Skip to content
Atlas
GET IN TOUCH

B://ASSESS21Risk Management

Know which risks
are worth carrying.

Technology risk management identifies what could go wrong, how likely it is, what it would cost, and which risks are worth treating rather than accepting. It is for boards and executives who need to make an informed decision about what they are exposed to.

Every organisation accepts technology risk. Most do it accidentally, without ever deciding to.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Risk register

    Identified, described, and rated on likelihood and impact, in business terms rather than technical ones.

  • 02

    Treatment options

    Mitigate, transfer, avoid, or accept, each costed, so the choice is a decision rather than a default.

  • 03

    Ownership

    A named owner and a review date per risk, which is what keeps a register alive rather than archived.

  • 04

    Board reporting

    A view of exposure a director can interrogate without needing a technical translator in the room.

Scope, assess, report, support

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Scope

    We agree what is being examined and what a useful answer looks like, so the work is not open-ended.

  2. 02Weeks 2 – 3

    Assess

    Evidence gathered from your systems and your people, because the documented process and the real one rarely match.

  3. 03Week 4

    Report

    Findings written for a decision maker: what is true, what it means, and what we would do about it, ranked.

  4. 04As needed

    Support

    We can hand the report over and step back, or stay and deliver the remediation. Both are normal.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is risk management?

Technology risk management identifies what could go wrong, how likely it is, what it would cost, and which risks are worth treating rather than accepting. It is for boards and executives who need to make an informed decision about what they are exposed to.

02What is the difference between risk management and a risk assessment?

A risk assessment is a point-in-time measurement of where you stand, usually against a framework, producing a ranked list of findings. Risk management is the ongoing discipline: maintaining the register, owning each risk, reviewing it, and reporting it upward. The assessment tells you the score. Management is what stops the score drifting back down six months later.

03What technology risks should a board actually be worried about?

In our experience, four recur. A cyber incident that stops trading, most often ransomware or business email compromise. Key person risk, where one individual holds knowledge or access nobody else has. Concentration risk, where a single supplier or system has no alternative. And compliance exposure, where an obligation is being carried without evidence. Everything else tends to be a variation on one of those.

04Is it acceptable to simply accept a risk?

Yes, and it is often the right answer. Accepting a risk knowingly, with the cost understood and a named owner, is a legitimate decision. What causes damage is accepting risk by accident, where nobody weighed it and nobody can say who decided. The register exists to move risks from the second category into the first.

05Does cyber insurance cover this risk for us?

Partially, and it is worth reading the policy closely rather than assuming. Cyber cover typically transfers some of the financial consequence, but it does not restore your systems, protect your reputation, or satisfy a regulator. Most policies also carry conditions such as multi-factor authentication and tested backups, and a claim can be declined where those conditions were not actually met. Insurance is one treatment option among several, not a substitute for the others.

06How often should the risk register be reviewed?

Quarterly for the register as a whole, and immediately whenever something material changes: a new system, an acquisition, a significant supplier change, or an incident. A register reviewed once a year is a compliance artefact rather than a management tool.

07How much does risk management cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with risk management?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver risk management alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to use Atlas for the work the report recommends?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Do you work with organisations outside Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who does the assessment, and who presents the findings?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What do we actually receive at the end?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services