

Almost nothing on a real register is dramatic. A server past its warranty. A backup that reports success every night and has never been restored. A domain nobody remembers renewing. One person who knows how the phone system is wired.
None of them are urgent, right up until the morning they are.
Every business in the country takes health and safety risk seriously enough to write it down, review it and put a name beside each item. Technology risk rarely gets the same treatment, even though it can stop the business just as quickly.
We keep the list. Everything we can see across your environment, scored so the serious items are obvious at a glance, each with an owner and a date.
It gets reviewed with you rather than filed. Items get closed, new ones appear as hardware ages and circumstances change, and the register tells you what changed since last time.
The point isn't the document. It's that you can answer the question at the top of this page without having to guess.
Real examples from registers we maintain, with identifying detail removed. Every item gets a plain description, a consequence and a rating, so the conversation is about priorities rather than technology.
| Risk | What happens if it isn't addressed | Rating |
|---|---|---|
| Devices still running Windows 10 | Support has ended, so any vulnerability found from here on stays open on those machines permanently | High |
| No multi-factor authentication on remote access | A password on its own is enough to reach the network from anywhere in the world | High |
| Microsoft 365 data not backed up | Microsoft keeps the service running, not your data. Files deleted or encrypted may not be recoverable beyond a short window | High |
| Wireless password unchanged for years and shared with guests | Former staff and every visitor ever given the password can still reach the same network as your servers | Medium |
| No security awareness training in place | The most common way in is somebody doing something reasonable, and nobody has shown them what to look for | Medium |
Anything that could interrupt the business or cost money if it isn't dealt with. In practice that means hardware and software approaching end of life, backups that haven't been proven, gaps in security configuration, accounts with more access than they need, expiring domains and certificates, licence positions that have drifted, undocumented systems, and anywhere a single device or a single person is holding something up. Each entry gets a plain-language consequence and a rating, because a list without priorities is just a list.
An audit is a snapshot. Useful, but it starts going out of date the day it's delivered, and most businesses have one sitting in a folder somewhere. A register is maintained. Items close, new ones appear as equipment ages and the business changes, and you can see what moved since the last review. The value is in it being current rather than thorough once.
Some do it well. The straightforward way to find out is to ask for your current register and see what comes back. If it arrives quickly, is written so you can follow it and has ratings you can act on, you are in good hands. If it takes a fortnight or turns up as a list of alerts, that is worth knowing either way.
Quarterly suits most businesses, with the underlying monitoring running continuously rather than only at review time. It's also worth revisiting after anything significant, such as an office move, a system replacement or someone with a lot of knowledge leaving, since all three tend to create new entries at once.
Yes, though it depends what they're asking. Insurers and larger customers increasingly want evidence that risks are identified and being managed rather than a yes or no answer, and a current register with dates and owners is exactly that kind of evidence. We are not compliance specialists, so if you need to meet a formal standard we will say so and work alongside someone who does.
Yes. What we produce is yours regardless of what you decide afterwards. We would rather you had an accurate picture of your own business than feel you had to sign something to see it.