The SMB risk library
37 risks I keep seeing at small organizations, written the way a register entry should be written: event, caused by cause, resulting in impact. Each comes with a suggested starting score, the first controls worth deploying, and the evidence that proves them.
A risk you can't write as event–cause–impact is a worry, not a risk. The suggested scores are starting points from my own anchors — re-score against yours (the register's Scoring Guide shows how).
Filter by situation, sort any column, and click a risk to see its full statement, first controls, and evidence. Sorting by score puts the library's 80/20 on top — the rows most registers should start from. Copy what fits into your risk register, or download the whole library as a workbook below. Don't import all 37 — a register with everything on it manages nothing.
| Fits | |||||
|---|---|---|---|---|---|
| RL-01 | Cyber | Universal | 6 | Mitigate | |
|
Ransomware encrypts servers and shared data, caused by phished credentials and no MFA on remote access, resulting in multi-day operational shutdown and recovery costs. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: MFA everywhere with legacy auth blocked; one backup copy offline or immutable; 7-day patch SLA for internet-facing systems. Evidence that counts: MFA policy export; dated restore test result. |
|||||
| RL-02 | Process | Universal | 6 | Mitigate | |
|
Unauthorized access via active accounts of departed employees, caused by offboarding without same-day disablement, resulting in standing credentials nobody monitors plus license waste. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Same-day disable checklist triggered by HR; quarterly account-vs-roster reconciliation. Evidence that counts: Quarterly reconciliation note with findings. |
|||||
| RL-03 | Operational | Universal | 6 | Mitigate | |
|
Permanent data loss after hardware failure or ransomware, caused by backups that were never restore-tested, resulting in unrecoverable systems and data. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Quarterly restore test with documented results; offline/immutable copy; written recovery order. Evidence that counts: Restore test log, dated. |
|||||
| RL-04 | Financial | Universal | 6 | Mitigate | |
|
Fraudulent vendor or payroll payment, caused by business email compromise impersonating an executive or supplier, resulting in unrecoverable financial loss. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Callback verification on any payment/banking change using known numbers; dual approval; DMARC at quarantine or reject. Evidence that counts: Documented callback rule; DMARC record. |
|||||
| RL-05 | People | Universal | 6 | Mitigate | |
|
Inability to operate or recover IT systems, caused by critical knowledge held by one person with no documentation, resulting in extended outages during absence or departure. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Runbooks for the top 10 procedures; decision log; cross-train a deputy; vendor contact list off-network. Evidence that counts: Runbooks with last-updated dates. |
|||||
| RL-06 | Cyber | Universal | 4 | Mitigate | |
|
Network intrusion, caused by delayed patching of firewall/VPN/edge appliances, resulting in data exfiltration or ransomware staging. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Vendor advisory subscriptions; 7-day SLA for critical edge patches; retire out-of-support gear. Evidence that counts: Firmware version list vs current. |
|||||
| RL-07 | Vendor | Universal | 3 | Transfer | |
|
Exposure of customer or company data, caused by a breach at a vendor holding it, resulting in notification obligations and reputational damage you didn't cause but still own. Suggested score: L1 × I3 = 3 · Response: Transfer First controls: Vendor inventory with data sensitivity; security evidence on file; verify insurance covers third-party incidents. Evidence that counts: Vendor inventory, reviewed dates. |
|||||
| RL-08 | Cyber | Universal | 4 | Mitigate | |
|
Breach notification obligations, caused by lost or stolen devices without verified disk encryption, resulting in legal exposure from what should have been a hardware loss. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Enforce encryption via MDM; verify compliance reporting; remote wipe capability. Evidence that counts: Encryption compliance report. |
|||||
| RL-09 | Process | Universal | 6 | Mitigate | |
|
Unmanaged data exposure, caused by easy self-signup SaaS adoption with no approval path, resulting in company data in tools nobody secures, renews, or offboards. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Lightweight approval path (fast yes beats silent no); review card statements quarterly for unknown subscriptions. Evidence that counts: SaaS inventory with owners. |
|||||
| RL-10 | Financial | Universal | 6 | Mitigate | |
|
Cyber insurance claim denied or reduced, caused by controls misrepresented on the application, resulting in uninsured incident costs at the worst moment. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Answer applications literally, not aspirationally; verify each claimed control actually operates; keep evidence. Evidence that counts: Application answers cross-checked against reality. |
|||||
| RL-11 | Cyber | Universal | 6 | Mitigate | |
|
Full environment compromise, caused by administrators using privileged accounts for email and browsing, resulting in one phish handing over the keys. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Separate admin accounts; 2-4 global admins max; phishing-resistant MFA for admins. Evidence that counts: Admin role membership export. |
|||||
| RL-12 | Process | Universal | 6 | Mitigate | |
|
