ISO 27001 Risk Calculator
Score each risk as Likelihood × Impact, document existing controls and treatment options, then export a CSV risk register. Risk-level thresholds are configurable in one place (RISK_CONFIG).
Want AI-powered remediation recommendations?
CyberVerse AI turns your risk register into a prioritized treatment plan with control recommendations mapped to ISO 27001 Annex A.
Analyse with CyberVerse AI →How the ISO 27001 risk score works
ISO/IEC 27001 requires organizations to identify, analyse and evaluate information security risks, then select appropriate treatment options and controls (Annex A). This calculator uses the common quantitative shortcut Risk Score = Likelihood × Impact on a 5×5 scale. Default bands: 1–4 Low, 5–9 Medium, 10–16 High, 17–25 Critical. Documenting existing controls and owners turns a raw score into an auditable risk register entry.
Related tools
All free tools → · CVSS Calculator (coming soon) · ISO 27001 Gap Assessment (coming soon)