A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →List your assets, the threats to them and the weaknesses those threats would use. Score each 1 to 5 and the worksheet calculates the risk and its band, following the Harmonized TRA structure.
One row per asset and threat pair. Risk = asset value × likelihood × vulnerability.
| Asset | Value | Threat | Likelihood | Vulnerability | Score | Risk | Proposed safeguard |
|---|
| # | Asset and threat | Risk | Proposed safeguard |
|---|
TRA-1 is a threat and risk assessment method published by the Communications Security Establishment and the RCMP for Government of Canada systems. It works through assets, threats, vulnerabilities and safeguards, and expresses residual risk as a combination of asset value, threat likelihood and vulnerability.
Asset value, threat likelihood and vulnerability are each scored 1 to 5 and multiplied, giving a risk from 1 to 125. The bands are very low (1 to 4), low (5 to 12), medium (15 to 32), high (36 to 75) and very high (80 to 125).
The injury if the asset's confidentiality, integrity or availability were compromised: to individuals, to the organization, or to the people and clients who rely on it. Score the worst of the three.
It is a working draft. A formal TRA for a federal or provincial system also documents the statement of sensitivity, the threat sources, existing safeguards and recommended safeguards, and is reviewed by someone independent of the system owner.
Yes, free and no signup. Your entries stay in your browser.
Not ready for a call yet?
Your ranked risks to keep, then a few short notes from Jacob on threat and risk assessments that hold up in review. Unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Want it done for you?
Threat and Risk Assessment
A formal TRA for one system, with safeguards recommended and residual risk documented.
Explore Threat and Risk Assessment →We run the threat and risk assessment for your system, document the statement of sensitivity, threats, vulnerabilities and safeguards, and recommend what brings residual risk down to a level you can accept. From $3,000 CAD.
See the threat and risk assessment Book a callThis gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.