
A Houston accounting firm got asked for their risk assessment during a cyber-insurance renewal. The owner pulled a 14-page PDF off the server, the one a previous vendor had handed over two years earlier, and forwarded it without opening it. The underwriter read it in about ninety seconds and replied with one question: “Can you confirm this assessment was performed on your environment?” It couldn’t be confirmed, because it hadn’t been. It was a template. The renewal stalled, the rate went up, and the firm spent six weeks doing the work they thought they’d already paid for.
This is the most common compliance failure we see, and it’s a quiet one. Almost every owner has “a risk assessment.” Far fewer have a real one. The good news is you don’t need to be technical to tell the difference. You just need to know what to look for. This is a guide to reading your own document and deciding, honestly, which kind you have.
Why this one document matters more than the rest
The risk assessment is the foundation. It’s the first thing auditors, insurers, and regulators ask for, and there’s a reason for that. Almost every framework an SMB runs into expects one: HIPAA requires it, the FTC Safeguards Rule requires it, PCI assumes it, and CMMC and NIST 800-171 are built around it. Cyber-insurance carriers increasingly ask to see it before they’ll write or renew a policy.
Here’s the part owners miss. Everything else you do is supposed to flow from the risk assessment. Your security policies, your access controls, your backup strategy, the firewall, the training, all of it is meant to be a response to risks you actually identified. When an examiner picks up your assessment first, they’re checking whether the rest of your program has a real source, or whether you bought controls off a shelf and wrote a document to match. A genuine assessment is the spine everything else hangs on. A fake one means the spine isn’t there, no matter how good the controls look in isolation.
That’s why we treat it as the starting point of any compliance engagement. You can’t fix risks you never named.
What a REAL risk assessment contains
A real assessment is specific to your business. It reads like someone walked your office, looked at your systems, and wrote down what they found. If yours has all of the following, you’re in good shape. If it’s missing pieces, you’ve found your gaps.
1. A real inventory of your assets, systems, and data
- Your actual systems, by name. The server in the back closet, the line-of-business application you live in, the cloud platforms you use, the laptops in the field.
- Where sensitive data actually lives. Not “data is stored securely,” but which data (client financials, health records, payment info) sits in which system, who can reach it, and how it leaves the building.
- Who owns what. Vendors, third-party platforms, and the people responsible for each system.
2. Threats and vulnerabilities specific to you
- Real findings, not categories. “The shared admin password on the file server has not been changed since 2021” is a finding. “Weak passwords are a risk” is filler.
- Vulnerabilities tied to your setup: an unpatched machine, a missing backup, an exposed remote-access tool, an employee with access they no longer need.
- Threats that fit your business and your industry, not a generic list copied from a textbook.
3. A rating of likelihood and impact for each risk
- Every identified risk gets scored: how likely is it, and how badly would it hurt if it happened?
- The ratings should make sense for your business. A missing backup on the system that runs your whole operation should rank higher than a minor issue on a rarely used PC.
- This is what turns a list into a plan. It tells you what to fix first.
4. A remediation plan with owners and dates
- What needs to be fixed — each gap, written plainly.
- Who owns it — a named person or vendor responsible for closing it, not “IT.”
- A target date — when it’s expected to be done.
- Status — open, in progress, or closed, so anyone can see progress.
5. A date — within the last 12 months
A risk assessment is a snapshot of a moving target. Your business changes, your systems change, the threats change. An assessment older than a year is stale, and an undated one is a red flag all by itself. Reassessment after any major change (new system, office move, acquisition) is just as important as the annual refresh.
How to spot a template or fake
Open your document and read it the way an underwriter or auditor would. Here are the red flags. Any one of these is a problem. Several of them together mean what you’re holding is a template with your logo on it.
- Generic boilerplate language. If you could swap your company name for any other business in Houston and the document would still “fit,” it isn’t about your business.
- No actual asset or system names. Real assessments name your server, your software, your cloud apps. Fakes talk about “systems” and “the environment” in the abstract.
- No specific findings or gaps. If it describes risk in general terms and never points at a concrete weakness in your setup, no one actually looked.
- No risk ratings. No likelihood, no impact, no prioritization. Just a list of things that could go wrong for anyone.
- No remediation owners or dates. Recommendations with nobody assigned and no deadline are a wish list, not a plan.
- Never been updated. Same document, year after year, with the date changed (or not changed at all).
- You can’t find who produced it. No author, no firm, no methodology, no signature. If you can’t say who did the work or how, neither can an examiner.
A useful gut check: if you can’t answer the questions in the “real” checklist above using your own document, your risk assessment isn’t real. It’s a PDF that says “risk assessment” at the top.
The “so what”: a fake is worse than nothing
This is the part that surprises owners. A faked risk assessment can be worse than not having one at all. Here’s the reasoning, and it’s the kind of thing we tell clients to take straight to their attorney and carrier.
When you produce a template, you’ve documented two things at once: that you knew a risk assessment was required, and that you faked it instead of doing it. After an incident, that document doesn’t protect you, it gets used against you. An opposing attorney in a breach lawsuit, a regulator investigating a complaint, an insurer looking for a reason to deny a claim — they all recognize a template instantly, because they read dozens of real ones. The generic language that felt “close enough” to you reads, to them, as a paper trail proving you cut the corner you most needed to round.
Auditors and underwriters spot it in seconds for the same reason a contractor can spot a fake permit. They know what the real thing looks like. We’re not lawyers and we don’t give legal advice, but we’ve sat in enough renewals and post-incident reviews to tell you plainly: the template doesn’t buy you the protection you think it does. Confirm the specifics with your attorney, your carrier, or your auditor.
What to do next
Take fifteen minutes and read your own assessment against the checklists above. Then sort it into one of three buckets:
- It’s real and current. It names your systems, lists specific findings, rates them, assigns remediation with owners and dates, and it’s less than a year old. Good. Put a reminder on your calendar to refresh it annually and after any major change.
- It’s real but stale. It was done properly once, but it’s aged out or your environment has changed. It needs a refresh, not a rebuild.
- It’s a template. It fails the checklist. You need a real one performed on your actual business — and then you need the gaps it finds actually closed.
That last step is where most assessments die. A real assessment will surface real gaps, and a list of gaps with nobody fixing them is just a more honest fake. This is what our compliance service is built to do: produce a genuine, business-specific risk assessment that names your systems and your risks, then tie it to a remediation plan that actually gets executed. The fixing happens through our managed IT services and network security work — patching, access control, backups, monitoring — so the controls in your environment match the risks named in your document. That alignment, assessment to remediation, is what makes compliance real instead of paper.
Let’s find out which one you have
If you read your assessment and you’re not sure which bucket it falls into, that uncertainty is your answer — and it’s worth a conversation. Book a free 15-minute discovery call at /discoverycall/ and we’ll talk through what you’re holding and what a real assessment would involve for a business like yours. To be straight with you: the discovery call is the only free thing. We charge professional rates for the actual work, because a real risk assessment and the remediation behind it is real work — you can review how we engage on our rates page, and see the full scope on our compliance page. What you get in return is a document that holds up when the underwriter, the auditor, or the attorney reads it — and the controls underneath it to match.
Aspendora Technologies provides cybersecurity, managed IT, and expert on-premise & open-source solutions to Houston-area small businesses since 2010.
