Back to furthermore
Furthermore Law
Assess your risks. Show your work.
Service

Threat Risk Assessments

A prioritized heat map, not an inventory of findings.

Two competing claims, both true:

Claim one

Checklists and prescriptive security frameworks are essential due diligence.

Claim two

Checklists are a waste of time. They cannot capture modern technical architectures or on-the-ground operational nuances.

Information security is the business of AND.

Earning trust in the confidentiality, integrity, and availability of your products and services requires both: an industry-standard framework as the foundation, and then professional judgment applied to the risks that actually exist in your environment. The framework tells you what to look for. Experience tells you which findings matter. You don’t need performative security, but you will need to show your work.

We build threat risk assessments for organizations of all sizes, on instruction from security, privacy, compliance, legal, and product teams. Every assessment maps to the frameworks you already report against and lands as a prioritized heat map, so what you receive is a sequencing and funding decision rather than an inventory of findings destined for the archive.

Business Case

  1. 01Every major security framework expects a documented, repeatable risk assessment. When an auditor or a customer asks for evidence, they want the assessment itself, not the policy that says one should exist.
  2. 02A penetration test reports what was reachable on the day it ran. A threat risk assessment ranks which of those paths matter, what a realistic compromise would cost, and which control to fund first.
  3. 03Vendor security reviews from enterprise customers no longer stop at a questionnaire. An arm’s-length assessment answers the follow-up questions once, in a form the customer’s own security team recognizes.
  4. 04Internal teams are rarely idle. Engaging an outside assessor is often less about a formal independence requirement than about finishing a defensible assessment inside the quarter it was promised.
  5. 05AI deployments concentrate risk in unfamiliar places: the model and vendor supply chain, what your own data does once it reaches a prompt or a retrieval index, and how long inference logs live. Assessing the platform before a pilot becomes production is considerably cheaper than assessing it afterward.
  6. 06Security, privacy, and AI risk assessments cover much of the same ground. Assessing it once, by one person credentialed in each domain, produces a shorter reading list for whoever has to approve the result.
FRFIs should identify current or emerging cyber threats proactively using threat assessments to evaluate threats and assess security risk. This includes implementing information and cyber security threat and risk assessments, processes, and tools to cover controls at different layers of defence.
OSFI Guideline B-13 — Technology and Cyber Risk Management

Background

What could possibly go wrong? Everyone has a midnight answer to that question. Risk management is the discipline of adopting a consistent methodology to convert ambient anxiety into rigorous, evidence-based, reportable, actionable decision making. Risk identification through third-party threat risk assessments is now a prerequisite for participation in many regulated industries. Auditors sample the assessment, procurement teams request it mid-deal, regulators expect it to predate the system rather than follow it, and insurers price against it. The bar has moved from holding a view on your risks to showing how you reached it, who was qualified to reach it, and what you decided to do about it.

Assess your risks. Show your work.

Services

Every engagement is delivered as a privileged legal opinion. That is deliberate: a document naming unmitigated weaknesses in your environment belongs under solicitor-client privilege, not in a discoverable ticketing queue. Methodology follows the environment rather than a house template, so we work in the framework your team already reports against, at the depth your obligations actually require.

  1. System or program Threat Risk Assessments (TRAs) Structured identification of threats, vulnerabilities, and safeguards for a defined system or program, delivered with prioritized treatment options rather than an undifferentiated list of findings.
  2. Cloud & SaaS Cloud Security Assessments Assessment of cloud and SaaS deployments against recognized cloud control frameworks, covering shared-responsibility boundaries, identity and key management, logging, and tenant isolation.
  3. Supply chain Vendor & Third-Party Security Assessments Independent review of the vendors and sub-processors in your supply chain, including support for the security questionnaires and customer assurance reviews you are asked to complete.
  4. One engagement, one report Converged Privacy & Security Assessments One engagement covering both domains. We hold both privacy (CIPP/C) and security (CISSP) credentials, so overlapping controls are assessed once, in a single report, rather than twice by two providers.
  5. AI deployments AI Platform Implementation Assessments Threat risk assessment scoped to an AI deployment: model and vendor supply chain, what data reaches prompts and retrieval indices, output handling, and inference logging and retention.
  6. Oversight & approvals AI Governance & Ethics Reviews Review of the governance wrapped around the deployment, covering approval gates, human oversight, acceptable use, bias and fairness considerations, and the records you need when a customer or regulator asks who signed off.

Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and Algorithmic Impact Assessments (AIAs) are covered on a separate page. An AIA examines the effect of an automated decision on the people subject to it; the AI assessments above examine the security and governance of the platform you are deploying. Where security and privacy are both in scope, the converged assessment above delivers them as a single engagement and a single report.

Qualifications & Experience

Qualifications

  • Certified Information Systems Security Professional (CISSP) — ISC2, 2026
  • Certificate of Cloud Security Knowledge (CCSK) — Cloud Security Alliance, 2021
  • Certified Information Privacy Professional / Canada (CIPP/C) — International Association of Privacy Professionals, 2020
  • Fundamentals of OCAP Certification (Indigenous Data Sovereignty) — First Nations Information Governance Centre, 2026
  • Practising Lawyer — Law Society of British Columbia, 2009
  • Degrees in computer science (Queen’s University) and management information systems (LSE)

Experience

  • 18+ years of professional services experience with technology companies. Six years in internal roles and twelve as a third-party service provider.
  • Completed internal and external TRAs and PIAs ranging from targeted assessments of a single system to comprehensive cross-organization reviews.
  • Specific focus on regulated industries including healthtech, fintech, and legal tech.
  • Agile engagement model. You work directly with the assessor from scoping through final report, with no junior staff layered in and no internal review queue between you and an answer.

Pricing

Project-based pricing reflects the professional services time an engagement requires. Considerations include:

  • Scoping complexity
  • On-site requirements and travel
  • Frameworks & methodologies
  • Reporting requirements
  1. StructureA fixed fee follows a short scoping exercise, so the number is settled before work begins. We also bid on formal requests for proposals.
  2. BudgetsModular service models reflect your budgeting constraints. Where a budget has been approved, we can shape scope, framework depth, and reporting format to fit it without weakening the defensibility of the result.

Getting Started

Tell us what needs assessing, the framework you report against, and the date the answer is due. One scoping call is usually enough to settle methodology, depth, and project fee.

Assessments sit where three practices meet. The same lawyer who negotiates your security schedules and advises on your AI governance program runs the assessment — drawing on Information Security, Privacy Law, and AI Governance.

Assess your risks. Show your work.

Start a conversation