Most UK businesses have heard of cyber security. Far fewer have ever taken a close look at their own vulnerabilities. A cyber security risk assessment changes that. It gives your business a clear picture of where the risks actually are, which ones matter most, and what to do about them.
What Is a Cyber Security Risk Assessment?
A cyber security risk assessment is a structured review of your business’s digital environment. It looks at what data and systems you hold, who can access them, what threats they face, and how much damage a breach could cause.
The goal is not to scare anyone. It’s to give you an honest view of your current security position so you can make sensible decisions about where to invest time and money.
Most assessments work through a similar process: identifying your assets (systems, data, devices), mapping the threats those assets face, checking whether your current controls are actually working, and scoring each risk by likelihood and potential impact. The output is a prioritised list of what needs to change and why.
Some businesses handle this in-house. Many work with a specialist IT security provider to make sure nothing gets missed.
Why Does It Matter?
According to the UK Government’s Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber security breach or attack in the last 12 months. For medium businesses, that figure rises to 67%. For large businesses, it’s 74%.
Yet the same survey found that only 29% of businesses carry out cyber security risk assessments. That’s a significant gap. The businesses that know what they’re protecting and where the weak points are tend to be far better placed to stop attacks before they cause damage.
Phishing remains the most common form of cyber crime, accounting for 93% of cyber crimes reported by UK businesses. And ransomware is rising: the proportion of businesses experiencing a ransomware attack doubled from less than 0.5% in 2024 to 1% in 2025, representing an estimated 19,000 UK businesses in a single year.
Your business doesn’t need to be large or high-profile to be targeted. Small and micro businesses are increasingly attacked, often because attackers assume they have weaker defences.
What Does a Cyber Security Risk Assessment Cover?
Every assessment is a little different depending on your business size and sector, but most will look at these areas.
Assets and data. What information do you hold? Customer records, financial data, business emails, contracts, and anything stored in the cloud all count.
Access controls. Who can access what? Weak passwords, shared logins, and unchecked admin access are common problems that a risk assessment will surface.
Network security. How is your network configured? Are your devices patched and up to date? Are you running any software that’s no longer supported by the manufacturer?
Third-party risk. What do your suppliers and partners have access to? A breach at a supplier’s end can expose your data just as easily as a direct attack.
Human behaviour. Staff are one of the most common entry points for attackers. Phishing, accidental data sharing, and poor password habits are all areas a thorough assessment will flag.
Incident response readiness. What happens if something goes wrong? Do you have a plan, a recent backup, and a clear process for containing and recovering from a breach?
Is It a Legal Requirement in the UK?
There’s no single UK law that specifically requires a cyber security risk assessment by name. However, if your business processes personal data, UK GDPR expects you to identify and manage risks to that data. Article 32 of the UK GDPR, as outlined by the ICO, requires appropriate technical and organisational measures to protect personal data. A risk assessment is a key part of demonstrating that.
If you operate in regulated sectors such as financial services, healthcare, or defence supply chains, additional requirements may apply on top of GDPR.
Businesses working towards Cyber Essentials certification will also find that the five technical controls it tests map closely to what a risk assessment covers. Many businesses use the assessment as preparation for Cyber Essentials rather than trying to tackle both at once.
Even without a strict legal obligation, not assessing your risks leaves you exposed to attacks and to regulatory scrutiny if a breach does occur and you cannot show you took reasonable steps.
How Often Should You Review It?
Once a year is a sensible baseline for most businesses. You should also revisit it whenever something significant changes: moving to a new office, adding a cloud platform, switching key suppliers, or taking on a large number of remote workers.
Cyber threats don’t stand still. An assessment that was accurate two years ago will likely miss threats that are common today, including newer phishing techniques, supply chain attacks, and vulnerabilities in software your business now relies on.
For businesses in higher-risk sectors or those handling particularly sensitive data, reviewing every six months makes more sense.
Should You Do This In-House or Bring In Support?
Smaller businesses often try to manage risk assessments internally, but it’s easy to overlook things when you’re close to the day-to-day. A specialist tends to catch vulnerabilities that internal teams miss, simply because they approach it without assumptions about what’s already in place.
If your business doesn’t have a dedicated IT team, this is one of the clearest arguments for working with an outsourced IT support provider. You get access to security expertise without the cost of hiring a specialist in-house.
Our cyber security services include helping businesses identify where they’re exposed and putting solid protections in place. And if you want ongoing coverage rather than a one-off review, our managed IT support service covers monitoring, patching, and access management as part of your day-to-day IT provision.
Frequently Asked Questions
How long does a cyber security risk assessment take?
It depends on the size and complexity of your business. A basic assessment for a small business can be completed in a day or two. Larger organisations with multiple sites or complex systems may need several weeks. The time is well spent: knowing where your risks are is far better than finding out during a breach.
Is a cyber security risk assessment the same as a penetration test?
No. A penetration test simulates an active attack on your systems to see whether defences hold up. A risk assessment is broader: it reviews your entire security setup, identifies risks, and scores them by likelihood and impact. Many businesses do both, with the risk assessment helping to define where the penetration test should focus.
Is a cyber security risk assessment a legal requirement in the UK?
There is no law that names it specifically, but UK GDPR requires you to manage risks to personal data, and a risk assessment is a key part of meeting that obligation. Sector-specific regulations in financial services and healthcare may also require formal risk reviews. If something goes wrong and you haven’t assessed your risks, that gap becomes visible to regulators.
Who should carry out a cyber security risk assessment?
Someone with a solid understanding of both your business and IT security. For most small and medium businesses, this means an external IT support provider or security specialist. Whoever does it should be thorough, impartial, and able to turn findings into clear, practical actions rather than a technical report that sits unread.
What’s the difference between a cyber security risk assessment and Cyber Essentials?
Cyber Essentials is a UK government-backed certification that tests five specific technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. A cyber security risk assessment is broader. It looks at your unique business risks across people, processes, third parties, and data. Many businesses use a risk assessment as preparation before applying for Cyber Essentials.
How much does a cyber security risk assessment cost in the UK?
Costs vary. A basic review for a small business can start from a few hundred pounds. A more thorough assessment for a business with complex systems or regulatory requirements may cost several thousand. Either way, the cost is almost always less than the cost of recovering from a breach you didn’t see coming.
The Bottom Line
Cyber security risks don’t disappear just because you haven’t looked at them. They build quietly until something breaks. A risk assessment gives you the information you need to make sensible decisions and protect your business before an attacker forces your hand.
If you’d like to understand where your business stands, get in touch with UK IT Services for a free consultation. We work with businesses across the UK to identify cyber security risks and put the right protections in place.