. No drama at the audit about a chain of mails as "proof".

How It Links to Other Modules

  • Asset management: risks hang on assets. How critical an asset is feeds into its risk rating.
  • Action plan: each treatment decision creates tasks in action tracking.
  • Review cycle: risks are rated again at least once a year.
  • BCDR: a critical risk starts a new BCDR plan on its own.
  • Audit export: a risk report with the treatment plan and the signed-off residual risk, ready for the ISO 27001 auditor.

Conclusion

Risk management is not a tool problem. It is a matter of sticking to a method and keeping records others can follow. SecTepe.Core gives you the tools that enforce the method. "We did a risk assessment two years ago" turns into ongoing work you can audit. Top management gets a real basis for its decisions. The auditor gets a full file.