A cyber security risk assessment identifies the digital and data-related threats facing a UK business — including data breaches, ransomware, phishing attacks, and insider threats — and determines what controls are needed to reduce those risks to an acceptable level. Under UK GDPR Article 32, data controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. For operators of essential services and digital service providers, the Network and Information Systems Regulations 2018 impose additional mandatory security and incident reporting obligations. Every UK business that processes personal data or relies on IT systems to deliver its services must conduct a cyber security and data protection risk assessment.
Why Cyber Security Risk Assessment is a Legal Requirement
UK General Data Protection Regulation (UK GDPR)
Under UK GDPR Article 32, data controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. This obligation explicitly requires a risk-based approach: you must assess the likelihood and severity of risks to individuals' rights and freedoms, and put controls in place proportionate to those risks. Article 5(1)(f) reinforces this by requiring that personal data be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (the integrity and confidentiality principle).
The Information Commissioner's Office (ICO) has made clear that a cyber security risk assessment is a mandatory part of demonstrating compliance with Article 32. Failure to conduct such an assessment — or failure to implement its findings — is evidence that an organisation has not met its security obligations, and will be a significant factor in any regulatory action following a breach.
Network and Information Systems Regulations 2018 (NIS Regulations)
The Network and Information Systems Regulations 2018 transpose the EU NIS Directive into UK law and impose specific security and incident reporting obligations on operators of essential services (energy, transport, health, water, digital infrastructure) and relevant digital service providers (online marketplaces, online search engines, cloud computing services). Under Regulation 10, operators of essential services must take appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems. Under Regulation 16, relevant digital service providers have a parallel duty. Both categories of organisation must identify and assess security risks, implement security measures, and report significant incidents to the relevant competent authority.
Computer Misuse Act 1990
While not a regulatory framework, the Computer Misuse Act 1990 creates criminal offences for unauthorised access to computer systems (Section 1), unauthorised access with intent to commit further offences (Section 2), and unauthorised acts impairing the operation of a computer (Section 3). Organisations that fail to secure their systems against known threats may face civil liability for negligence if a breach occurs, and directors may face personal liability if there is evidence of wilful neglect.
What Does a Cyber Security Risk Assessment Cover?
A cyber security and data protection risk assessment must identify and evaluate all categories of digital risk that could affect the organisation's data, systems, and operations. The scope typically includes:
- Data protection risks — unauthorised access to personal data, data breaches, accidental disclosure, inadequate encryption, weak access controls, insecure data transfers, data loss through hardware failure or ransomware.
- Network security risks — external attacks (DDoS, SQL injection, cross-site scripting), internal threats (disgruntled employees, accidental misconfiguration), weak firewall rules, unpatched software vulnerabilities, unsecured Wi-Fi networks.
- Endpoint security risks — malware and ransomware infections on laptops, desktops and mobile devices, lost or stolen devices containing unencrypted data, unauthorised USB devices, lack of remote wipe capability.
- Access control risks — weak passwords, lack of multi-factor authentication, excessive user privileges (users with admin rights who do not need them), failure to revoke access when staff leave, shared login credentials.
- Third-party risks — insecure processors or cloud providers, inadequate data processing agreements, lack of assurance over third-party security practices, supply chain attacks.
- Human factors — phishing susceptibility, lack of security awareness training, poor password hygiene, social engineering, insider threats.
- Business continuity risks — lack of regular backups, untested disaster recovery plans, reliance on single points of failure, no incident response plan.
The Five-Step Cyber Security Risk Assessment Process
Step 1: Identify Digital Assets and Data Flows
Begin by mapping what you hold and where it flows. Identify all systems that store, process or transmit personal data or business-critical information: customer databases, HR systems, email servers, cloud storage (Google Drive, Dropbox, OneDrive), CRM systems, payment processing systems, backup systems. Identify the categories of personal data held: names, addresses, financial information, health data, criminal records, biometric data. Map how data enters the organisation (online forms, telephone, email, third parties), how it moves internally (email attachments, shared drives, API integrations), and how it leaves (to processors, to clients, through third-party analytics tools).
