Learning Objectives:

  • Understand the purpose and components of a cyber risk register.

  • Apply risk scoring methodologies to cyber risks.

  • Develop a cyber risk register for a central bank.

  • Use risk registers to prioritise risk management activities.

4.1 The Purpose of a Cyber Risk Register

A cyber risk register is a document that records and tracks cyber risks identified by an organisation. The risk register is a key tool for managing cyber risk, as it provides a structured way to document risks, assess their likelihood and impact, and track the implementation of mitigation strategies.

The Central Bank of Nigeria’s Framework requires that identified risks should be documented in a central register, and periodically monitored and reviewed . This ensures that risks are systematically tracked and managed.

4.2 Key Components of a Cyber Risk Register

A comprehensive cyber risk register typically includes:

  • Risk Description: A clear description of the cyber risk, including the potential threat and vulnerability.

  • Risk Category: The category of cyber risk (e.g., phishing, ransomware, supply chain).

  • Inherent Risk: The level of risk before controls are applied, assessed based on likelihood and impact.

  • Controls: The controls in place to mitigate the risk.

  • Residual Risk: The level of risk after controls are applied.

  • Risk Owner: The individual or department responsible for managing the risk.

  • Treatment Actions: The actions to be taken to mitigate the risk to an acceptable level.

  • Status: The current status of the risk and treatment actions.

4.3 Risk Scoring Methodologies

Risk scoring methodologies are used to assess the likelihood and impact of cyber risks. The Central Bank of Nigeria’s Framework requires SFIs to quantify the financial impact of cybersecurity risks through the risk measurement process .

Common Risk Scoring Methodologies:

Likelihood Rating: The likelihood of a cyber event occurring, rated on a scale from low to high. Factors that can affect likelihood include the strength of controls, the history of incidents, and the external threat environment.

Impact Rating: The potential impact of a cyber event, rated on a scale from low to high. Impact should consider both financial and non-financial consequences, such as reputational damage and regulatory penalties.

Risk Score: The product of likelihood and impact ratings. A high-risk score indicates a high priority for mitigation.

Qualitative Risk Scoring: Risk is assessed using descriptive scales (e.g., low, medium, high). This approach is useful for initial risk assessment and for risks that are difficult to quantify.

Quantitative Risk Scoring: Risk is assessed using numerical values for likelihood and impact, often expressed in financial terms. This approach is useful for prioritising risks and making investment decisions.

4.4 Using Risk Registers to Prioritise Risk Management

Risk registers are used to prioritise risk management activities by focusing resources on the highest risks. The Central Bank of Nigeria’s Framework requires the status of compliance with Board-approved cyber risk thresholds to be reported .

Key Considerations:

  • Risk Prioritisation: Prioritise risks based on their residual risk score. High-risk areas should receive the most attention and resources.

  • Resource Allocation: Allocate resources to areas of highest risk. This ensures that limited resources are used effectively.

  • Monitoring: Monitor risk indicators to detect changes in risk levels. Key risk indicators (KRIs) can be used to track cyber risk over time.

  • Reporting: Report risk register findings to Senior Management and the Board. The CBN requires quarterly reports detailing the overall status of the cybersecurity programme .