Table of Contents
Type: Assignment | Subject: Cyber Security | Level: Masters | Word Count: ~2600 words
This model assignment was produced by an Essays UK specialist as reference material for learning purposes only. For support in this field, see our cyber security assignment specialists.
Acting as an external information security consultant, conduct a structured risk assessment for a small or medium-sized enterprise of your choice. Identify key information assets and threats, apply a recognised risk assessment methodology to score and prioritise risks, and support at least one risk with a worked quantitative loss-expectancy calculation. Conclude with a prioritised, evidence-based set of risk treatment recommendations. (2,600 words)
Small and medium-sized enterprises (SMEs) are disproportionately exposed to cyber risk relative to their capacity to manage it: they typically hold commercially sensitive and personal data comparable to larger organisations, yet operate with limited dedicated security expertise and budget (ENISA, 2021). This assignment presents an information security risk assessment for Thornfield Associates, a fictional forty-five-employee UK accountancy practice handling client financial records, payroll data and confidential tax filings across a mix of on-premises and cloud-hosted systems. The assessment is conducted from the perspective of an external information security consultant engaged to identify and prioritise the practice’s principal information security risks ahead of a planned Cyber Essentials Plus certification.
The assignment has three objectives. First, to apply a recognised risk assessment methodology to identify, score and prioritise the organisation’s key information security risks. Second, to support the highest-priority risk with a worked quantitative loss-expectancy calculation, illustrating how qualitative risk scoring can be complemented by financial estimation to justify investment in controls. Third, to critically evaluate the assessment methodology itself and conclude with prioritised, proportionate recommendations appropriate to an organisation of this size, consistent with the UK National Cyber Security Centre’s (NCSC, 2023) guidance that SME security measures should be proportionate to risk rather than modelled uncritically on enterprise practice.
The scope of the assessment is deliberately bounded to reflect what a single external consultancy engagement of this kind could realistically cover: it addresses the practice’s core information assets, the systems and third-party services through which client data is processed and stored, and the human and procedural factors most directly implicated in the highest-profile threats affecting comparable organisations. Physical security of the practice’s single office premises and the security posture of its outsourced payroll bureau are noted as adjacent areas but are excluded from detailed analysis, consistent with the engagement’s agreed terms of reference; both are flagged in the recommendations as candidates for a follow-on assessment.
The assessment follows the risk management process set out in ISO/IEC 27005 (2022), which structures information security risk assessment into context establishment, risk identification, risk analysis, risk evaluation and risk treatment, and is broadly consistent with the process described in NIST Special Publication 800-30 (NIST, 2012). Context establishment involved a review of Thornfield Associates’ information assets, business processes and existing controls, based on a structured walkthrough of its IT environment: a cloud-hosted accounting platform, an on-premises file server holding archived client records, staff laptops with local and cloud storage, a hosted email system, and an office Wi-Fi network serving both staff and visitors. Evidence for this context-setting stage was gathered through a structured interview with the practice’s operations manager, a review of existing IT policy documents and supplier contracts, and a technical walkthrough of key systems conducted jointly with the practice’s outsourced IT support provider, an approach to evidence-gathering consistent with the “understand the organisation” activity specified in ISO/IEC 27005 (2022).
Likelihood and impact were each scored against explicit descriptors rather than left to unstructured judgement, in order to improve consistency and defensibility of the resulting risk register. On the likelihood scale, a score of 5 (“almost certain”) was defined as an event expected to occur multiple times per year based on sector threat intelligence and the organisation’s current control gaps, while a score of 1 (“rare”) was defined as an event not expected to occur within a five-year horizon absent a significant change in circumstances. On the impact scale, a score of 5 (“severe”) was defined as an event causing sustained operational disruption of more than five working days, a reportable personal data breach under the UK GDPR, or client losses sufficient to threaten the practice’s ongoing viability, while a score of 1 (“negligible”) was defined as an event causing no measurable disruption or financial loss beyond routine remediation effort. Anchoring the ordinal scales to these concrete descriptors, an approach recommended by Whitman and Mattord (2021), reduces the risk that different assessors would apply the scale inconsistently and makes the resulting scores easier to defend to the practice’s partners.
Risk identification combined asset-based and threat-based approaches, cross-referencing each identified asset against relevant threat categories drawn from the NCSC’s (2023) small business guidance and recent sector threat intelligence, including the annual Verizon Data Breach Investigations Report (Verizon, 2023), which consistently identifies phishing, stolen credentials and ransomware as the threat categories most frequently implicated in breaches affecting smaller organisations. For each identified asset-threat pairing, likelihood and impact were scored independently on five-point ordinal scales (1 = rare/negligible to 5 = almost certain/severe), following the qualitative scoring approach recommended in ISO/IEC 27005 and widely used in practice (Whitman and Mattord, 2021). Likelihood scores reflected both the general prevalence of the threat in the sector and specific characteristics of Thornfield Associates’ controls at the time of assessment, such as the absence of multi-factor authentication (MFA) on several systems. Impact scores reflected potential financial loss, operational disruption, regulatory exposure under the UK GDPR and Data Protection Act 2018, and reputational damage to a professional services firm whose business depends on client trust.
