How the Enhanced Risk Register Works
Start from the Risk Register on any client account. Users with the Editor or Admin role can make changes; Viewers can see the register but not edit it. Add your own risks for anything the standard library doesn’t cover, or adapt one of Cynomi’s standard risks by duplicating it and adjusting the wording, while leaving the original system risk untouched. If a client already has an established register, bring it in directly from an .xlsx or file instead of rebuilding it by hand, and export the register later for a client deliverable or an offline review. Both live inside Cynomi’s Risk Management capability page.
Every risk should carry the tasks meant to reduce it. Open a risk and review Cynomi’s suggested task links, each with a rationale and a confidence level, then confirm the ones that apply. Nothing links automatically, so the connection between exposure and remediation always reflects your judgment. You can also add tasks manually from the client’s full task list if a suggestion misses something.
Set a treatment for each risk: Mitigate, Accept, Transfer or Avoid. When the client chooses to accept a risk rather than remediate it, Cynomi’s formal acceptance workflow records who made the decision, when, why and for how long, so risk acceptance lives in the register rather than in a meeting note or a separate spreadsheet.
As the engagement progresses, deactivate risks that no longer apply without losing their history, reactivate them if circumstances change, and set review dates so a risk that hasn’t been revisited doesn’t get lost. Once you’ve set a tolerance threshold for a client, the register shows you whether their current risk sits within or exceeds it.
What the Enhanced Risk Register Means for Your Practice
For vCISOs and risk leads running ongoing advisory engagements, the register can now reflect the risks a client actually carries, including risks that come from their industry, their operations or their own risk methodology, rather than forcing every client through the same standard list.
Bringing an existing register in from a spreadsheet means a client with an established risk program doesn’t need it rebuilt from scratch, and linking risks directly to mitigating tasks gives your team and the client a clear, shared view of which security work is addressing which exposure.
Formal risk acceptance gives you a documented answer when a client’s leadership asks why a particular risk was carried rather than remediated: who decided, when, why, and for how long. That record supports client reviews and QBRs where treatment decisions come up, and it holds up on its own without you having to reconstruct the reasoning from notes or email.
Because the register is scoped to each client account, none of this changes how any other client’s register looks or behaves. Every client’s risk program stays its own.
See the Enhanced Risk Register for Yourself
Cynomi’s enhanced Risk Register is now available to all partners as of version 3.45.0.
Log in and open any client’s Risk Register to add a custom risk, bring in an existing register, or record your first formal risk acceptance. Or contact your Cynomi Partner Account Manager for a walkthrough.