RA-BR2 Information Security (Small Office)
File Reference : RA-BR2 Information Security (Small Office)
Date File Updated 18-06-2026
File Format MS Word
No. of files 1
Category Business Risk Assessments
Tags: ISO 27001
  • £2.50

  or  

Login to Download


Using this example is a real head-start when preparing an information security risk assessment for a small office, and it gives you solid input for your information security risk register.

Free Support
Effective form templates

This example risk assessment has been prepared using the
F-Q36 General Risk Assessment form template - a purpose-built template designed to focus entirely on what matters: identifying business risks, assessing their likelihood and impact, and recording the controls that manage them, without any unnecessary fields getting in the way.

The file is supplied in fully editable MS Word format and can be easily customised and saved to Google Docs format if required. The document uses pre-defined style formatting throughout with styles to match the risk-ratings which are input using select boxes pre-populated with all possible risk ratings. All text is in Calibri font for improved readability.
The following document labelling is included in the footer:

  • Form number and title
  • Information-classification
  • Version
  • Page number / total pages
alphaZ documents - beautifully designed, tried and tested form templates. No junk, jargon or unecessary fields. Simple and usuable form templates developed over 25 years through practical use in the real world. No AI generated nonsense here!
Further Reading
Further Reading

Further guidance on information security risk for a small office:

Document Preparation
Logo Update Service *

Download this form template with your company name and logo already added!
Document Preparation available with all document toolkits.

How to Download

To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download.

Document template File Formats

Information Security Risk Assessment (Small Office)

This fully completed information security risk assessment example has been prepared by experienced ISO management system consultants. It covers information security across the IT systems and data of a small, office-based business using simple onsite equipment, and can be used as a starting point when developing your own information security risk assessment.

What Does This Information Security Risk Assessment Cover?

This risk assessment identifies the key information security risks a small office faces, including:

  • Phishing and social engineering targeting staff
  • Malware and ransomware infection
  • Weak passwords and account access, and the role of multi-factor authentication
  • Cloud storage and online service security
  • Loss or theft of laptops and mobile devices
  • Remote and home working, and the physical security of the premises
  • Insider threat, third-party access and legal and regulatory compliance

A residual risk rating is then assigned to each risk, demonstrating how practical controls - such as staff awareness training, anti-malware and patching, multi-factor authentication, regular backups and device encryption - reduce the overall risk to a tolerable level.

A Professional Easy-to-Use Risk Assessment Template

This document uses colour-coded header styles matched to risk ratings, making it quick to read and easy to communicate during team briefings and staff training. A built-in risk rating matrix supports consistent evaluation of likelihood and consequence, and clear risk symbols help communicate each risk at a glance. An inherent and a residual rating are recorded for every risk, so the effect of your controls is easy to demonstrate.

Risk, Control and Prohibition Symbols

Each row in the assessment is tagged with a small symbol so the type of risk, the control that manages it and any prohibition are clear at a glance. The same icon set runs across every alphaZ business risk assessment, which keeps a finished document quick to read and easy to compare. You can read more about them in our blog post on the alphaZ business risk icons.

alphaZ risk, control and prohibition symbols

Who Is This Information Security Risk Assessment Suitable For?

This template is suitable for small and office-based businesses that need to identify, assess and document information security risk in a practical way. It is particularly useful when implementing or maintaining an information security management system aligned with ISO 27001, and when supporting the risks and opportunities requirements (clause 6.1) of ISO management system standards. Owners, managers and IT or office leads can all use it as a ready-made starting point.

There are currently no comments for this document.

Add a Comment

Please Login or Subscribe to add Comments.