ADD-ON · ENTERPRISE RISK MANAGEMENT

Risk sits on something concrete.

It sits on the processing activity, the system behind it and the supplier hosting the whole thing. Assess processes, assets and suppliers against the scenarios that actually apply to them, and get the risk level calculated for you.

Trusted by 400+ organisations
Watch a demo of risk assessment👇
GDPR-compliant
Hosted in EU
Free onboarding
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
A risk assessment of the VPN Gateway asset in .legal, showing a risk exposure of 150,000 EUR and two scenarios: hardware failure rated low, NIS2 non-compliance rated high

Not everything faces the same threats

A VPN gateway doesn't get hit by the same scenarios as a recruitment process. Pushing both through the same checklist produces assessments nobody trusts, and a lot of fields marked not applicable.

  • Three different entity types: Processes, assets and systems, and suppliers each carry their own kind of exposure.
  • Scenarios have to fit: A scenario list that applies to everything usually applies to nothing in particular.
  • Loose assessments aren't a picture: A pile of individual assessments only becomes useful once you can see them together.
Intro

From single assessments to a risk picture

A short look at how entities, scenarios and assessments fit together.

The risk scenario catalogue in .legal, each scenario tagged with the frameworks it belongs to and an entity type selector open on processing activity and asset

Choose which entities each risk area assesses

Before you assess anything, you decide what the area covers.

  • Pick the entity types: Processes, assets and systems, suppliers, or any combination of them.
  • Keep the scope honest: An area that only concerns suppliers shouldn't be asking about processing activities.
  • Different per area: Information security and GDPR rarely look at the same things in the same way.
The assessment form in .legal for accidental deletion of data, with consequence, probability, security measures and justifications filled in and the matrix calculating a high risk level

Assess against concrete scenarios

Add a risk scenario to an entity and work through the assessment in one place.

  • Consequence and probability: Set the level for each, along with the actual consequences and the security measures already in place.
  • Calculated for you: The risk level comes straight from that area's own matrix, so nobody is doing mental arithmetic.
  • Exposure if you want it: Add an estimated financial loss for the case where the risk materialises.
The history tab in .legal for one legal entity, listing every assessment, reassessment and proposed mitigation with the risk level before and after

Every assessment carries its justification

Consequence and probability both require a written justification. It isn't optional.

  • An audit trail by default: You can always point to why a risk was assessed the way it was, at the time it was assessed.
  • Nothing gets overwritten: Each assessment adds to the record rather than replacing it. Every entity and scenario keeps its own timeline.
  • Gaps get flagged: Where a risk has been reassessed without any new action being taken, the system says so.
Bulk assessment in .legal with four assets and the hardware failure scenario selected, and one set of consequence, probability and security measures applied to all of them

Assess many entities at once

Doing this one entity at a time is fine for a handful. It isn't fine for two hundred.

  • Bulk assessment: Select several entities and several scenarios and assess them together.
  • Same rigour, less clicking: Justifications and security measures still apply, they just don't have to be typed twenty times.
  • Useful for onboarding: The fastest way to get an existing register into the platform and assessed.
The NIS2 risk area overview in .legal: 27 of 27 entities assessed, four risks over appetite, four linked risks over appetite, a populated matrix and the risk distribution over time

Watch the risk picture build

Once enough entities are assessed, the area overview stops being a list.

  • A populated matrix: See how many entities sit in each combination of consequence and probability.
  • Key figures alongside it: Entities over appetite, linked risks over appetite, overdue mitigation plans.
  • Development over time: A chart shows how the distribution has moved, so you can tell whether anything is actually improving.
The .legal customer success team, ready to help with onboarding and support

Getting You Started Customer Support

You can always get help from a team member who’s ready to support you and your colleagues.
  • You get a dedicated Customer Success Manager.
  • Personal onboarding to ensure a smooth start.
  • Support available Monday to Friday, 9 AM to 3 PM.
A risk area in .legal showing the risk picture as it would be once every open mitigation plan is completed

.legal compliance platform Begin with Enterprise Risk Management today

Curious to see it on your own risk work? Book a conversation and we'll walk through your risk areas, your scales and where the add-on would fit.
  • Works alongside your existing frameworks
  • Free onboarding included
  • No commitment

Frequently Asked Questions about Risk Assessment

What can I assess risk on?

Processes, assets and systems, and suppliers. You choose which of them each risk area covers.

How risk areas are set up

Does the platform calculate the risk level for me?

Yes. You set consequence and probability, and the level comes from the matrix belonging to that risk area.

Do I have to write a justification every time?

Yes, on both consequence and probability. It's what gives you an audit trail worth having when someone asks why a risk was rated the way it was.

Can I assess more than one entity at a time?

Yes. Bulk assessment lets you handle several entities and several scenarios in one go.

What happens to an old assessment when I reassess?

Nothing is overwritten. The new assessment is added and the previous state is kept, so the full history stays intact.

From an assessment to a mitigation plan

Can I record what a risk would cost us?

Yes. Risk exposure is an optional field on the assessment, and it rolls up into the area overview and the management report.

Risk exposure in figures

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell