Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Security Risk Register Builder

Add each risk by asset, threat, likelihood, and impact. We compute the rating on a standard 5×5 matrix, sort by severity, and build a register you can copy straight into your docs. Everything stays in your browser.

Rating = likelihood × impact (1 to 25). Bands: Low 1 to 4 Medium 5 to 9 High 10 to 15 Critical 16 to 25, the standard qualitative approach in ISO 27005 / NIST-style assessments.

#AssetThreat / RiskLikelihoodImpactScoreRating
No risks yet. Add your first risk above to start building the register.

Not ready for a call yet?

Get the risk management playbook

A few short notes from Jacob on turning a risk register into an actual security program. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

Fractional security leadership

A retained security leader to own your risk register, controls, and treatment plan end to end.

Explore Fractional security leadership →

Turn the register into a program

A register lists risks. A fractional security leader owns them, assigns treatment, and closes them, mapped to SOC 2 or ISO 27001 compliance. Led by a published security researcher.

Explore fractional security leadership

Frequently asked questions

How is the risk rating calculated?

Each risk is scored on a standard 5x5 matrix: likelihood (1 to 5) multiplied by impact (1 to 5) gives a score from 1 to 25. Scores map to bands: 1 to 4 Low, 5 to 9 Medium, 10 to 15 High, and 16 to 25 Critical. This is the common qualitative approach used in ISO 27005 and NIST-style risk assessments.

Is my data sent anywhere?

No. The register is built entirely in your browser. Nothing you type is sent to a server or stored by this tool. Use the copy button to save your register into your own documents.

Is this a full risk assessment?

It is a starting structure, not a complete assessment. A real risk assessment also considers existing controls, residual risk, risk ownership, and treatment decisions, and validates likelihood and impact against your actual environment. This tool gives you a clean, prioritized register to build from.

Is it free?

Yes, the risk register builder is free with no signup required. Add as many risks as you like and copy the result into your own compliance or security documentation.

Want the full picture on your risks?

This gives you the shape of the problem. traztech Workspace carries a real risk register with owners, treatment plans, and review dates, wired to the control assessments that create the risks in the first place. Start free and keep the register somewhere it will actually get looked at.

Open your free Workspace See what is in the Workspace

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.