Step 2: Identify Cyber Security Threats and Vulnerabilities
For each asset and data flow, identify the threats that could compromise its confidentiality, integrity or availability. Common threats include: phishing emails targeting staff, ransomware delivered through email attachments or compromised websites, brute-force attacks on weak passwords, SQL injection attacks on web applications, insider threats from disgruntled employees, accidental data disclosure through misdirected emails, physical theft of laptops or USB drives, DDoS attacks disrupting service availability, man-in-the-middle attacks on unencrypted connections.
Then identify the vulnerabilities that make those threats realistic: outdated software with known security flaws, default or weak passwords, lack of encryption on devices or in transit, inadequate firewall rules, no multi-factor authentication, inadequate staff training on phishing recognition, no logging or monitoring of access to sensitive data, lack of a written information security policy.
Step 3: Assess the Likelihood and Impact
For each combination of threat and vulnerability, estimate the likelihood of the threat being realised (low, medium, high) and the potential impact on the organisation and on individuals if it occurs. Impact should consider the harm to data subjects (financial loss, identity theft, distress, reputational damage), harm to the organisation (regulatory fines, loss of customer trust, business disruption, legal claims), and whether the breach would trigger mandatory reporting under UK GDPR Article 33 (breach notification to the ICO within 72 hours) or Article 34 (notification to affected individuals).
UK GDPR does not prescribe a particular risk assessment methodology, but the ICO recommends considering both the likelihood and severity of harm. A high-likelihood, high-impact risk (such as a database containing unencrypted customer payment card details) demands immediate action. A low-likelihood, low-impact risk (such as a single paper file temporarily misfiled) may require only routine controls.
Step 4: Determine and Implement Controls
Apply the principle of defence in depth: multiple layers of control so that if one fails, others remain. Controls should address technical measures, organisational measures, and human factors. Common technical controls include encryption of data at rest and in transit (using TLS 1.2 or higher for data in transit, AES-256 for data at rest), multi-factor authentication on all systems holding personal data, regular software patching and updates, firewall and intrusion detection systems, endpoint protection (antivirus, anti-malware), secure backup and disaster recovery systems tested at least annually, access controls based on the principle of least privilege, logging and monitoring of access to sensitive data.
Organisational controls include a written information security policy, data protection impact assessments (DPIAs) for high-risk processing under UK GDPR Article 35, data processing agreements with all processors under UK GDPR Article 28, a clear incident response plan, regular reviews of user access rights, secure disposal of hardware and paper records, and defined responsibilities for information security.
Human factors controls include mandatory cyber security awareness training for all staff (covering phishing recognition, password hygiene, secure handling of data), simulated phishing exercises to test and reinforce training, a clear acceptable use policy for IT systems, and a whistleblowing mechanism for reporting security concerns.
Step 5: Document, Review and Update
Under UK GDPR Article 5(2) (the accountability principle), you must be able to demonstrate compliance with the security requirements. This means documenting the cyber security risk assessment, the controls implemented, the rationale for accepting any residual risks, and evidence that controls are operating effectively (such as logs of security training completion, records of software updates, results of penetration testing). The assessment must be reviewed whenever there is a change in processing activities, a new system is introduced, a data breach occurs, or at least annually. Under the NIS Regulations, operators of essential services and digital service providers must review and update their risk assessments regularly and after any significant incident.
Common Cyber Security Threats Facing UK Businesses
Phishing and Social Engineering
Phishing remains the most common attack vector. According to the UK government's Cyber Security Breaches Survey 2024, 84% of businesses reported having experienced a phishing attempt in the past 12 months. Attackers impersonate trusted entities (banks, HMRC, suppliers, senior managers) to trick staff into disclosing credentials, clicking malicious links, or transferring funds. Spear-phishing targets specific individuals with tailored messages. Defences include email filtering, staff training, multi-factor authentication (so that even if credentials are compromised, the attacker cannot log in), and simulated phishing to test awareness.
Ransomware
Ransomware encrypts an organisation's files and demands payment for the decryption key. The National Cyber Security Centre (NCSC) reports that ransomware attacks on UK organisations increased significantly in 2023, with attackers increasingly targeting small and medium-sized businesses. Once inside a network, ransomware can spread laterally, encrypting backups and file shares. Defences include offline or immutable backups, endpoint protection, network segmentation, and an incident response plan that includes isolating infected systems immediately. The NCSC's guidance is clear: do not pay the ransom — it funds further attacks and there is no guarantee data will be recovered.
