How to Run an Annual IT Risk Review (Without Starting From Scratch)
Think of the annual review as year two of your IT risk assessment process, and it should cost a fraction of year one. You aren't rebuilding the risk picture. You're finding which parts of it moved, re-scoring those, and putting every risk you chose to live with back in front of the person who chose it.
Table of Contents
An annual IT risk review updates last year's risk assessment instead of repeating it. You re-score only the risks whose inputs changed, decide again on every risk you accepted, and report the result to leadership in writing.
Your first assessment is the expensive one. Somebody inventories every system, maps where the data lives, interviews department heads, and scores dozens of risks from a blank page. Nobody wants that twice. So plenty of companies quietly skip it, and the binder from 2024 sits on a shelf describing a business with different vendors, different software, and in some cases a different owner.
That binder isn't a plan anymore. It's a photograph.
NIST wrote down the cheaper version back in 2012. It's on page 38.

What Is an Annual IT Risk Review, Really?
Technically, an annual IT risk review is a subsequent risk assessment. It starts from last year's findings and asks what changed, instead of rebuilding the analysis. A full reassessment only happens when something significant has moved.
NIST's guide to conducting risk assessments, Special Publication 800-30 Revision 1, splits the work into four steps. Prepare, conduct, communicate, and maintain. The first two get the attention.
Step four covers exactly this situation. It says that when nothing significant has changed, an update identifies and assesses "only how selected risk factors have changed," which in plain terms means new threats, new weak spots, new systems, and shifts in how likely or how damaging something is. If something significant did change, you go back and revisit the scope and assumptions of the whole assessment. NIST leaves the definition of significant to you. Be honest with it.
Read that as a budget line for your IT risk assessment process. Year one is a full assessment. Year two is a delta. Just the differences.

If you haven't kept one, a risk register is the running list of risks, how each one is scored, and who owns it. Everything below assumes you have one from your last assessment. No register? Then you're not ready for a review.
When Does the Annual Review Stop Being Enough?
Go back to a full assessment when the business changes shape. An acquisition, a new ERP system (the core software that runs orders, inventory, and accounting), a move from on-premise servers to Azure or AWS, a new kind of regulated data, or a serious incident all qualify.
Any of those rewrites the map, not just a few scores on it. Start over. Run the full step-by-step cybersecurity risk assessment, then go back to annual reviews the year after.
And if your last real assessment is more than 3 years old, skip the delta entirely. There's nothing current enough to compare against.
What to Pull Together Before the Meeting
Budget a half day for the meeting itself. The prep is where the hours go, and IT carries most of it. Four things, specifically.
Last Year's Register and Treatment Plan
Every risk, its score, its owner, and what you said you'd do about it. Next to each treatment, mark it done, partly done, or not started. Be honest about the third pile, because in a lot of registers it's the tallest one, and a review that skips it is just re-signing last year's promises.
What Changed in 12 Months
- Systems added or retired. The ERP upgrade counts. So does the shared drive somebody swore was decommissioned in March.
- Vendors with access to your data or network, including any whose contract ended while their accounts didn't. A working third-party risk management program should hand you this list without anyone digging.
- People. Headcount, key departures, and who holds admin rights today.
- Did you sign a customer contract with security clauses in it?
- Incidents and near misses, including the invoice-fraud email that got as far as accounts payable before someone called to check.
The Known Exploited Vulnerabilities Check
CISA's Known Exploited Vulnerabilities catalog listed 1,717 entries as of September 21, 2026. Every one is a flaw attackers are using right now. Not theory. CISA's own guidance is to treat the catalog as an input to how you prioritize patching, and the annual review is where priorities get set, so have IT match it against what you actually run before the meeting.
It's a spreadsheet job. It's also the quickest way to learn whether the monthly patching everyone reports is really happening.
What's Already Due This Year
CISA's Cybersecurity Performance Goals 2.0, released in December 2025, put several items on a yearly clock. Security policies get reviewed at least annually. Incident response plans get reviewed and drilled at least once a year. Network documentation gets a yearly review, and every user gets security training at least annually. Fold all of it into the same review, and the evidence ends up in one folder when an insurer or auditor asks for it.
Who Needs to Be in the Room?
The people who can accept a business risk. That's the owner or CEO, the CFO or COO, and whoever runs IT, plus your managed service provider if it holds admin access. IT can score risks. It can't accept them alone.
NIST's Cybersecurity Framework 2.0 (CSF 2.0) puts this in its governance section without hedging, stating that organizational leadership is responsible and accountable for cybersecurity risk. Not the IT manager. Leadership.
An IT-only review produces a list of IT tasks, several of which will need money nobody in the room can approve, so they roll into next year untouched. Put the CFO in the chair next to the IT lead and the same risk list comes out the other side with dollar amounts, dates, and names. The list is identical in both meetings. Only one of them produces a budget.
If an outside provider runs your IT, they belong at the table and on the register, which CISA reinforced in CPG 2.0 by adding a goal specifically for managing risk from managed service providers over the whole life of the engagement. An MSP that won't sit through a review of its own access is telling you something.
Five Decisions for Every Risk on the List
Five decisions cover every risk on the register. Re-score it, close it, escalate it, transfer it, or accept it with a named owner and an expiry date. Nothing leaves the room undecided.