Quiet data exposure, caused by permissive sharing defaults (anyone-links) in M365/Google, resulting in sensitive folders reachable via forwardable links nobody remembers. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Default sharing to specific people; link expiration; quarterly review of externally shared content. Evidence that counts: Sharing settings export. |
|||||
| RL-13 | Operational | Universal | 4 | Mitigate | |
|
Unplanned downtime of core systems, caused by aging servers and network gear past support, resulting in halted operations and premium-priced emergency replacement. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Lifecycle plan with budget line; replace before failure; evaluate hosted alternatives at refresh. Evidence that counts: Asset list with support dates. |
|||||
| RL-14 | Operational | Universal | 4 | Mitigate | |
|
Idle staff and missed commitments, caused by single internet connection failure with cloud-dependent operations, resulting in company-wide stoppage from one cable. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Secondary connection or LTE failover sized for critical work; test the failover. Evidence that counts: Failover test note. |
|||||
| RL-15 | People | Universal | 4 | Mitigate | |
|
Competitive and legal harm, caused by departing employees retaining access during notice periods with no data review, resulting in customer lists and IP leaving quietly. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Access review at resignation; revoke high-risk access immediately; exit acknowledgment of obligations. Evidence that counts: Offboarding checklist runs. |
|||||
| RL-16 | Financial | Startups | 6 | Mitigate | |
|
Slipped or lost enterprise revenue, caused by no prepared security answers or evidence when the questionnaire arrives, resulting in weeks of delay and rushed concessions. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Master questionnaire answered once and maintained; evidence folder; honest gap list with dates. Evidence that counts: Master questionnaire, last-updated date. |
|||||
| RL-17 | Cyber | Startups | 6 | Mitigate | |
|
Cloud account compromise, caused by API keys and credentials committed to source repositories, resulting in data breach or a five-figure compute bill. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Secret scanning in CI; secrets manager instead of env files in repos; rotate anything ever committed. Evidence that counts: Scanner output; rotation log. |
|||||
| RL-18 | Process | Startups | 6 | Mitigate | |
|
Customer data breach via the weakest copy, caused by production data cloned into dev/test environments with weaker controls, resulting in exposure no production control could prevent. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Synthetic or masked data for non-production; if prod data is unavoidable, same controls apply. Evidence that counts: Data handling rule; spot-check. |
|||||
| RL-19 | Process | Startups | 6 | Mitigate | |
|
IP and system exposure, caused by contractor offboarding that misses accounts outside SSO (repos, cloud consoles, SaaS), resulting in third parties retaining quiet access. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Contractor access inventory at engagement start; offboarding checklist includes non-SSO accounts. Evidence that counts: Completed offboarding checklists. |
|||||
| RL-20 | People | Startups | 6 | Mitigate | |
|
Operational standstill, caused by the founder holding sole admin for every critical system with nothing documented, resulting in lockout during absence, departure, or dispute. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Second admin (or break-glass) on every critical system; password manager with emergency access; one-page system map. Evidence that counts: System map; emergency access test. |
|||||
| RL-21 | Compliance | Startups | 4 | Mitigate | |
|
Contractual liability, caused by DPA data-deletion commitments with no implementing process, resulting in breach of contract discovered at audit, renewal, or worse, post-incident. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: List contractual data commitments; build the deletion runbook; test it once. Evidence that counts: Deletion run log. |
|||||
| RL-22 | Operational | Startups | 3 | Mitigate | |
|
Days-long platform outage, caused by accidental deletion or compromise of the single production cloud account, resulting in rebuild from memory without tested infrastructure-as-code. Suggested score: L1 × I3 = 3 · Response: Mitigate First controls: Separate prod/dev accounts; IaC for core infrastructure; backup outside the primary account; test a rebuild. Evidence that counts: Rebuild test notes. |
|||||
| RL-23 | Compliance | US Gov | 6 | Mitigate | |
|
Non-compliance with obligations already in force, caused by receiving CUI without identifying it (no marking review or contract analysis), resulting in 800-171/CMMC exposure on live contracts. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Contract-by-contract data analysis with your primes, in writing; CUI handling decision before the next award. Evidence that counts: Written CUI determinations. |
|||||
| RL-24 | Compliance | US Gov | 6 | Mitigate | |
|
False Claims Act liability, caused by self-assessment scores submitted as better than reality, resulting in settlements, penalties, and lost contracts when checked. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Score literally, as an assessor would; POA&M with dates for gaps; re-score after changes. Evidence that counts: Scoring worksheet with evidence per item. |
|||||
| RL-25 | Operational | US Gov | 6 | Mitigate | |
|
Disqualification from CUI solicitations, caused by starting C3PAO certification later than assessor availability allows, resulting in eligible work you can't bid after Nov 2026. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Treat certification as a dated pipeline decision with leadership now; book assessment early; enclave first to shrink scope. Evidence that counts: Decision recorded in leadership briefing. |