Insider Threats
Insider threats arise from current or former employees, contractors, or business partners who misuse their access to data. This may be malicious (stealing customer data to sell, sabotaging systems after dismissal) or accidental (misconfiguring access controls, emailing data to the wrong recipient). Defences include the principle of least privilege (users only have access to the data they need for their role), logging and monitoring of access to sensitive data, background checks for roles with access to sensitive systems, timely revocation of access when staff leave, and data loss prevention (DLP) tools that block the transfer of sensitive data outside the organisation.
Unpatched Software Vulnerabilities
Software vulnerabilities are discovered constantly. When a vendor releases a security patch, attackers reverse-engineer it to identify the vulnerability, then scan the internet for unpatched systems. The WannaCry ransomware attack in 2017 exploited a Windows vulnerability for which a patch had been available for two months. Defences include a formal patch management process with defined timelines (critical patches within 14 days, high-priority patches within 30 days), automated patching where possible, and maintaining an inventory of all software and hardware so that nothing is overlooked.
Weak Passwords and Authentication
Default passwords, simple passwords (Password123), and password reuse across multiple systems remain widespread. The NCSC's guidance recommends passwords of at least 12 characters, use of password managers, and multi-factor authentication on all systems that support it. Multi-factor authentication (MFA) reduces the risk of account compromise by 99% according to Microsoft research, because even if a password is stolen, the attacker cannot log in without the second factor (a code sent to a phone, a biometric scan, or a hardware token).
Data Protection Impact Assessments (DPIAs) and Cyber Security
Under UK GDPR Article 35, a Data Protection Impact Assessment (DPIA) is mandatory before beginning any type of processing that is likely to result in a high risk to individuals' rights and freedoms. High-risk processing includes large-scale processing of special category data (health, biometric, criminal records), systematic monitoring of publicly accessible areas (CCTV), or use of new technologies such as AI profiling. A DPIA must describe the processing, assess its necessity and proportionality, and assess the risks to individuals. Critically, the DPIA must identify measures to mitigate those risks — which means conducting a cyber security risk assessment as part of the DPIA process. The ICO expects to see evidence of encryption, access controls, pseudonymisation, regular testing, and a clear incident response plan within a DPIA.
Cyber Essentials and Cyber Essentials Plus
Cyber Essentials is a UK government-backed certification scheme that sets out five basic technical controls every organisation should have in place: secure configuration of devices and software, secure internet gateways (firewalls), access control and administrative privilege management, malware protection, and patch management. Cyber Essentials Plus includes the same requirements but adds independent verification through technical testing. While not a legal requirement for most organisations, Cyber Essentials is mandatory for organisations bidding for central government contracts involving the handling of sensitive information. Many insurers now require Cyber Essentials certification as a condition of cyber insurance cover. Achieving Cyber Essentials demonstrates that an organisation has conducted a basic cyber security risk assessment and implemented proportionate controls.
What Happens if You Suffer a Data Breach?
Under UK GDPR Article 33, if a personal data breach is likely to result in a risk to individuals' rights and freedoms, the data controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Under Article 34, if the breach is likely to result in a high risk to individuals, the controller must also notify the affected individuals without undue delay. Failure to report a notifiable breach is itself a breach of UK GDPR and can result in a fine.
The ICO has the power to impose administrative fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious infringements. Under UK GDPR Article 83(4), failure to implement appropriate technical and organisational measures (the Article 32 security obligation) can result in a fine of up to £8.7 million or 2% of turnover. In determining the level of fine, the ICO considers the nature, gravity and duration of the infringement, whether it was intentional or negligent, what action the controller took to mitigate harm, and the degree of cooperation with the ICO. Evidence that an organisation had conducted a thorough cyber security risk assessment and implemented its findings will significantly reduce the penalty. Conversely, evidence that no assessment was conducted, or that known risks were ignored, will increase it.
According to ICO data for 2023, the average fine for a data security breach where the organisation had failed to implement appropriate technical and organisational measures was £380,000. High-profile cases have resulted in multi-million pound fines: British Airways was fined £20 million in 2020 for a breach affecting 400,000 customers, following an investigation that found inadequate security practices.
Practical Cyber Security Controls for Small Businesses
Small businesses often believe cyber security is beyond their budget or expertise. In reality, many effective controls are low-cost or free. The NCSC's Small Business Guide recommends the following baseline measures, all of which address risks identified in a typical cyber security risk assessment:
- Use strong, unique passwords — at least 12 characters, stored in a password manager (free options include Bitwarden, KeePass). Enable multi-factor authentication on email, cloud storage, and any system holding customer data.
