Risk Management with RiskTree®

RiskTree process flow Identify Assess Prioritize Manage

2T Security has developed RiskTree as a structured approach for risk management. Based around the well-established concept of attack trees, RiskTree provides a systematic way of capturing and prioritizing the risks to your business and systems. It presents its results in an easy-to-understand format that integrates well with existing business processes.

Key benefits

Tried and trusted

RiskTree has already been deployed by clients in both the public and private sectors. One client has replaced their previous information risk management processes completely, and is already seeing the benefits of the RiskTree approach from better business engagement, end-to-end lifecycle support for security from projects, and more comprehensive risk registers - all leading to better assurance.


The RiskTree software allows creation of the trees within the browser environment. This can be done during the workshops, or as a data-capture exercise afterwards. The tree is built quickly and efficiently, and can then be submitted to the on-line service for secure assessment.

RiskTree reports can be created using trees with and without controls applied, and so can be used to give a view of intrinsic risk (at the very start of a project), and residual risk (once controls have been planned); this allows the effect of the controls to be demonstrated. The Processor analyses the risk data and generates a prioritized table of risks. The default is that this is sorted on a traditional six-point scale (Very High - Very Low), but a configuration tool allows this to be modified to suit your own requirements.

The RiskTree process Download the brochure