Release 3.45.0

Cynomi’s Enhanced Risk Register: Built Around Each Client

Each client carries risks that don't fit a standard security risk library: industry-specific exposures, operational quirks, or risks already tracked in a separate spreadsheet. Cynomi's enhanced Risk Register lets you build the register around each client's actual risks instead of working from a fixed list, then connect those risks to the mitigating work and decisions behind them. The result is a living, client-specific register that connects risk, action, decision and review in one place.

Risk Management

How the Enhanced Risk Register Works

Start from the Risk Register on any client account. Users with the Editor or Admin role can make changes; Viewers can see the register but not edit it. Add your own risks for anything the standard library doesn’t cover, or adapt one of Cynomi’s standard risks by duplicating it and adjusting the wording, while leaving the original system risk untouched. If a client already has an established register, bring it in directly from an .xlsx or file instead of rebuilding it by hand, and export the register later for a client deliverable or an offline review. Both live inside Cynomi’s Risk Management capability page.

Every risk should carry the tasks meant to reduce it. Open a risk and review Cynomi’s suggested task links, each with a rationale and a confidence level, then confirm the ones that apply. Nothing links automatically, so the connection between exposure and remediation always reflects your judgment. You can also add tasks manually from the client’s full task list if a suggestion misses something.

Set a treatment for each risk: Mitigate, Accept, Transfer or Avoid. When the client chooses to accept a risk rather than remediate it, Cynomi’s formal acceptance workflow records who made the decision, when, why and for how long, so risk acceptance lives in the register rather than in a meeting note or a separate spreadsheet.

As the engagement progresses, deactivate risks that no longer apply without losing their history, reactivate them if circumstances change, and set review dates so a risk that hasn’t been revisited doesn’t get lost. Once you’ve set a tolerance threshold for a client, the register shows you whether their current risk sits within or exceeds it.

What the Enhanced Risk Register Means for Your Practice

For vCISOs and risk leads running ongoing advisory engagements, the register can now reflect the risks a client actually carries, including risks that come from their industry, their operations or their own risk methodology, rather than forcing every client through the same standard list.

Bringing an existing register in from a spreadsheet means a client with an established risk program doesn’t need it rebuilt from scratch, and linking risks directly to mitigating tasks gives your team and the client a clear, shared view of which security work is addressing which exposure.

Formal risk acceptance gives you a documented answer when a client’s leadership asks why a particular risk was carried rather than remediated: who decided, when, why, and for how long. That record supports client reviews and QBRs where treatment decisions come up, and it holds up on its own without you having to reconstruct the reasoning from notes or email.

Because the register is scoped to each client account, none of this changes how any other client’s register looks or behaves. Every client’s risk program stays its own.

See the Enhanced Risk Register for Yourself

Cynomi’s enhanced Risk Register is now available to all partners as of version 3.45.0.

Log in and open any client’s Risk Register to add a custom risk, bring in an existing register, or record your first formal risk acceptance. Or contact your Cynomi Partner Account Manager for a walkthrough.

Frequently Asked Questions About Cynomi's Enhanced Risk Register

Who can make changes to a client's Risk Register?

Users with the Editor or Admin role in the client account can add, adapt and update risks. Viewers can see the register but cannot make changes.

Can I bring in a risk register I already manage outside Cynomi?

Yes. Use bulk upload to bring in an existing register from an .xlsx or .csv file instead of rebuilding it manually, up to 100 risks per file.

Does duplicating a standard risk change Cynomi's original version?

No. Duplicating a standard risk creates a separate, editable copy for that client, and the original system risk keeps its original wording and score.

Are mitigating tasks linked to a risk automatically?

No. Cynomi suggests task links with a rationale and a confidence level, and you review and confirm each one before it's added to the risk.

Who decides whether a client accepts a risk instead of remediating it?

The client makes that decision. Cynomi's formal acceptance workflow records who accepted the risk, when, why and for how long, once the decision is made.

Will changes I make to one client's Risk Register affect other clients?

No. Every client's Risk Register is scoped to that client's account, so changes made for one client never affect another.

The Security Growth Platform
for Service Providers

Discover how Cynomi can help you standardize delivery, accelerate onboarding, and scale your CISO advisory services.