Only around 30% of UK businesses conduct a cyber security risk assessment, according to the UK Cyber Security Breaches Survey 2025/26. That leaves a basic management question unanswered in many boardrooms: which systems, suppliers and business processes would cause the greatest harm if they failed or were compromised?
For an East Midlands SMB, the answer rarely sits only inside a server room. It may involve Microsoft 365 identities, an Azure workload, a finance mailbox, a manufacturing supplier, a logistics platform or an AI tool handling customer information. A practical security risk assessment turns those dependencies into decisions, owners and deadlines.
What Security Risk Assessment Really Means for UK Businesses
A security risk assessment is a business decision-making exercise, not a technical audit dressed up in formal language. It identifies what matters, what could harm it, how exposed it is, and which action deserves attention first.
A useful working definition is simple:
A security risk assessment identifies important business assets, maps credible threats and weaknesses to those assets, evaluates likelihood and impact, and records the treatment decision.
The deliverable should be a prioritised risk register connected to outcomes such as lost orders, operational downtime, contractual failure, regulatory scrutiny, supplier disputes or reputational damage. It shouldn't be a 60-page report that directors approve and nobody opens again.
What it isn't
A penetration test tries to demonstrate whether selected weaknesses can be exploited. A vulnerability scan identifies technical weaknesses across defined systems. An IT health check reviews the general condition of technology, support arrangements and controls. Each can provide useful evidence, but none replaces the assessment.
The NCSC risk assessment and management method sets out a structured process involving scope and method, asset analysis, threat analysis, vulnerability assessment and a risk register. Those stages help a business move from isolated technical observations to a defensible treatment decision.
The board also needs the legal and commercial context. Under UK GDPR, organisations remain accountable for how they protect personal data. Contracts may require particular controls or assurance evidence, while directors need enough clarity to decide whether to reduce, transfer or accept a risk.
The rest of this guide treats assessment as a repeatable management loop, with technology supplying evidence and directors making the final risk decisions.
Why Security Risk Assessment Matters for SMBs Right Now
Only 30% of UK businesses conducted a cyber security risk assessment, while 43% reported a breach or attack in the previous 12 months, according to the Cyber Security Breaches Survey 2025/26. That gap matters at board level. Directors cannot decide which risks to fund, accept or transfer if exposure has not been recorded against business outcomes.
The cost is easy to underestimate. UK businesses reported an average self-reported mean cost of £1,600 for their most disruptive breach or attack in the previous 12 months, rising to £3,550 when responses of £0 are excluded, according to the Cyber Security Breaches Survey 2025. For a manufacturer, logistics firm or professional services practice, the recovery invoice may be only one part of the loss. Lost orders, operational downtime, management time, contractual failure and customer reassurance can carry greater consequences.

East Midlands SMBs usually have lean IT teams and closely connected suppliers. An assessment must therefore examine Microsoft 365 and Azure exposure, identity permissions, remote access, supplier connections and the information moving through those services. A checklist that ignores those dependencies gives directors false confidence.
Why annual paperwork fails
An annual document becomes stale after a licence change, supplier integration or new workflow. Microsoft 365 permissions can shift, and staff may enter business information into an AI tool before anyone has assessed the resulting exposure.
The NCSC Cyber Assessment Framework guidance summarises 204 nationally significant cyber incidents in the year to September 2025, compared with 89 recorded in the previous period. The answer is not a longer report. Reassess after material change, assign owners, and keep a prioritised register that supports board decisions on downtime, customer commitments, regulatory scrutiny and supplier disputes.
Comparing Common Security Risk Assessment Frameworks
Frameworks provide structure, but they don't make judgement calls for directors. The right choice depends on customer expectations, regulation, supplier relationships and the maturity your team can maintain.
| Framework | Origin | Best Fit For UK SMB | Typical Effort (25-75 seats) | Primary Output |
|---|---|---|---|---|
| ISO 27005 | International ISO information security risk management guidance | Businesses facing ISO-led customer or tender requirements | High, particularly when integrated with an ISO management system | Formal risk methodology, treatment records and evidence |
| NIST SP 800-30 | US National Institute of Standards and Technology | UK SMBs reporting to a US parent or customer | Moderate to high, depending on required documentation | Structured assessment of threats, vulnerabilities, likelihood and impact |
| NCSC Cyber Assessment Framework | UK National Cyber Security Centre | Regulated organisations and critical suppliers needing governance assurance | Moderate to high, with evidence gathering across outcomes | Structured governance and cyber-resilience assessment |
| Cyber Essentials and Cyber Essentials Plus | UK government-backed scheme | SMBs supplying government or larger organisations, and businesses needing a practical baseline | Lower for the basic scheme, higher for Plus due to independent technical verification | Baseline control evidence, with deeper technical verification for Plus |
The National Risk Register 2025 places UK security risk assessment in a broad national prioritisation context, covering 89 risks across 9 risk themes. That perspective matters. A business shouldn't reduce risk management to patching laptops while ignoring suppliers, premises, people and critical processes.
My recommendation is direct:
- Use Cyber Essentials as the floor if your SMB trades with government or larger suppliers. It gives the business a practical baseline and a clear way to discuss common controls.
