Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Add each risk by asset, threat, likelihood, and impact. We compute the rating on a standard 5×5 matrix, sort by severity, and build a register you can copy straight into your docs. Everything stays in your browser.
Rating = likelihood × impact (1 to 25). Bands: , the standard qualitative approach in ISO 27005 / NIST-style assessments.
| # | Asset | Threat / Risk | Likelihood | Impact | Score | Rating | |
|---|---|---|---|---|---|---|---|
| No risks yet. Add your first risk above to start building the register. | |||||||
Not ready for a call yet?
A few short notes from Jacob on turning a risk register into an actual security program. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Fractional security leadership
A retained security leader to own your risk register, controls, and treatment plan end to end.
Explore Fractional security leadership →A register lists risks. A fractional security leader owns them, assigns treatment, and closes them, mapped to SOC 2 or ISO 27001 compliance. Led by a published security researcher.
Explore fractional security leadershipEach risk is scored on a standard 5x5 matrix: likelihood (1 to 5) multiplied by impact (1 to 5) gives a score from 1 to 25. Scores map to bands: 1 to 4 Low, 5 to 9 Medium, 10 to 15 High, and 16 to 25 Critical. This is the common qualitative approach used in ISO 27005 and NIST-style risk assessments.
No. The register is built entirely in your browser. Nothing you type is sent to a server or stored by this tool. Use the copy button to save your register into your own documents.
It is a starting structure, not a complete assessment. A real risk assessment also considers existing controls, residual risk, risk ownership, and treatment decisions, and validates likelihood and impact against your actual environment. This tool gives you a clean, prioritized register to build from.
Yes, the risk register builder is free with no signup required. Add as many risks as you like and copy the result into your own compliance or security documentation.
This gives you the shape of the problem. traztech Workspace carries a real risk register with owners, treatment plans, and review dates, wired to the control assessments that create the risks in the first place. Start free and keep the register somewhere it will actually get looked at.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.