- Re-score. The inputs moved, so the number moves. A server that faced the internet last year and sits behind the firewall now drops, while a vendor that started processing your payroll in the spring climbs, even though nothing about the vendor itself changed. If the scoring itself is fuzzy, how a cyber risk score works walks through the math.
- Close it only when the fix is verified. An email from IT saying it's done doesn't count. A scan result or a configuration screenshot does.
- Escalate anything that climbed sharply or missed its treatment date twice, because a risk that has slipped two deadlines is usually waiting on money rather than effort, and money only gets decided in the budget conversation with a cost written next to it.
- Transfer? Cyber insurance or a contract clause can move some of the financial hit to someone else. Some. A policy pays the invoice, not for the week your warehouse can't ship.
- Accept, with an owner and a date. This is where registers rot.
Accepted risks go stale in a very particular way. Someone decides in 2023 that the old file server can wait. By 2026 nobody remembers deciding, so the server has stopped being a risk and become furniture. CSF 2.0 expects risk responses to be chosen, prioritized, planned, tracked, and communicated, and the word doing the work in that sentence is tracked.
So give every accepted risk an expiry, 12 months at the outside, and a person's name. When it expires, that person either accepts it again, out loud, in the review, or funds the fix. Picture a 150-person distributor whose warehouse management system can't support multifactor authentication (the second login step, like a phone prompt, that stops a stolen password from being enough). Accepting that risk for a year while a replacement is budgeted is a defensible call. 4 years by default isn't a call at all. It's drift.
Has Your Risk Appetite Changed Since Last Year?
Probably, if revenue, headcount, or major customer contracts changed. Risk appetite is how much exposure leadership will tolerate to run the business, and NIST CSF 2.0 expects it to be maintained, not written once and filed.
CSF 2.0's risk management strategy category says risk appetite and risk tolerance statements are "established, communicated, and maintained." That's the review's job. ISO 31000:2018, the international risk management standard, which ISO last reviewed and confirmed in 2023, makes the same point from the governance side. Risk management belongs inside how the organization is run, and that includes monitoring and communicating risk on a cycle, not only identifying it once.
A manufacturer that landed its first defense subcontract this year should have watched its tolerance for anything touching the file share where engineering drawings live drop to somewhere near zero the day the contract was signed. So should the tolerance of a firm that just signed a customer contract requiring breach notice within 72 hours. Did anyone write the appetite down last year? If not, start now.
The One-Page Report Leadership Actually Reads
Leadership needs one page, not the register. It should show what moved, what needs a decision, and what it costs. Anything longer goes in an appendix nobody opens.
- The five risks that matter most right now, each marked up, down, or flat since last year
- What changed in the business that moved them
- Decisions needed today, with a cost beside each one
- Accepted risks up for renewal, and whose name is on each
- Budget tied to specific risks. If a security line item can't be traced back to something on the list, ask why it's in the budget.
That's the whole page.
For some companies the report isn't optional. The FTC's Safeguards Rule requires covered non-bank financial businesses, a group that includes mortgage brokers, tax preparation firms, and collection agencies, to keep a written risk assessment and repeat it periodically. A designated qualified individual then has to report in writing to the board, or its equivalent, at least annually, covering the risk assessment, risk management decisions, service provider arrangements, test results, and security events. Firms holding information on fewer than 5,000 consumers don't have to put the risk assessment in writing or deliver the annual board report, though they still have to assess risk. Check your count.
Even if the rule never touches you, its list of required contents is a decent outline for the page.
How Do You Keep the Review From Going Stale Between Years?
Check the top risks every quarter, reopen the register whenever a trigger event hits, and let continuous monitoring feed it. The annual review should confirm what you already know. It shouldn't surprise anyone.

NIST doesn't actually say annual. SP 800-30 leaves the frequency of updates to the organization. The NIST Risk Management Framework, SP 800-37 Revision 2, goes further and builds ongoing monitoring into its final step, so decisions get made on current information rather than last year's snapshot. Annual is a convention. It's a sensible one, since budgets and board calendars already run on a yearly clock, but it's the floor, not the whole job.
Between reviews, a 30-minute quarterly look at the top 10 risks is plenty for a company of 20 to 1000 users. Calendar it now. Trigger events skip the queue.
When Outside Help Makes Sense
With a dedicated governance, risk, and compliance team and a chief information security officer (CISO) who reports to the board, you have the machinery already. Run it yourselves.
Outside help earns its fee in two situations. One is when nobody inside owns the register, which is common below a few hundred users, where IT is one or two people who are already busy keeping the lights on. The other is quieter. The people who made last year's calls are the ones grading them this year, and an outside reviewer has no stake in whether the 2025 decision on the warehouse server looks good in hindsight.
Consilien is a managed IT and cybersecurity provider for companies with 20 to 1000 users across the US, and our virtual CISOs and CIOs (part-time security and technology executives) work with leadership teams that don't have a full-time one on exactly this kind of review. If you'd like a baseline first, the free NIST CSF-based risk assessment is quick. For a look at what the remediation side can look like afterward, one 120-employee company's 90-day plan lays it out.
Still working off a 2024 assessment? Speak to a risk expert about turning it into this year's review.