# Risk Assessment

> Give leadership a prioritized view of where security risk concentrates and what to address first.

Canonical page: https://www.guvenkaya.co/services/risk-assessment

**Know which security risks to address first.** An assessment across systems, vendors, people, and controls that ends in one ranked list of where risk concentrates and what to fix first.

## What we assess

We rank risks by impact, likelihood, and the strength of existing controls, then assign remediation priorities and owners.

- **Where the impact lands**: We start from business impact and work back to the systems that concentrate it, rather than assessing everything evenly.
- **What is holding**: We assess the evidence that prevention, detection, response, and recovery controls work in practice.
- **Who owns the decision**: We establish where security decisions get made, who is accountable, and what evidence exists when someone asks.
- **What you can realistically fix**: We size remediation against the team and the time you actually have, so the sequence survives contact with the roadmap.

## Best used when you need to know what to fix first.

- **When leadership needs clarity**: Leadership needs a clear account of the risks, priorities, and owners.
- **Before an external assessment**: A regulator, auditor, insurer, investor, or customer needs evidence of how risks are managed.
- **When priorities are unclear**: The program has many findings but no clear sequence.
- **When your risk profile changes**: A new product or program changes the organization's exposure.

## How we turn risk evidence into priorities.

1. **Define the decision and gather evidence**: Agree the leadership, investment, or remediation decision. Review architecture, controls, and incident history, and record gaps in the available evidence.
2. **Map where risk accumulates**: Trace failure scenarios across systems and teams. Assess likelihood, impact, and control strength to show where exposure is concentrated.
3. **Rank actions and assign owners**: Prioritize decisions and remediation based on the evidence and the team’s capacity. Agree owners and explain the order of work.
4. **Prepare the executive readout**: Summarize the material risks, evidence gaps, and recommended sequence of decisions so leadership can act on the assessment.

## Deliverables

- **Risk concentration map**: Where material exposure accumulates across the organization.
- **Prioritized decisions**: One ranked list, with an owner against each item and an order we can defend.
- **Executive readout**: A concise view of material risk and sequencing.

## Engagement team

- **Piotr Cielas**, Principal Advisor: Financial-services assessments, offensive security, risk leadership, CVEs, and patents.
- **Paul Vijender**, Specialist Advisor: Product security, IAM, cloud, network, data, DevSecOps, blockchain, and AI leadership.
- **Timur Güvenkaya**, Founder & Partner: Rust-based and non-EVM systems, protocol security, architecture, infrastructure, and custody.

## Frequently asked questions

### How is this different from a penetration test?

A penetration test validates attack paths in a system. A risk assessment examines evidence across systems, vendors, people, and controls to prioritize what to address.

### Do you need to scan or test our systems?

Not usually. The assessment runs on architecture, controls, evidence, and interviews with the people who operate the systems. Where a claim cannot be substantiated any other way, we say so rather than assume it holds.

### We already have a list of findings. Why do this?

We help rank the findings, assign owners, and sequence remediation against your team’s capacity and business priorities.

### Who is the output written for?

Leadership, boards, regulators, auditors, insurers, and institutional customers. It is written to be read by someone who is not an engineer, with the technical detail kept underneath rather than removed.

### Can you use our existing audits and assessments?

Yes. Existing reports, remediation records, incident reviews, and control evidence can inform the assessment. We check what they cover, whether the system has changed, and where evidence is still missing.

### What happens if the evidence is incomplete?

We identify the gaps and explain which conclusions they limit. Where a decision depends on an unverified control or assumption, we state what further evidence or testing is needed.

## Related services

- [Secure Architecture & Process Design](https://www.guvenkaya.co/services/secure-architecture-process-design.md): Design or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.
- [Penetration Testing](https://www.guvenkaya.co/services/penetration-testing.md): Test the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.
- [Digital Asset Program Advisory](https://www.guvenkaya.co/services/digital-asset-program-advisory.md): Make security, custody, vendor, and operating-model decisions across a broader digital asset program.

## Make the next security decision clearer.

Describe your main concerns, the decision you need to make, and who needs the results. We will define the assessment scope.

Discuss your scope: https://www.guvenkaya.co/contact
