devguard

Risks

Risks highlight potential threats or uncertainties that could impact your objectives, helping you proactively address vulnerabilities across your policies, controls, or frameworks.

Overview

The Risks module is the central place for identifying, evaluating, and managing risks across your organization. It integrates Threat Classes, Vulnerability Classes, Treatment Actions, and the Assessment Matrix to provide a complete view of risk posture and treatment.

Risks allow you to connect controls, policies, and roles with structured evaluations of probability, impact, and residual risk. This ensures that your organization can prioritize the most critical risks, track remediation, and demonstrate compliance readiness.

Risks

Risks are the core entity of the module. Each risk represents a potential threat or uncertainty and aggregates related treatment actions, threat classes, vulnerability classes, and linked controls.

Risks are also represented visually in the Assessment Matrix, showing their initial and residual positions.

Risk Fields

FieldDescriptionExample
NameThe name of the risk (required)Rogue Workload in Production
SlugUnique identifier for referencing the risk (required)rogue-workload-in-production
OwnerRole responsible for managing the risk (required)IT Operations
DescriptionDetailed description of the riskUncontrolled workloads in production...
LabelsFree-form tags to group and filter the risk (multiple allowed)PII, GDPR, Q3-initiative
Affected partiesRelated roles potentially affected (multiple allowed)Developers, Business Owners
Threat classRelated threat classUnauthorized access
Vulnerability classRelated vulnerability classAbuse of authorization
Impact descriptionFree-text explanation of possible impactSystem outage or data leakage
Probability ratingLikelihood of occurrence (1–10, or unset)7
Impact ratingPotential impact severity (1–10, or unset)9
ControlsRelated controls (multiple allowed)Access Control Policy, Firewall
Treatment typeStrategy for addressing the riskMitigate, Accept, Avoid, Transfer
Treatment descriptionFree-text treatment explanationApply network segmentation
Treatment actionsLinked treatment actions (multiple allowed)WAF, User Access Reviews
Residual probabilityLikelihood after mitigation (1–10, or unset)4
Residual impactImpact after mitigation (1–10, or unset)6

Labels

Labels are free-form, color-coded tags you manage centrally under Collections → Labels and attach to a risk to capture cross-cutting groupings that the structured fields don't — an initiative, a regulatory driver, a business unit, or a data-sensitivity class. A risk can carry any number of labels, and the risk list offers a Labels filter so you can narrow to everything sharing a tag. The same labels can be applied to assets and vendors, giving you one consistent vocabulary across the product.

Probability, Impact, and Residual Ratings

  • Probability represents how likely the risk is to occur (from rare to certain).
  • Impact represents the potential severity if the risk materializes (from negligible to catastrophic).
  • Residual ratings reflect the remaining probability and impact after treatments are applied.

Best practice is to quantify risks consistently and regularly review ratings to reflect organizational changes.

Import and Export

Risks can be imported/exported in CSV format:

risks.csv
slug,name,ownerId
lack-of-capacity-management,Lack of capacity management,{ownerId}
rogue-workload-in-production-environment,Rogue workload in production environment,{ownerId}
data-leak-via-third-party,Data leak via third-party SaaS provider,{ownerId}
unmonitored-admin-access,Unmonitored administrator access,{ownerId}

Starting from a template

Add Risk opens the create form for a blank risk; the arrow beside it opens the template picker. The picker lists ready-made register entries drawn from recognized risk catalogs, grouped by source:

  • BSI IT-Grundschutz elementary threats (a selection from G 0.1 – G 0.47) — the reference catalog for ISMS work in the DACH region.
  • ENISA Threat Landscape — the EU agency's yearly prime threats, in the vocabulary NIS2 supervisors use.
  • CSA Top Threats to Cloud Computing — for organizations running on public cloud and SaaS.
  • OWASP Top 10 — the application-security categories for organizations that build software.
  • NIS2 and DORA operational risk areas — the risk-management measures both regulations require, expressed as the risk each measure treats.

Search across the catalogs, tick the entries that apply to you, choose the owner role, and create them in one step. Each template brings a description, an impact description, a treatment strategy and initial and residual ratings, and links the matching threat and vulnerability class (creating either if your organization has none of that name). Every created risk is your own copy: edit it freely afterwards, the catalog never changes it. A template you already used is marked Already in your register.

Assessment Matrix

Risk Assessment Matrix helps evaluate and prioritize risks by mapping their likelihood and impact—providing a structured, visual tool to support consistent, informed decision-making across your risk and compliance workflows.

The matrix has three readings, switched with the tabs above it:

  • Heat map — one cell per probability × impact bucket, showing how many risks sit in it, the severity band, and a pip per risk. Toggle between Initial, Residual and Both (both shows the residual count with the initial count beside it). Select a cell to open the inspector on the right, which lists the risks in that cell with their treatment strategy. The statistics strip below gives the distribution after treatment, with arrows for how each band changed against the initial ratings, and the treatment-action posture.
  • Drift — the initial and residual exposure side by side as two compact grids, and the biggest movers with their before-and-after band.
  • Plot — every risk as a point on continuous probability and impact axes. Risks sharing a coordinate merge into a bubble sized by their count; hover it for the entries. The dashed curves are the medium and high thresholds. Filter to Untreated risks or those Owned by me. The side panels show how many risks sit above appetite (score 41 or higher) and the five largest exposures.

