Home / Tools / ISO 27001 Risk Calculator

ISO 27001 Risk Calculator

Score each risk as Likelihood × Impact, document existing controls and treatment options, then export a CSV risk register. Risk-level thresholds are configurable in one place (RISK_CONFIG).

⚠️ This tool is for informational purposes only and does not replace a professional risk assessment, audit, or certification body review.
Risk Score
Set L & I

Want AI-powered remediation recommendations?

CyberVerse AI turns your risk register into a prioritized treatment plan with control recommendations mapped to ISO 27001 Annex A.

Analyse with CyberVerse AI →

How the ISO 27001 risk score works

ISO/IEC 27001 requires organizations to identify, analyse and evaluate information security risks, then select appropriate treatment options and controls (Annex A). This calculator uses the common quantitative shortcut Risk Score = Likelihood × Impact on a 5×5 scale. Default bands: 1–4 Low, 5–9 Medium, 10–16 High, 17–25 Critical. Documenting existing controls and owners turns a raw score into an auditable risk register entry.

Related tools

All free tools → · CVSS Calculator (coming soon) · ISO 27001 Gap Assessment (coming soon)