Methodology

Axiona Risk Diagnostic Cycle

The Axiona Risk Diagnostic Cycle is based on internationally recognized risk management and resilience frameworks, including COSO ERM, ISO 31000, NIST CSF, and ISO 22301, adapted for executive-level diagnostics.


7 stages — from understanding the context to the final executive deliverables package.

01
Context & Scope
All domains

Executive interviews, analysis of business context, definition of diagnostic scope, risk appetite, and critical services. Establishing a baseline understanding of the organization, IT landscape, and vendors.

Context BriefScope DefinitionStakeholder MapInformation Request List
02
Target Profile & Critical Processes
Operational

Define the target level of resilience and identify critical business processes. Establish the linkage “process → assets → dependencies → owners,” focusing only on elements that affect operational continuity.

Critical Process Map (Tier 1–3)Asset & Dependency MapTarget Profile SummaryProcess Owners List
03
Risk Identification
Human · Cyber · Ops

Identify risks across three domains through interviews, practice reviews, and selective assessments. Document threats, vulnerabilities, and potential impacts on critical processes.

Risk Register (draft)Interview NotesRisk StatementsDomain Mapping
3.1 Quick Wins Scan — conducted in parallel

Identify immediate risk reduction measures before the full diagnostic is completed. The client receives a Quick Wins Log and Client Decision Record already at this stage.

04
Risk Analysis & Prioritization
All domains

Assess the likelihood and impact of each risk. Produce a management-level view of priorities: what is critical, what is acceptable, and what requires immediate attention.

Risk HeatmapPrioritized Risk RegisterTop-10 RisksRisk Analysis Summary
05
Risk Treatment & Roadmap
All domains

Define mitigation measures for each critical risk, develop a 30-60-90 day roadmap, and provide control recommendations. Assess the need for Security Awareness Training.

Risk Treatment PlanPOA&M / 30-60-90 RoadmapControl RecommendationsAwareness Need Assessment
06
Financial Impact Modeling
Semi-quantitative

Estimate financial consequences of key risks under realistic and worst-case scenarios. Use ranges instead of precise figures, with explicit assumptions. Led by the team’s financial analyst.

Financial Impact BriefLoss ScenariosAssumptions & Notes
07
Implementation Options
Next steps

Provide options for further actions: what can be implemented internally, what should be outsourced, whether Security Awareness is needed, and how it may be structured.

Implementation Options PaperService ProposalsNext StepsOptional Engagement Plan