FACILITATED CYBER RISK ASSESSMENT
Cyber Risk Assessment
Close the Compliance Gap
CRA Online runs your team through a simulated year of operations — executive roles, real-world risks and controls, and one player quietly working against the room. Facilitated online for remote and hybrid teams, and closed out with a structured debrief and an exported session report.
- Risk Workshop
- Understand the basics Evaluate your controls Defend against a risk Transfer, treat, or accept — someone will not agree
- Crisis Workshop
- Prepare for the worst Controls fail when you need them Someone at your table is an insider threat
- Standards Specific
- ISO 27001, ISO 27702, … DORA, NIS2, PCI-DSS and many more Or bring your own
Learn how it runs
The manual and a full walkthrough
Both guides are open — read them before you book a room or sign up as a facilitator.
Facilitator manual
How to run a CRA workshop
Preparation, onboarding, the ten rounds, crisis injects and the export at the end. About ten minutes to read.
Read it →
Workshop walkthrough
A session, minute by minute
The same four-player session from both sides: the facilitator setting up and delivering, and a participant joining by code.
Read it →
Exercises by standard
Pick the framework you are assessed against
Every workshop is played against a standard. Each deck is pre-authored for its clause set, and you can import your own standard as CSV.
SOC 2 (Trust Services Criteria)
Trust service criteria for service providers handling customer data.
ISO/IEC 27001:2022 Annex A
Risk-based ISMS controls for confidentiality, integrity, availability.
ISO/IEC 27701 (Privacy)
Privacy information management on top of an ISMS.
ISO/IEC 42001 (AI management)
AI management system: governance, impact assessment, lifecycle.
HIPAA Security & Privacy Rules
Administrative, physical and technical safeguards for PHI.
EU GDPR
Lawful processing, consent, data-subject rights, breach duties.
NIST CSF 2.0
Govern, Identify, Protect, Detect, Respond, Recover outcomes.
PCI DSS v4.0
Protecting cardholder data: encryption, access control, monitoring.
NIS 2 Directive (EU 2022/2555)
EU-wide baseline: management accountability, ten measures, strict incident clocks.
DORA (EU 2022/2554)
Financial-sector ICT resilience: testing, third-party risk, major-incident reporting.
How a session runs
Seven phases, one facilitator
The facilitator drives the room. Every table screen follows the same phase, so nobody races ahead and nobody gets lost.
- 1Lobby
Waiting for the facilitator to start. Sit tight.
- 2Deal cards
Cards are being dealt to your table.
- 3Select cards
Pick the cards from your hand that matter most and add a note.
- 4Discussion
Talk it through at your table. You can still play more cards.
- 5Vote
Vote for the cards your table should carry forward.
- 6Submit answer
Agree your table's answer and submit it.
- 7Review
Reviewing results together.
Facilitator
Control room
- Create a workshop, get a join code
- Seat participants across tables
- Advance rounds, set timers, deal or recall
Participants
The table
- A hand of threat, vulnerability and control cards
- Play with a note, discuss, vote
- Agree and submit the table's answer
Afterwards
Assessment
- Framework coverage scored from what the room decided
- Gap list and per-table divergence
- Anonymised CSV export and a drafted findings narrative