Severity bands: Low (score 1–10), Medium (11–40), High (41–69) and Critical (70 and above). Critical is the top of the high band, so every count of "high or above" matches the High figure elsewhere in the product.

Best Practices

  • Risks should ideally be reduced to low wherever possible.
  • Medium and high residual risks should be tied to treatment actions.
  • Regular reviews ensure that ratings remain aligned with reality.

Treatment Actions

Risk Treatment Actions define how identified risks are addressed—whether by mitigating, accepting, transferring, or avoiding them—ensuring clear, trackable responses within your risk and compliance workflows.

Treatment Action Fields

FieldDescriptionExample
NameThe name of the action (required)WAF and DDoS Protection
SlugUnique identifier (required)waf-and-ddos-protection
OwnerRole responsible for the action (required)Security Team
DescriptionDetailed explanationDeploy and configure a WAF
Due dateDeadline for implementation (links to Deadlines)31.12.2025
StatusCurrent status of the actionPlanned, In Progress, Implemented

Import and Export

Treatment actions can be imported/exported in CSV format:

treatment-actions.csv
slug,name,ownerId
waf-and-ddos-protection,WAF and DDoS protection,{ownerId}
formal-user-access-reviews,Formal user access reviews,{ownerId}
encryption-rollout,Encryption rollout across endpoints,{ownerId}

Treatment actions display where they are used across risks, ensuring traceability. If an item is no longer valid, related data must be reviewed before removal.

Deadlines

The due date behavior for treatment actions differs from that of assets, entitlements, and risks: treatment action due dates are intended as manually managed reminders and are not cleared automatically. Once a treatment action is completed, its due date must be reviewed and removed manually, and the status should be updated accordingly.


Threat Classes

Threat Classes categorize types of malicious actions or events, providing a structured way to identify, assess, and mitigate security threats across your assets, controls, or frameworks.

Threat Class Fields

FieldDescriptionExample
NameThe name of the action (required)Unintentional access
SlugUnique identifier (required)unintentional-access
DescriptionDetailed explanationPrevent access to sensitive data

Import and Export

Threat classes can be imported/exported in CSV format:

threat-classes.csv
slug,name
users-fall-to-phishing,Users fall to social engineering or phishing attacks
unintentional-sensitive-data,Unintentional access to sensitive data
unauthorized-software,Unauthorized installation of software
unauthorized-system-access,Unauthorized access to the information system

Vulnerability Classes

Vulnerability Classes group common weaknesses in systems or processes, helping you consistently identify and manage exposure points across your assets, risks, or compliance frameworks.

Vulnerability Class Fields

FieldDescriptionExample
NameThe name of the action (required)Abuse of authorization
SlugUnique identifier (required)abuse-of-authorization
DescriptionDetailed explanationUnauthorized access to the information system

Import and Export

Vulnerability classes can be imported/exported in CSV format:

vulnerability-classes.csv
slug,name
abuse-of-authorization,Abuse of authorization
asset-not-returned,Asset not returned
weak-password-policy,Weak password policy
unencrypted-data-storage,Unencrypted data storage

Reviews

Reviews provide a structured way to periodically assess and validate your risks, controls, or compliance elements. They capture a snapshot in time, ensuring that changes are tracked, validated, and approved while maintaining accountability and alignment with your governance objectives.

Review Management

When starting a review, you define the scope and responsibilities. A review automatically creates review items based on your selected scope (e.g., all risks or only high-priority risks).

FieldDescriptionExample
TitleThe name of the review (required)"Q3 Risk Review"
CoordinatorResponsible role coordinating the review (required, relation to a role)"Customer Success"
PriorityDefines which risks are included (required)"High Risks Only"
DeadlineDue date for completing the review (integrates with Deadlines)"2025-10-04"
NotesOptional context or additional instructions"Focus on operational risks this cycle"

Reviews support full CRUD operations: they can be created, edited, or withdrawn before being finalized. Once a review is closed, it becomes locked and immutable.

Review Process

Each review lists all risks according to the chosen scope. Any changes made during the review are tracked and displayed as diffs, allowing you to compare against the latest version or earlier cycles. A split view can be enabled for easier side-by-side comparison.

Each review item must be explicitly approved. If necessary, items can also be withdrawn. Once all review items are approved, the review can be closed by selecting Finish Review. This locks the review and prevents further modifications.

Reviews also integrate with the Reports feature through Generate Report, allowing you to export finalized review results for audits, compliance evidence, or internal governance tracking.


Tasks

Each risk's detail view has a Tasks tab for the follow-up work attached to it. Where Treatment Actions are the structured, owned mitigations that reduce a risk's residual score, tasks capture the lighter, ad-hoc work around a risk — a quick investigation, a document to write, a check to run. Use Add task and it is attached to the risk automatically. These tasks appear in the central Tasks worklist and, when given a deadline, on the Roadmap.


Comments

Detail views across the risks area (risks, treatment actions, threat classes, vulnerability classes and risk reviews) have a Comments tab for discussing it in place, so the reasoning behind a decision stays attached to the record instead of living in a chat thread nobody can find later.

Write a comment with light formatting (bold, italic, underline, lists), reply to any comment (replies cannot be nested further), and edit or delete your own. Deleting a comment that has replies leaves a placeholder so the conversation still reads in order.

Type @ to mention a colleague. They are notified in the app and by email, and can adjust how often they hear about comments under Account → Notifications.

How is this guide?

On this page