- Choose the NCSC CAF when you're regulated, support an essential service or sit inside a critical supplier chain. The Cyber Assessment Framework is particularly useful when directors need a governance view rather than a list of technical findings.
- Use ISO 27005 when a customer, tender or management system requires it. Don't adopt it merely to create ceremony.
- Use NIST SP 800-30 when a US parent company mandates alignment. It's a sensible fallback, but UK organisations should still address UK GDPR, UK contractual duties and NCSC expectations.
The framework is scaffolding. The value comes from repeating the process and acting on its decisions.
Running a Security Risk Assessment Step by Step
Start with a written scope statement. List the systems, data, sites, suppliers, Microsoft 365 tenants and Azure subscriptions under review, then have the board or accountable director approve it. A vague scope creates a confident-looking result that excludes the systems most likely to matter.
Build the evidence before scoring
Identify and classify assets next. Include Microsoft 365 sensitivity labels, on-premises file shares, endpoints, line-of-business SaaS and unmanaged shadow IT. Record who owns each asset, what process depends on it, what data it holds and what happens if it becomes unavailable.
Then assess vulnerabilities across the actual attack surface:
- Endpoints: Review patching, encryption, local administrator access and protection status.
- Identity: Examine Entra ID accounts, privileged roles, inactive users and Conditional Access policies.
- Email: Check authentication controls, forwarding rules, shared mailboxes and phishing resilience.
- Cloud: Review Microsoft 365 and Azure configuration, logging, backup arrangements and external access.
- Suppliers: Document connections, data flows, support accounts and contractual security obligations.
A vulnerability assessment can supply technical findings, but the assessment must connect each finding to an asset and business consequence.
Turn findings into decisions
Map realistic threats to assets. A finance mailbox may face phishing and unauthorised payment fraud. A production planning system may face ransomware or cloud outage. A supplier account may create a route into customer or operational data.
Score likelihood and impact using a consistent method, evaluate existing controls, and record the residual risk after those controls. The final risk register needs a description, evidence, owner, treatment, target date and acceptance authority. Finish with a treatment plan and set the first reassessment date before the meeting ends.
For teams reviewing information flows and disposal alongside cyber controls, the Reworx Recycling data risk guide provides useful context on how data risk continues beyond the live IT environment.
The NCSC-aligned sequence is practical because each stage produces something usable: scope register, asset record, threat and vulnerability evidence, scored risks, treatment actions and residual-risk decisions.
A Sample Risk Register and Checklist in Practice
A 45-person manufacturer in the East Midlands might run Microsoft 365 across three sites, connect its production operation to a logistics supplier, use an external payroll provider and rely on a managed service provider for infrastructure support. Its first assessment shouldn't begin with a generic control checklist. It should start with the routes that could interrupt production, expose customer data or compromise payments.
The following entries show the level of specificity required. The scores are illustrative working values for the scenario, not measured findings from a real company.
| Risk ID | Risk Description | Likelihood | Impact | Residual Score | Treatment | Owner |
|---|---|---|---|---|---|---|
| R-01 | Legacy VPN has no MFA for remote access | 4 | 5 | 15 | Replace or protect the VPN with MFA and restrict access | IT manager |
| R-02 | Shared finance mailbox enables weak accountability | 3 | 4 | 8 | Move users to named access and review delegation | Finance director |
| R-03 | Contractor retains standing global administrator rights | 3 | 5 | 10 | Remove standing privilege and introduce time-limited elevation | Operations director |
| R-04 | AI tool ingests customer data without a DPIA | 3 | 5 | 12 | Pause sensitive use, complete DPIA and approve contractual safeguards | Data protection lead |
| R-05 | Production file share lacks tested recovery evidence | 3 | 5 | 12 | Test restoration and document recovery ownership | Production manager |
| R-06 | Supplier connection lacks current access review | 3 | 4 | 8 | Confirm data flow, access scope and review date | Procurement lead |
| R-07 | Unmanaged devices access Microsoft 365 data | 3 | 4 | 9 | Enforce compliant-device access and enrolment | IT manager |
| R-08 | Dormant user accounts remain enabled | 3 | 3 | 6 | Disable inactive accounts and automate joiner-mover-leaver checks | HR manager |
| R-09 | Phishing reporting route is unclear | 4 | 3 | 9 | Publish reporting process and test staff response | Security lead |
| R-10 | Azure logging isn’t retained for key workloads | 2 | 4 | 6 | Define logging requirements and review alert coverage | IT manager |
A checklist people can actually use
Before the assessment
- Confirm scope: Obtain sign-off covering sites, tenants, suppliers, data and applications.
- Request evidence: Gather asset lists, admin reports, supplier contracts, backup records and policies.
- Invite decision-makers: Include finance, operations, HR, procurement and a director, not only IT.
During the workshop
- Validate assets: Ask department leads what they use, including unapproved SaaS.
- Walk through scenarios: Test phishing, lost device, supplier compromise and production outage assumptions.
- Agree ownership: Give every material risk one accountable owner and a target date.
After the workshop
- Publish the register: Record residual risk and the person authorised to accept it.