|||||
| RL-26 | Vendor | US Gov | 6 | Mitigate | |
|
Unbudgeted compliance scramble, caused by prime contractors passing requirements down late in the bid cycle, resulting in rushed spend or forced no-bids. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Ask primes now what next cycle requires; standing compliance summary ready to send. Evidence that counts: Prime correspondence on requirements. |
|||||
| RL-27 | Compliance | US Gov | 4 | Mitigate | |
|
Costly migration under deadline, caused by tenant architecture (commercial vs GCC/GCC High) decided before contract analysis, resulting in five-figure rework to qualify. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Decide cloud architecture from contract data types before migration; segregate CUI workloads. Evidence that counts: Architecture decision record. |
|||||
| RL-28 | Operational | US Gov | 4 | Mitigate | |
|
Whole-company assessment boundary, caused by CUI allowed to flow through every mailbox and laptop instead of an enclave, resulting in compliance cost scaling with headcount instead of contracts. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Enclave strategy: CUI confined to defined systems and people; written data flow. Evidence that counts: Data flow diagram; enclave access list. |
|||||
| RL-29 | Compliance | India | 4 | Mitigate | |
|
Regulatory exposure from a minor incident, caused by no detection-and-reporting pipeline able to meet CERT-In's six-hour window from noticing, resulting in penalties stacked on incident costs. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: One reporting channel everyone knows; no-blame rule; CERT-In contacts and report format pre-staged in the IR policy. Evidence that counts: IR policy with CERT-In details; a test run. |
|||||
| RL-30 | Compliance | India | 4 | Mitigate | |
|
Inability to produce required logs, caused by retention under 180 days or storage outside Indian jurisdiction, resulting in non-compliance discovered exactly when logs are needed most. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Verify retention and storage location per log source now; fix gaps; document the map. Evidence that counts: Log source inventory with retention/location. |
|||||
| RL-31 | Compliance | India | 6 | Mitigate | |
|
Failed DPDP breach reporting, caused by no notification process, contacts, or templates prepared, resulting in regulatory penalties compounding incident damage. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Breach notification runbook with Board and data-principal templates; legal contact retained before needed. Evidence that counts: Runbook; tabletop note. |
|||||
| RL-32 | Compliance | India | 6 | Mitigate | |
|
Processing without valid notice or consent, caused by apps and forms designed before DPDP requirements, resulting in remediation under deadline pressure and Board complaints. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Inventory collection points; itemized notices and withdrawal mechanism; retention schedule per purpose. Evidence that counts: Notice text; consent records. |
|||||
| RL-33 | Financial | India · ISO/MS | 4 | Mitigate | |
|
Disqualification from government and PSU tenders, caused by certification listed as a qualifying gate with lead time longer than the tender window, resulting in lost pipeline. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Treat certification timing as a leadership pipeline decision with costs and lead times on the table. Evidence that counts: Decision recorded with dates. |
|||||
| RL-34 | Compliance | ISO/MS | 4 | Mitigate | |
|
Major nonconformity and credibility loss, caused by policy documents describing controls that don't operate, resulting in failed or delayed certification and a skeptical auditor thereafter. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Policy-reality review: change the statement or change the operation; document deviations honestly. Evidence that counts: Review notes; updated policies. |
|||||
| RL-35 | Process | ISO/MS | 6 | Mitigate | |
|
Recurring crunch and missed findings, caused by evidence assembled retrospectively instead of produced by operations, resulting in burnout and nonconformities that routine evidence would have caught. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Evidence as byproduct: reviews end in dated sign-offs, tests file their results, register carries review dates. Evidence that counts: Evidence calendar with completions. |
|||||
| RL-36 | Operational | ISO/MS | 4 | Mitigate | |
|
Permanent audit tax, caused by certifying broader scope than any customer required, resulting in surveillance cost across systems nobody asked about, forever. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Narrowest defensible scope; revisit scope at each recertification, not just additions. Evidence that counts: Scope statement with rationale. |
|||||
| RL-37 | Process | ISO/MS | 4 | Mitigate | |
|
Certificate at risk, caused by internal audits or management reviews skipped in busy seasons, resulting in major nonconformity at the next surveillance audit. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Calendar the system: internal audit and management review as recurring, owned, dated events. Evidence that counts: Meeting minutes; audit reports. |
|||||
The whole library, as a workbook
Same 37 risks in register-compatible columns — copy rows straight into your risk register. No macros, ever.
Download the workbookHow this connects: pick 8–15 risks that match your situation, paste them into the register, re-score with your own anchors, and take the top rows to leadership with the briefing template. The library is a menu, not a meal — and the 90-day plan shows where seeding the register fits in your first quarter.