Free Tool

Cyber Risk Matrix Builder

Build a simple cyber risk register and custom 5x5 risk matrix from the risks your team already knows about. Add likelihood, impact, owners, treatment decisions, status, target dates, and current controls, then export the register as CSV or print the matrix for a leadership discussion.

This tool does not generate risks for you. That is intentional. A useful cyber risk matrix should reflect your business context, systems, vendors, obligations, incidents, and leadership decisions.

What you can export

  • Risk ID and title
  • Category and affected asset or process
  • Likelihood, impact, and rating
  • Owner, treatment, status, and target date
  • Existing controls or next notes
When To Use It

A lightweight matrix for real security conversations.

The goal is not mathematical perfection. The goal is to make risk visible enough that executives, security owners, privacy, IT, legal, and product teams can decide what needs action and what is being accepted.

You need a board-ready view of cyber risk without buying a full GRC platform.

You are turning a workshop, audit finding, customer request, or vendor concern into a practical register.

You want owners, treatment decisions, and target dates beside the 5x5 matrix instead of a standalone heat map.

You need a simple exportable CSV that can move into Jira, a spreadsheet, a board packet, or a remediation plan.

Risk Matrix Tool

Create the register, then use the matrix to prioritize.

Add known risks one by one. The tool places each risk in the matrix based on likelihood and impact, then keeps the risk register below the matrix so owners and treatment decisions do not get separated from the visual.

Step 1

Make your matrix first

Start with the default Custom 5x5 risk matrix, then customize the ratings if your leadership, regulator, insurer, or board uses a different risk appetite. Changes update the summary cards, register ratings, and CSV export.

LowModerateHighCritical
Likelihood
Impact 1
Impact 2
Impact 3
Impact 4
Impact 5
5 - Almost Certain81-100% chance within the next 5 years
Moderate
High
Critical
Critical
Critical
4 - High61-80% chance within the next 5 years
Moderate
Moderate
High
Critical
Critical
3 - Moderate41-60% chance within the next 5 years
Low
Moderate
Moderate
High
Critical
2 - Low21-40% chance within the next 5 years
Low
Low
Moderate
Moderate
High
1 - Very Low<20% chance within the next 5 years
Low
Low
Low
Moderate
Moderate
1 - Very Low
2 - Low
3 - Moderate
4 - High
5 - Critical
Total Risks
0
Critical
0
High
0
Missing Owner
0

Step 2

Add risks to your register

GreenHat does not guess your risks for you. Add the risks your team already knows about, score likelihood and impact, then use the matrix to make prioritization visible.

Risk register template

Use the table as a lightweight working register. Export it when you need to brief leadership, hand work to owners, or turn the assessment into a remediation plan.

IDRiskRatingOwnerTreatmentStatusTargetControlsAction
Add your first risk to populate the register and matrix.
Impact 1

Very Low

<$4,999, limited internal awareness, no impact on continued compliance

Impact 2

Low

$5,000-$24,999, most staff know, potential for non-compliance

Impact 3

Moderate

$25,000-$99,999, some external awareness, non-compliance is likely

Impact 4

High

$100,000-$499,999, media or customer attention, potential penalties

Impact 5

Critical

>$500,000, regulator or customer impact, lawsuits or serious penalties