- Track treatment: Put actions into the same management system used for operational work.
- Set review triggers: Record the next scheduled review and the changes that will force an earlier reassessment.
Common Pitfalls That Quietly Undermine Assessments
Most failed assessments don't fail because the team misunderstood a technical term. They fail because the business completes the document and never changes how it makes decisions.
Five failure modes to remove
-
The one-off PDF exercise. A report becomes obsolete when Microsoft 365 configuration, suppliers or business processes change. If nobody reviews actions, the assessment creates evidence of awareness without reducing exposure.
-
The office-network boundary. Teams often inspect routers, servers and laptops while overlooking Microsoft 365, Azure, Google Workspace and SaaS applications. That scope misses the places where staff store data, authenticate and collaborate.
-
The missing supplier. Managed service providers, payroll platforms, logistics partners and software vendors can hold privileged access or process important information. Excluding them hides dependency risk and leaves directors unable to judge contractual exposure.
-
The ungoverned AI workflow. Staff may enter customer, financial or HR information into an AI tool without an approved use case, DPIA or contractual safeguards. The ICO guidance on data protection impact assessments identifies technology, profiling, biometric or genetic data, invisible processing and tracking of location or behaviour among processing contexts that can require a DPIA. The ICO DPIA requirements also require a description of processing, risk assessment, risk measures and safeguards where a DPIA is required.
-
No accountable owner. A risk register without a named owner becomes an archive. Directors need to know who will act, who can accept residual exposure and when the decision will be reviewed.

Practical rule: If a finding has no owner, deadline and acceptance authority, it isn't being managed.
Prioritising Remediation and Reassessment Cadence
SMBs rarely need a complicated scoring model. They need a method people will maintain when production is busy and budgets are tight. I recommend combining likelihood, impact and cost to fix, then reporting the result through a simple Red, Amber and Green view.
Likelihood asks how probable exploitation is under current controls. Impact covers operational, financial, legal and reputational harm. Cost to fix prevents the board from treating every weakness as equally urgent when one control change could reduce exposure quickly and another requires a major redesign.
A workable treatment model
Use the three factors to make a decision:
- Red, fix now: Critical risks should be treated within 14 days. This might include unauthorised privileged access, an exposed production route or sensitive AI processing without the required assessment.
- Amber, plan next: High risks should have an agreed treatment plan within 90 days, with budget and ownership visible to management.
- Green, monitor: Medium risks can be handled in the next assessment cycle, provided the organisation records why the residual exposure sits within its appetite.
These timeframes are management targets, not universal legal deadlines. The board should override them when a contractual, regulatory or operational consequence makes a lower-scored risk unacceptable.

Set triggers, not just calendar dates
Schedule a full review annually, then add reassessment triggers for material change and incidents. A new supplier, Microsoft 365 tenant restructure or AI rollout should prompt a focused review of affected assets and data flows.
A change in Microsoft 365 Defender exposure indicators or the purchase of new Copilot licensing shouldn't automatically force a complete reassessment. It should trigger a targeted review of identity, information protection, prompts, permissions and data handling. For a broader governance view that includes how external perception can affect business harm, solutions for reputation monitoring can complement the operational risk register.
The board report should fit on one page: top risks, movement since the previous review, overdue treatments, accepted residual risks and decisions required. Review the detail operationally each quarter, but give directors the concise information they need to challenge ownership and investment.
Turning Assessment Into Ongoing Security Governance
A security risk assessment earns its keep only when it becomes part of governance. The operating rhythm should contain four touchpoints:
- Quarterly risk register review: Confirm treatment progress, changed assumptions, overdue actions and new supplier or system dependencies.
- Annual full assessment: Revisit scope, assets, threats, vulnerabilities, controls and risk appetite.
- Change-triggered reassessment: Review material changes such as cloud restructuring, AI adoption, acquisitions, new sites or supplier onboarding.
- Post-incident review: Reassess the affected assets and controls after a breach, attack or serious near miss.
This approach also reduces duplicated assurance work. A maintained register can feed an ISO-style statement of applicability, support Cyber Essentials renewal evidence and help answer insurer cyber questionnaires. The same evidence can support customer assurance conversations instead of different teams recreating it for every request.
The governance case is becoming stronger across the UK. The UK Cyber Governance Code of Practice expects boards and directors to build organisational resilience, while secure-by-design guidance positions risk assessment as an input to a risk register, residual-risk decisions and ongoing management.
For East Midlands SMBs, F1Group can run an initial assessment, attend quarterly reviews and help remediate findings across Microsoft 365, Azure and endpoint estates. Its services cover Microsoft-focused IT support, cloud environments and cyber security, so the register can remain connected to practical technical work rather than sitting with a consultancy team after the report is issued.
A clear IT governance framework gives the board the structure to review risk, approve priorities and hold owners accountable. That's the difference between compliance paperwork and security governance.
F1Group can assess your Microsoft 365, Azure, endpoint, supplier and data risks, then turn the findings into an owned remediation plan. Call 0845 855 0000 today to discuss a first assessment or a focused reassessment, or send us a message and visit F1Group to arrange a practical scoping conversation.