Risk Register

Enterprise risk inventory — inherent, treatment, residual, accountable owner.

Open risks
15
Accepted
2
Avg residual
7
Reviewed this Q
11

5×5 risk heatmap

I1
I2
I3
I4
I5
Impact
1×5
2×5
3
3×5
2
4×5
5×5
1×4
2×4
1
3×4
2
4×4
2
5×4
1×3
2×3
1
3×3
2
4×3
2
5×3
1×2
2×2
3×2
4×2
5×2
1×1
2×1
3×1
4×1
5×1
L1L2L3L4L5
Likelihood

Acceptance queue

R-0044
DDoS against public checkout surface
Sara Okafor • review Q1 2025
R-0108
Legacy ledger service unpatchable critical CVE
Diego Alvarez • review Q4 2024

All risks

IDRiskCategoryLIInherentResidualTreatmentOwnerStatus
R-001Loss of payment card data due to insider threatData Protection25186mitigatePriya Shahmitigating
R-002Cloud account takeover via leaked CI/CD credentialsCloud Security35209mitigateSara Okaforopen
R-003Supply chain compromise via npm dependencyAppSec441610mitigateMarcus Linmitigating
R-004DDoS against public checkout surfaceAvailability43124transferSara Okaforaccepted
R-005Regulatory fine for delayed breach notificationCompliance24124mitigatePriya Shahopen
R-006Internal data lake PII exfiltrationData Protection35189mitigateMei Wongmitigating
R-007Loss of availability — payments-api outageAvailability25156mitigateJordan Vegamitigating
R-008Phishing-led credential compromise of adminIdentity44169mitigatePriya Shahopen
R-009Third-party vendor breach exposing customer dataThird Party34126transferPriya Shahmitigating
R-010Legacy ledger service unpatchable critical CVEAppSec25128acceptDiego Alvarezaccepted
R-011Mobile app reverse-engineering and API abuseMobile3396mitigateBen Carteropen
R-012Misconfigured S3 bucket exposing internal docsCloud Security3394mitigateSara Okaformitigating
R-013Insider IP theft via departing engineerInsider2364mitigatePriya Shahopen
R-014AI model prompt-injection leaking customer contextAI/ML43128mitigateMei Wongopen
R-015Unauthorized changes to production via overly broad IAMIdentity34126mitigateSara Okaformitigating