Risk assessments are required by nearly every major compliance framework.. but most organizations approach them as a documentation exercise rather than a genuine evaluation of exposure. The result is a report that satisfies an auditor but doesn’t actually help leadership make better decisions.
Thorium’s risk assessments are grounded in real threat analysis. We identify the threats relevant to your industry, evaluate the effectiveness of your existing controls, and quantify risk in language your board can understand and act on. Delivered in alignment with NIST SP 800-30, every assessment produces findings that are both examiner-ready and operationally useful.
AT A GLANCE
• Aligned to NIST SP 800-30 methodology
• Covers people, process, and technology
• Threat scenarios tailored to your industry
• Board-ready executive summary included
• Satisfies FFIEC, HIPAA, and CMMC requirements
Request a Scoping Call →
Average total cost of a data breach, climbing year over year
Average time to identify and contain a breach without a mature risk program
The NIST risk methodology every engagement is built on, end to end
Of major compliance frameworks require a documented, current risk assessment
ASSESSMENT METHODOLOGY
A Structured Path From Scope to Roadmap
01
Scope & Objectives
02
Asset & Data Inventory
03
Threat Modeling
04
Control Evaluation
05
Risk Scoring
06
Report & Roadmap
ASSESSMENT DOMAINS
What a Thorium Risk Assessment Covers
We evaluate risk across people, process, and technology, mapping every finding to a likelihood and a business impact rather than a generic checklist.
GOVERNANCE / PROGRAM
Governance & Program Maturity
We evaluate policies, risk ownership, and whether your security program is genuinely operating, not just documented.
POLICY
RISK REGISTER
OWNERSHIP
IDENTITY / ACCESS
Identity & Access Management
Least-privilege, MFA coverage, privileged accounts, and joiner-mover-leaver hygiene across every system that touches sensitive data.
MFA
LEAST PRIVILEGE
OFFBOARDING
DATA / ASSETS
Data & Asset Inventory
Data classification, crown-jewel identification, and the shadow IT that never made it onto the official asset list.
CLASSIFICATION
CROWN JEWELS
SHADOW IT
INFRASTRUCTURE
Network & Infrastructure
Segmentation, patch cadence, external exposure, and configuration drift across on-prem and cloud environments.
SEGMENTATION
PATCHING
EXPOSURE
THIRD-PARTY
Vendor & Supply-Chain Risk
SaaS sprawl, vendor due diligence, and the contractual and technical risk your third parties quietly introduce.
SUPPLY CHAIN
SaaS
DUE DILIGENCE
RESILIENCE
Backup, DR & Incident Response
Backup integrity, recovery objectives, and whether your incident response plan survives contact with a real event.
BACKUPS
DR / BCP
IR PLAN
HOW WE SCORE RISK
Likelihood × Impact, Not Guesswork
Every finding is rated on how likely it is to be exploited and what it would cost you if it were. That produces a defensible, prioritized risk score your leadership can act on, rather than an undifferentiated list of problems.
Critical
Immediate exposure to sensitive data or operations. Remediate now.
High
A serious weakness likely to be exploited. Prioritize this quarter.
Medium
A meaningful gap with limited immediate impact. Plan remediation.
Low
A minor hygiene issue. Address opportunistically as capacity allows.
WHAT YOU RECEIVE
Documentation Built for Boards and Examiners
Executive Risk Briefing
A plain-language summary of your overall risk posture and the priority areas that deserve investment.
Examiner Evidence Package
Documentation formatted for direct submission to NCUA, HIPAA auditors, and other regulatory examiners.
Prioritized Risk Register
Every finding scored by likelihood and impact and ranked so your team can act in the right order.
Remediation Roadmap
Sequenced fixes mapped to owners and realistic timelines, from quick wins to strategic investments.