A composite risk score was calculated for each risk as the product of its likelihood and impact scores (score range 1-25), categorised as Low (1-6), Medium (7-14) or High (15-25), a simple but widely adopted approach that supports rapid prioritisation while remaining transparent to non-specialist stakeholders such as the practice’s partners (Sommestad, Ekstedt and Johnson, 2010).
Table 1 presents the six highest-priority risks identified through this process, ranked by composite risk score.
| Asset | Threat | Likelihood (1-5) | Impact (1-5) | Risk Score | Rating |
|---|---|---|---|---|---|
| Cloud accounting platform & client records | Ransomware attack via phishing | 4 | 5 | 20 | High |
| Staff laptops | Credential theft via phishing | 4 | 4 | 16 | High |
| Hosted email system | Business email compromise / invoice fraud | 3 | 4 | 12 | Medium |
| Cloud accounting platform | Account takeover (no MFA) | 3 | 4 | 12 | Medium |
| Backup systems | Backup failure / no offline copy | 2 | 5 | 10 | Medium |
| Office Wi-Fi network | Unauthorised access via weak encryption | 2 | 3 | 6 | Low |
The highest-scoring risk – a ransomware attack against the cloud accounting platform and associated client records, most plausibly delivered via a phishing email to a staff member without MFA enabled – was selected for further quantitative analysis, following the loss-expectancy approach set out by Whitman and Mattord (2021). A plausible attack scenario was sketched to ground the quantitative estimates that follow: an employee receives a convincing phishing email impersonating a known supplier, clicks a malicious link on a laptop without up-to-date endpoint protection, and enters their credentials into a spoofed login page; because MFA is not enforced on the cloud accounting platform, the harvested credentials are sufficient for an attacker to access and encrypt client financial records directly within the cloud environment, triggering both an operational crisis and a potential UK GDPR notification obligation to the Information Commissioner’s Office. The Single Loss Expectancy (SLE) was first estimated as the product of the asset’s estimated value and an exposure factor representing the proportion of that value likely to be lost in a single incident:
Asset value (incident cost estimate) = £180,000, comprising incident response and forensic costs, system recovery, business downtime during remediation, and estimated regulatory and client-notification costs under the UK GDPR in the event client personal data is affected.
Exposure factor (EF) = 0.70, reflecting an assumption that a well-configured (if imperfect) backup regime would allow partial but not complete recovery without full loss of the estimated asset value.
SLE = Asset Value × EF = £180,000 × 0.70 = £126,000
The Annualised Rate of Occurrence (ARO) was then estimated at 0.25 (approximately once every four years), informed by NCSC (2023) and Verizon (2023) sector data on ransomware incidence among UK SMEs of comparable size and profile in the absence of MFA and modern endpoint protection. The Annualised Loss Expectancy (ALE) was then calculated:
ALE (before controls) = SLE × ARO = £126,000 × 0.25 = £31,500
This figure represents the expected annual cost of this single risk if left untreated, and was used to test the business case for a proposed control package – enforced MFA, an endpoint detection and response (EDR) tool, and an immutable, offline-replicated backup – estimated to cost £8,000 per year. Assuming this package reduces the ARO from 0.25 to 0.05 (roughly once every twenty years) by closing the most likely attack path and ensuring reliable recovery, the post-control ALE becomes:
ALE (after controls) = £126,000 × 0.05 = £6,300
A Return on Security Investment (ROSI) figure was then calculated to express the value of this control package relative to its cost:
ROSI = (ALEbefore − ALEafter − Cost of Control) / Cost of Control
= (£31,500 − £6,300 − £8,000) / £8,000
= £17,200 / £8,000 = 2.15 (215%)
A ROSI of 215% provides a clear, board-level justification for the proposed control package, translating a qualitative “High” risk rating into a concrete financial argument that non-technical partners at Thornfield Associates can use to approve the associated budget.
The risk assessment methodology adopted here has clear strengths for an SME context. The ISO/IEC 27005-aligned process is structured, repeatable and produces outputs – the risk matrix and prioritised risk register – that are easy for non-specialist decision-makers to interpret, supporting the proportionality principle the NCSC (2023) recommends for smaller organisations. Complementing the qualitative matrix with a worked ALE and ROSI calculation for the top risk addresses a common criticism of purely qualitative risk matrices: that ordinal scores of “High”, “Medium” and “Low” can obscure very different magnitudes of actual financial exposure and make it difficult to compare the cost-effectiveness of competing control investments (Sommestad, Ekstedt and Johnson, 2010). By pairing the matrix with a single worked ALE and ROSI calculation, the assessment gives Thornfield Associates’ partners both a quick, intuitive prioritisation tool and a more rigorous financial justification for the specific investment decision that follows directly from it, without requiring the full analytical overhead of quantifying every row in the risk register in monetary terms.
