The foundation of your IT risk assessment
Every IT risk assessment starts with one question: what do we actually have? Most companies fall down here. Ejerblik maps your digital assets, so the foundation is in place before you assess the risk.
Risk assessment has become a management responsibility
The NIS2 Directive is being transposed into national law across the EU and sets requirements for risk management, incident handling and documentation of digital assets and suppliers for a broad range of companies. A central point: senior management must approve the risk management and can be held personally accountable.
IT security is therefore no longer only the IT department's job. But whether or not your company is directly in scope, the same basic rule applies: you cannot assess the risk of something you do not know you have. So the work begins with mapping the assets.
A solid basis you can stand behind
- A complete asset register with an owner, a responsible person and a risk status per asset
- An IT risk assessment audit structured around the four asset categories
- Automatic flagging of missing documentation, expiry and unclear ownership
- A prioritised overview, so the most serious risks stand out first
- Documentation ready for management, an accountant or an IT adviser
From a blank page to a prioritised action plan with Ejerblik
Map
Record your assets with owner, responsible person and access. The account scanner finds forgotten subscriptions for you.
Assess
Work through the IT risk assessment audit with the four asset categories and the impact section.
Prioritise
See impact and risk together, so the most serious risks stand out first.
Act
Attach a responsible person and a deadline to each action point, and record management approval.
How it looks in Ejerblik


The four categories you need to map
- Information and data. Customer data, personal data, contracts and trade secrets. Mark what is business-critical and what is personally sensitive.
- Software and systems. CRM, ERP, finance, email, hosting and subscriptions, with owner, access and renewal date per system.
- Hardware and devices. Computers, phones, servers and network equipment, and who uses and is responsible for them.
- People and key persons. Who has access to what, and where are the single-person dependencies that are a risk?
How Ejerblik covers CIS18
- Control 2 · Inventory of software
- The core of the asset register: systems, subscriptions and licences
- Control 5 · Account management
- The employee directory links people to accounts and platforms
- Control 6 · Access control
- Documented access, administrator rights and two-factor status
- Control 15 · Supplier management
- The supplier behind each asset is recorded and can be risk-assessed
The foundation, not the whole journey
An IT risk assessment builds on a complete picture of what the company holds of value. Ejerblik covers all four categories in one system.
Many IT advisers point owner-managers towards CIS18, the recognised framework for cybersecurity. Several of the foundational controls start with an inventory of software, accounts and access. That is exactly what Ejerblik provides.
Ejerblik does not implement the technical measures in the controls. We provide the inventory and the documentation that is the precondition for meeting them at all. To see the whole picture, our coverage of both CIS18 and NIS2 is set out control by control on the coverage page, including what we do not cover.
Ejerblik is a documentation tool and a management aid. It provides step 1 and the frame around the risk assessment, but it does not replace the professional assessment of complex technical threats by an IT security expert. For most owner-managed companies, a complete, up-to-date asset register is exactly the foundation that is missing today.
Put the foundation in place
Get started free and map your digital assets. Step 1 of your IT risk assessment typically takes under half a day.
No lock-in · Data in the EU · Support in English