Skip to main
University-wide Navigation

The Enterprise Cybersecurity Team has launched a formal Governance, Risk, and Compliance (GRC) program. As part of this program, we are offering risk analysis of technology systems to our partners across the University.  Benefits include, but are not limited to:

Identification of Vulnerabilities

Identification of vulnerabilities allows your IT staff to assess their existing cybersecurity controls and determine where they may be exposed to risks or threats.

Prioritization of Resources

A risk analysis will assist your area in understanding which cybersecurity measures or controls need immediate attention and therefore prioritizing investment based on the level of risk they pose.

Mitigation of Threats

A risk analysis enables your IT staff to proactively identify and mitigate these threats. By understanding the potential impact and likelihood of different risks, your area can implement appropriate countermeasures to reduce the overall risk level.

Regulatory Compliance

The University is subject to many specific cybersecurity and data privacy regulations and compliance requirements. Conducting a risk analysis helps the University ensure that we meet these obligations and avoid potential penalties or legal issues. 

Protection of Critical Assets

Higher education possesses valuable data, such as student data, intellectual property, and trade secrets. A risk analysis assists in identifying the critical assets that need the highest level of protection. 

Incident Response Planning

By understanding the potential risks and vulnerabilities, the University can develop effective incident response strategies. This includes establishing protocols, defining roles and responsibilities, and outlining procedures to mitigate the impact of cybersecurity incidents.

Increased Confidence

Demonstrating a commitment to cybersecurity and risk management enhances stakeholder confidence in UK. Students, patients, families, community members, and our employees value the protection of their data. A risk analysis helps the University showcase our dedication to safeguarding data and mitigating potential risks.

Cost-Efficiency

Investing in cybersecurity without a proper risk analysis can lead to inefficient resource allocation. A risk analysis helps identify cost-effective cybersecurity measures by focusing resources on the most critical risks. This ensures that your college/unit makes informed decisions when investing in cybersecurity technologies, training programs, or third-party services.

Our team engages with IT personnel and business office staff within your unit over a period determined by your IT staff. During that time, we’ll assess your technology systems, software, hardware, contracts, etc. Afterwards you’ll be provided with a full analysis report identifying your strengths, weaknesses, opportunities, and threats in each of the above areas. We’ll then walk side-by-side with you to find the best solutions and implement the next steps.  

Request a Risk Assessment

To request a Cybersecurity Technology Risk Assessment, email GRC@uky.edu

EMAIL GRC