Measure 3 of Annex II of the Croatian Cybersecurity Regulation requires a documented risk management process with assessment, levels, owners and a treatment plan. Most organisations have a document that looks like that. A minority have one that survives questioning.
These are the recurring patterns, ordered by how quickly they are spotted.
1. The register is not linked to the asset inventory
The risk reads "data loss" or "cyber attack", with no indication of which asset. Such an entry can be neither treated nor verified - it is not clear what is being protected, nor when the risk has ceased to exist.
The Regulation explicitly ties the risk assessment to assets from the critical asset inventory. If the risk register and the asset register share no common reference, two measures that should stand on one another are standing next to one another instead.
Take a random row from the risk register and try to find the corresponding entry in the asset inventory. If that takes longer than a minute, the link does not exist.
2. Risks have a department, not an owner
The owner column says "IT". A department cannot decide to accept a risk, cannot be held accountable and cannot report to the board. The Regulation requires identification of risk owners and their area of responsibility - which means a person with a name.
The consequence is predictable: a risk owned by a department stays open for years because nobody individually is late.
3. The score exists, the reasoning does not
Likelihood 3, impact 4, level high. Why 3 and not 2? When was it last reviewed? Without a trace of reasoning, a score is a number that can be neither defended nor challenged.
This bites particularly in a self-assessment, where every score has to be defensible with evidence. A risk register whose scores were produced in a meeting without minutes creates the same problem one level up.
4. The treatment plan is a wish list
Treatment measures are phrased as "improve monitoring" or "consider additional protection", with no deadline, owner or resource estimate. That is not a treatment plan but a record of good intentions.
The Regulation requires the response to a risk to be proportionate to its level and criticality, through appropriate technical, operational and organisational measures. Proportionality cannot be assessed if the measure is not specific.
- Poor: "improve access management"
- Good: "enforce multi-factor authentication on all administrator accounts, owner M. K., due 31 March, estimated 12 working days"
5. The register never changes
The clearest signal that the system is not alive. The same thirty-two risks, the same scores, the only change being the date in the header. The Regulation requires the process to be updated annually, but substantive updating means something else: new risks come in, resolved ones are closed, scores change when circumstances do.
A register that has not changed after a new system went live, after a change of supplier or after an incident is telling you it is not used in decision-making but maintained for review.
What distinguishes a register that passes
Not size. We have seen hundred-row registers that fail and twenty-five-row registers that pass without comment. Five things separate them:
- Every risk points to an asset in the inventory.
- Every risk has a person as its owner.
- Every score carries a short justification and a date.
- Every treatment measure has a deadline, an owner and a resource estimate.
- There is a trace of the register changing, with a reason for the change.
The fifth is also the hardest to produce retrospectively, which is why the risk register is not something to leave until the end of a compliance project.
The risk register is an input to several other measures: it determines the level of implementation for conditional controls, it justifies the selection of measures in the compliance roadmap, and it connects to third-party risk assessment under measure 8. A weak risk register does not fail alone - it takes down everything that relies on it.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.