This report, prepared for Regional Gardens, addresses critical IT risk management concerns. As the newly appointed CIO, the author analyzes the company's IT infrastructure, identifying key risks such as unrestricted internet access, excessive costs, lack of onboarding/offboarding processes, system maintenance issues, data loss, data integrity failures, inadequate monitoring, and lack of backup/disaster recovery. A detailed risk register is presented, outlining each risk, its description, potential impact, assessment, likelihood, consequences, control strategies, residual risks, and priority. The report emphasizes the importance of proactive risk mitigation, including restricting internet access, managing budgets, establishing formal processes, improving system maintenance, updating storage, encrypting data, implementing monitoring systems, and ensuring data backup and recovery procedures. The risks are prioritized based on their impact and likelihood, emphasizing the need for immediate action on high-priority issues. The report concludes that effective risk assessment is crucial for enhancing the overall performance of the organization, and that proper risk identification strategies are essential for mitigating potential issues.