Nonetheless, several limitations qualify the assessment’s reliability. First, likelihood and impact scores, and the ARO and exposure-factor estimates underlying the loss-expectancy calculation, are ultimately subjective judgements informed by sector data and professional experience rather than organisation-specific incident history, which Thornfield Associates does not maintain in sufficient detail to support statistical estimation. Sensitivity analysis – recalculating the ALE and ROSI under more conservative assumptions, for example an ARO of 0.15 rather than 0.25 – would strengthen confidence in the business case; at ARO = 0.15, the pre-control ALE falls to £18,900, still comfortably exceeding the £8,000 control cost, suggesting the recommendation is reasonably robust to moderate changes in this assumption.
Second, the risk register in Table 1 treats each asset-threat pairing largely independently, whereas in practice several of the identified risks are causally linked: the absence of MFA that elevates the ransomware and account-takeover risk scores is a single underlying control gap, meaning that a single well-chosen intervention (MFA enforcement) would reduce multiple risk scores simultaneously rather than requiring separate, additive investment. A more sophisticated attack-path or bow-tie analysis would make these dependencies explicit and might reveal that the most cost-effective control portfolio differs from one selected by treating each risk in the register in isolation.
Third, the assessment is a point-in-time exercise; both the threat landscape (reflected in annually updated sources such as the Verizon DBIR) and Thornfield Associates’ own systems and staff will change, meaning the risk register requires scheduled review – the NCSC (2023) and ISO/IEC 27005 (2022) both recommend at least annual review, with earlier reassessment triggered by significant changes such as new systems, mergers or notified incidents at similar organisations.
It is also worth situating the approach taken here against more formal quantitative alternatives, particularly the Factor Analysis of Information Risk (FAIR) framework, which decomposes loss expectancy into probability distributions for threat event frequency and loss magnitude rather than the single-point ARO and exposure-factor estimates used above, and propagates uncertainty through Monte Carlo simulation to produce a range of plausible annualised loss rather than one figure (Freund and Jones, 2015). A full FAIR analysis would likely produce a more defensible and nuanced loss estimate than the single-point ALE calculated here, and would be a reasonable next step were Thornfield Associates a larger organisation with the analytical capacity and data maturity to support it. For a forty-five-employee accountancy practice at the start of its Cyber Essentials Plus journey, however, the simpler point-estimate approach adopted in this assessment offers a defensible balance between analytical rigour and the proportionality principle central to the NCSC’s (2023) SME guidance, while the sensitivity check performed above provides a lightweight substitute for full probabilistic uncertainty analysis.
This assessment identifies ransomware delivered via phishing against the cloud accounting platform as Thornfield Associates’ highest-priority information security risk, with a worked annualised loss expectancy of approximately £31,500 in its current, largely untreated state. A proposed control package of enforced multi-factor authentication, endpoint detection and response tooling, and immutable offline-replicated backups is estimated to reduce this exposure to approximately £6,300 per year at a cost of £8,000, yielding a return on security investment of around 215% and providing a clear, financially grounded justification for immediate investment.
Three further recommendations follow. First, MFA enforcement should be prioritised as an immediate, low-cost intervention given its effect on multiple risks simultaneously, ahead of the more resource-intensive backup and EDR rollout. Second, Thornfield Associates should begin logging security-relevant incidents and near-misses systematically, even informally, to build the organisation-specific evidence base needed to refine likelihood estimates in future assessment cycles rather than relying solely on sector-wide data. Third, the risk register should be formally reviewed at least annually, and immediately following any significant change to systems or staffing, with progress towards Cyber Essentials Plus certification used as an external forcing function to sustain momentum on the lower-scoring, but still material, risks identified in Table 1.
Finally, the two excluded areas noted in the scope of this assessment – physical premises security and the security posture of the outsourced payroll bureau – should not be treated as out of scope indefinitely. Given that the payroll bureau processes a comparable volume of sensitive personal data to the practice’s own systems, a supplier security review, including a request for evidence of the bureau’s own Cyber Essentials or equivalent certification, is recommended within the next assessment cycle to close this visibility gap in Thornfield Associates’ overall risk picture.
Need a Model Assignment Written to Your Exact Brief?
Our 350+ UK-qualified writers deliver referenced model documents from £15 per 250 words, with free plagiarism and AI-detection reports.
You May Also Like