- Keep software up to date — enable automatic updates on all devices. Remove software that is no longer supported by the vendor (such as Windows 7, which no longer receives security patches).
- Protect against malware — use antivirus software on all devices (Windows Defender is built into Windows 10 and 11 and is effective for most threats). Do not disable it. Train staff to recognise suspicious emails and not to click links or open attachments from unknown senders.
- Back up your data — follow the 3-2-1 rule: three copies of data, on two different types of media, with one copy stored offsite or offline. Test that backups can be restored. Cloud backup services (Backblaze, Carbonite) are inexpensive and automate the process.
- Control who has access — create separate user accounts for each person. Do not share passwords. Do not give people administrative privileges unless they need them. Remove access immediately when someone leaves.
These controls address the majority of threats facing small businesses and satisfy the basic requirements of UK GDPR Article 32 for many low-risk processing activities.
Cyber Security Risk Assessment Worked Example: Small Accountancy Practice
A sole practitioner accountant processes personal and financial data for 80 clients. Data is stored on a laptop and backed up to Google Drive. The accountant works from home and occasionally from client premises.
Assets and data: Laptop (Windows 11), Google Drive account, client files (names, addresses, National Insurance numbers, bank statements, tax returns). Special category data: none routinely processed, but some clients have disclosed health conditions affecting benefits claims.
Threats identified: Laptop theft from car or client premises. Phishing email leading to Google account compromise. Ransomware infection via malicious email attachment. Accidental email to wrong recipient. Loss of data if laptop hard drive fails and backup is not current.
Vulnerabilities: No full-disk encryption on laptop. No multi-factor authentication on Google account. No anti-phishing training. No written policy on checking recipient before sending sensitive emails. Backup to Google Drive is manual, not automatic — accountant forgets to back up weekly as intended.
Risk assessment: Laptop theft: medium likelihood (works in various locations), high impact (all client data lost or exposed) = high risk. Google account compromise: medium likelihood (phishing common), high impact (access to all client files) = high risk. Ransomware: low likelihood (Windows Defender active, accountant rarely opens attachments from unknown senders), medium impact (data encrypted, but can restore from backup if backup is current) = medium risk. Accidental disclosure: low likelihood (small number of emails sent), low impact (typically one client affected, not large-scale breach) = low risk. Backup failure: medium likelihood (manual process, sometimes forgotten), high impact (permanent data loss) = high risk.
Controls implemented: Enable BitLocker full-disk encryption on laptop (free, built into Windows 11 Pro). Enable multi-factor authentication on Google account using the Google Authenticator app. Enrol in NCSC free training module on phishing recognition. Implement policy: when attaching client data to email, type recipient address rather than auto-selecting, and double-check before sending. Move to automatic backup: install Google Drive desktop app so that files sync continuously rather than relying on manual upload. Document these controls and set a calendar reminder to review the assessment annually and after any security incident.
Residual risk: With these controls, the risk of data loss from laptop theft is reduced to low (data encrypted). The risk of account compromise is reduced to low (MFA in place). Backup failure risk is reduced to low (automated sync). Total cost: £0 (all tools free or already owned). Time to implement: approximately 2 hours. The accountant can now demonstrate compliance with UK GDPR Article 32 and has documentary evidence to present to the ICO if required.
The Role of AI in Cyber Security Risk Assessments
AI-powered tools are increasingly used to identify and assess cyber security risks. Machine learning algorithms can analyse network traffic to detect anomalies that may indicate an attack, scan email for phishing indicators, and identify unusual user behaviour that may signal account compromise. For small and medium-sized businesses, AI-generated risk assessments can provide a structured starting point: the business describes its IT environment and data processing activities, and the AI generates a risk assessment document identifying likely threats, vulnerabilities and controls specific to that context. This is materially faster than starting from a blank template, and reduces the risk of overlooking common threats. However, the business must still review the AI output, confirm it reflects the actual environment, and implement the recommended controls. The legal duty under UK GDPR Article 32 remains with the data controller and cannot be delegated to an algorithm.
Also see: The Ultimate Guide to Risk Assessment in the UK · Do I Need a Risk Assessment? · Risk Assessment Legal Requirements · AI Risk Assessment Generator
