How to Get a Cyber Security Risk Assessment Done: Hire or Train?

A cyber security risk assessment is a structured review that identifies the ways your business could be harmed through its systems and data, ranks them by how likely and how damaging they are, and decides what to do about each one. That's the definition. The reason to care is arithmetic.

The average data breach now costs $4.44 million, and over $10 million in the United States, according to IBM's 2025 Cost of a Data Breach report. Behind the headline number sit weeks of downtime, lost customers, regulatory fines and legal fees, and here's the uncomfortable part: most of the companies paying those bills owned security tools. Firewalls, antivirus, backups, the lot. What they hadn't done was seriously work out where they were actually exposed, so the spending went where the salespeople pointed rather than where the risk lived.

Companies take this lightly for an understandable reason. The cost of skipping an assessment never appears in any budget line. There's no invoice for it, no monthly reminder, nothing to approve. It stays invisible right up until it arrives all at once, with an incident response firm's rates attached.

If you run a business or a budget, the practical question isn't whether your cyber risk should be assessed. It's who should do it, and that decision deserves far more thought than it usually gets.

What an assessment actually involves

Strip away the industry language and an assessment is five moves:

  • Decide what you're reviewing: the whole business, or one critical system to start.
  • List what matters most, the systems and data your company genuinely cannot operate without.
  • Work out what could go wrong for each: ransomware, a tricked employee, a failed supplier, a leaked password.
  • Judge each risk by how likely it is and what it would cost you.
  • Decide what to do about the big ones, give each decision an owner and a date, and set a date to review it all.

Nothing on that list requires genius. All of it requires judgement, and judgement is where assessments succeed or fail, because a wrong guess about likelihood or impact sends your money to the wrong place. Which brings us to the factor that matters more than any template or tool.

An assessment finds and ranks your risks; a https://www.readynez.com/en/blog/your-next-cyber-security-audit-will-ask-about-ai-ready/https://www.readynez.com/en/blog/your-next-cyber-security-audit-will-ask-about-ai-ready/ then checks the controls you built are real and working.

The most important factor is who does it

An assessment is only as good as the people making those judgement calls. Someone has to look at your systems and see what an attacker would see, put a realistic number on the damage, and defend those conclusions when the board or an auditor pushes back. That's a skill, it's learnable, and whether you buy it or build it is the real decision this article exists to help you make.

Consultants or your own team?

Hiring a consultancy gets you:

  • Speed and experience. They've assessed dozens of companies and arrive with a method, so you get a credible report in weeks.
  • Independence. An outside name carries weight with boards, insurers and customers.
  • No training investment up front.

But it also means:

  • A snapshot, not a capability. The report describes one moment, and it starts ageing the day it lands.
  • The knowledge leaves with them. Every future assessment is another invoice.
  • They don't know your business. The first chunk of what you pay for is them learning what your own people already know.

Building the capability in-house gets you:

  • Context. Your people already know which systems matter, where the shortcuts are and what actually happens on a Friday afternoon.
  • Permanence. The skill stays, so reassessing after a change costs days, not a procurement cycle.
  • Better economics over time. Training a few employees costs a fraction of repeated engagements.

The honest cons: it takes an upfront investment in training, it needs at least two people so no single view dominates, and an internal team can inherit internal blind spots if nobody challenges them.

Why your own team is the better answer

For most organisations, build it. The reason is that risk doesn't hold still. Every new system, supplier, hire and AI tool changes your exposure, so an assessment isn't really a document you commission, it's a capability you either have or don't. A consultant hands you a photograph; a trained team gives you eyes. And with European rules like NIS2 making management personally accountable for cyber risk, and DORA demanding continuous risk management in finance, a once-a-year PDF from an outside firm is increasingly the wrong shape for the obligation.

There's a sensible middle path for the first time round: bring a consultant in once, and put your own people in the room for every step. You get the independent report and the transfer of method, and the second assessment is yours.

How does AI change the assessment?

In both directions at once. On the risk side, AI belongs in your assessment as a subject, because if your business has adopted Copilot-style assistants or agents, you've added software that reads company data at scale and acts on its own, and an assessment that predates those tools is missing entries. IBM's report gives this teeth: breaches involving ungoverned, unauthorised AI use cost measurably more.

On the defence side, AI is the assessor's friend. The same IBM report credits faster, AI-assisted detection and containment as a main reason global breach costs fell this year for the first time in years. A team that knows how to put AI to work, scanning for exposures, summarising incidents, monitoring what changed, covers more ground than one working by hand. Put those two directions together and the target becomes clear: the strongest position is a trained team with AI in its toolkit, assessing a business whose AI is itself on the risk register.

Start with what applies to you

Before any training plan, know your obligations, because they decide what your assessment must cover and what evidence it must produce. NIS2 applies if you're in or supplying an essential or important sector in the EU. DORA applies if you're in financial services. GDPR applies to nearly everyone holding personal data, card payments bring PCI DSS, and customers in tenders increasingly ask for ISO 27001. Which of these bind you is the first thing to establish, and it shapes everything from scope to paperwork. Our guide to CISSP's security and risk management domain shows how deep this ground goes for the people doing the work.

The certifications that make a team credible

Credibility is the whole point of training here: your assessment has to convince boards, auditors, insurers and customers, and recognised certifications are how a small team earns that trust. Four map cleanly onto the work:

  • CRISC (Certified in Risk and Information Systems Control) is the closest match to risk assessment itself: identifying, evaluating and responding to IT risk is the entire syllabus.
  • CySA+ equips the hands-on analyst who finds vulnerabilities and reads threat data day to day.
  • CISM fits the person who owns the risk decisions and has to defend them to leadership.
  • ISO 27001 Lead Implementer suits whoever turns assessments into a running security system, and it's the credential behind the certificate customers ask about.

Two or three people covering that ground between them is a genuine assessment capability. If you're training a group rather than one person, Unlimited Security Training carries all of these courses under one subscription, which tends to be how teams do it in practice.

So the choice comes down to two invoices. One is for training a few of your own people this quarter, a known number you approve in advance. The other is the one in IBM's report, and it arrives unapproved. Companies that take risk assessment lightly aren't avoiding the cost; they're just choosing the invoice they can't see yet.

Written by:

Frank Hojgaard

Frank Højgaard is the Founder and CEO of Readynez, where he focuses on how organisations build the skills and capabilities needed to succeed with AI. With more than 15 years in IT training and workforce development, he writes about AI adoption, Copilot enablement, skills intelligence, role-based learning, and how companies can move from traditional course consumption to measurable workforce readiness and business impact.

Two people monitoring systems for security breaches

Unlimited Security Training

Get Unlimited access to ALL the LIVE Instructor-led Security courses you want - all for the price of less than one course. 

  • 60+ LIVE Instructor-led courses
  • Money-back Guarantee
  • Access to 50+ seasoned instructors
  • Trained 50,000+ IT Pro's

Basket

{{item.CourseTitle}}

Price: {{item.ItemPriceExVatFormatted}} {{item.Currency}}