Skip to content
IT risk assessment

The foundation of your IT risk assessment

Every IT risk assessment starts with one question: what do we actually have? Most companies fall down here. Ejerblik maps your digital assets, so the foundation is in place before you assess the risk.

Risk assessment has become a management responsibility

The NIS2 Directive is being transposed into national law across the EU and sets requirements for risk management, incident handling and documentation of digital assets and suppliers for a broad range of companies. A central point: senior management must approve the risk management and can be held personally accountable.

IT security is therefore no longer only the IT department's job. But whether or not your company is directly in scope, the same basic rule applies: you cannot assess the risk of something you do not know you have. So the work begins with mapping the assets.

A solid basis you can stand behind

  • A complete asset register with an owner, a responsible person and a risk status per asset
  • An IT risk assessment audit structured around the four asset categories
  • Automatic flagging of missing documentation, expiry and unclear ownership
  • A prioritised overview, so the most serious risks stand out first
  • Documentation ready for management, an accountant or an IT adviser

From a blank page to a prioritised action plan with Ejerblik

  1. Map

    Record your assets with owner, responsible person and access. The account scanner finds forgotten subscriptions for you.

  2. Assess

    Work through the IT risk assessment audit with the four asset categories and the impact section.

  3. Prioritise

    See impact and risk together, so the most serious risks stand out first.

  4. Act

    Attach a responsible person and a deadline to each action point, and record management approval.

How it looks in Ejerblik

A padlock on a laptop, digital risk and data security
app.ejerblik.com
Ejerblik audits and risk assessment, actual screenshot
Step 1: asset identification

The four categories you need to map

  • Information and data. Customer data, personal data, contracts and trade secrets. Mark what is business-critical and what is personally sensitive.
  • Software and systems. CRM, ERP, finance, email, hosting and subscriptions, with owner, access and renewal date per system.
  • Hardware and devices. Computers, phones, servers and network equipment, and who uses and is responsible for them.
  • People and key persons. Who has access to what, and where are the single-person dependencies that are a risk?

How Ejerblik covers CIS18

Control 2 · Inventory of software
The core of the asset register: systems, subscriptions and licences
Control 5 · Account management
The employee directory links people to accounts and platforms
Control 6 · Access control
Documented access, administrator rights and two-factor status
Control 15 · Supplier management
The supplier behind each asset is recorded and can be risk-assessed

The foundation, not the whole journey

An IT risk assessment builds on a complete picture of what the company holds of value. Ejerblik covers all four categories in one system.

Many IT advisers point owner-managers towards CIS18, the recognised framework for cybersecurity. Several of the foundational controls start with an inventory of software, accounts and access. That is exactly what Ejerblik provides.

Ejerblik does not implement the technical measures in the controls. We provide the inventory and the documentation that is the precondition for meeting them at all. To see the whole picture, our coverage of both CIS18 and NIS2 is set out control by control on the coverage page, including what we do not cover.

Ejerblik is a documentation tool and a management aid. It provides step 1 and the frame around the risk assessment, but it does not replace the professional assessment of complex technical threats by an IT security expert. For most owner-managed companies, a complete, up-to-date asset register is exactly the foundation that is missing today.

Put the foundation in place

Get started free and map your digital assets. Step 1 of your IT risk assessment typically takes under half a day.

No lock-in · Data in the EU · Support in English