Skip to content
Skip to article text

Risk Analysis for Startups and Solo: The New Method

Two advisors and a founder sketching a realistic risk scenario on a small workshop table

Why Beraterium is updating risk analysis for startups and solo founders now

Till Blania and Peter Münstermann have spent recent months sharpening their method specifically for startups and solo self-employed people. The trigger was practical: an approach that works for an 80-person mid-market company does not automatically fit a two-person startup or a single freelancer.

The difference is not about diligence — it is about size. A larger team can work through a list of a hundred hazards point by point because different departments give different answers. With one person or a three-person team, that internal contrast is missing — and a hundred questions turn into a hundred repetitions of the same answer. That is exactly why the method needed an update.

What the hazard catalogue with around 160 hazards delivers — and where it hits a limit

Beraterium's master catalogue now bundles about 160 hazards, clustered down to a third level so that ideally no conceivable hazard falls through the cracks. That remains the foundation of every risk analysis, as Peter Münstermann puts it: "The hazard catalogue holds up for a very long time."

For solo self-employed people, startups or small mid-market companies, though, the full catalogue would be impractical. Not because individual hazards are wrong, but because there are too many of them, too abstractly framed, to discuss in a manageable workshop. So the catalogue does not turn into a rigid form — it becomes an individually assembled set, matched to company size and industry.

How baseline risks, industry-specific risks and probing questions differ

Every tailored set is built from three blocks:

  • Baseline risks: Roughly half the set — topics that matter for almost every company equally, such as IT system outage or losing a key person.
  • Industry-specific risks: About two-thirds of the remaining half — depending on whether the business is a tax practice, a 3D-printing startup or a fund management firm.
  • Probing questions: The last third of the remaining half — deliberately sharpened toward what usually gets overlooked.

It is not randomness but a system that decides which questions end up in a set. That split is exactly what separates a generic checklist from an analysis that actually fits the company's size.

What probing questions actually uncover

Probing questions are the core of the "risk sniffer" role Beraterium claims for itself. They do not target the obvious risks — they target what does not get said openly in everyday business.

Typical examples from practice:

  • Reputational damage: What happens if a wave of bad reviews suddenly hits — and how hard does that land on a business model that lives on trust?
  • Weaponised attachments: Images or PDFs from clients can now carry malicious code. One click is enough to encrypt a hard drive or, via a zip bomb, flood an entire storage system.
  • Knowledge drain: What happens when an experienced employee retires or a key person on a startup team drops out — is there a backup, or does the knowledge leave with the person?
  • Dependencies: On a single supplier, a specific piece of technology, or one supply-chain route.

Peter Münstermann adds a category that goes even deeper: "What would you say or ask if the boss weren't in the room?" The point is not to find someone to blame — it is to surface topics that people already think about but never say out loud.

What would you say or ask if the boss weren't in the room?

How the workshop runs today: scenario first, assessment second

The overall sequence of a risk analysis is unchanged: a hazard is identified, assessed for damage and probability, placed into a portfolio, and the largest risks are then worked through with measures. What is new is a step in the middle that Peter Münstermann describes as the real added value of the current method.

It is not the raw hazard that gets assessed — it is a concrete scenario built around it. For fire, that means: not "the whole building burns down," but realistically "the workshop or one section of the warehouse." Only once the scenario stands does the group discuss it — explicitly without hunting for someone to blame, along the lines of "who forgot to check the fire extinguisher."

Dimension Old sequence New sequence
Starting point Abstract hazard Abstract hazard
Middle step Build and discuss a realistic scenario
Before assessment Capture existing measures (inventory)
Assessment Right after the hazard Only after scenario and inventory

For startups and solo founders, this step makes the decisive difference. An abstract term like "cyberattack" stays vague until someone spells out what it concretely means: system locked down, server corrupted, devices wiped and rebuilt. Only then can you ask how often such a case realistically occurs and what it would cost — and only then can you attach a damage amount and a probability to it.

Why a measures inventory comes before the assessment

Every company has already done something against risk — even if nobody ever called it that. Someone knows where the fire extinguisher is. There is an insurance policy, even if nobody knows its fine print by heart. That inventory is now deliberately captured before the assessment, instead of staying an implicit assumption in the back of someone's mind.

The boundary matters here: at this stage, Beraterium runs no fact-check. Nobody reviews an insurance policy line by line or asks for bank statements. That would blow the scope of a workshop and is not the mandate. Instead, the inventory named in the room counts as the starting point — unless the group itself flags a known gap, such as "we're not covered against natural disasters." In that case, it flows straight into the assessment.

How the method differs for solo founders and small teams

For larger teams of five or more people, the classic list works well because different departments bring different knowledge. For solo self-employed people and two- to three-person startups, that internal contrast is missing — so the number of questions drops sharply without losing depth.

  • Larger team (mid-market): Up to 100 questions, worked through point by point because several perspectives sit in the room.
  • Solo founders and small startups: 12 to 14 individually assembled questions, each discussed as its own scenario instead of just checked off.

In this setup, Beraterium itself takes an active role. Because there is no second or third opinion at the table, Till and Peter build the scenario together with the person and bring in additional perspectives — for example from comparable cases such as a fund management firm where a calculation error leads to a wrong asset weighting in the portfolio. It is not the number of questions that decides the quality of the analysis — it is how realistic the scenario behind it becomes.

Solo self-employed people also tend to feel certain risk types far more heavily than mid-market companies do. Reputational damage can be existential for a financial adviser or a bespoke tailoring business, because the person and the brand are inseparable — an aspect covered in more depth in the biggest risks for the self-employed and freelancers.

What role the roundtable with multiple perspectives plays

For larger teams, the ideal setup has the leader plus four more people from different areas at the table — accounting, sales, production, warehouse. The value does not come from the number of chairs; it comes from the contrast between perspectives.

A practical example: asked about supplier problems, the managing director says "no issues." The person from the warehouse disagrees immediately — late deliveries, damaged goods, even though the contract says otherwise. Both views are honestly meant; both are incomplete without the other. The same pattern shows up with IT: "It runs fine," says leadership — "two hours a day fighting an outdated system," says accounting.

For solo self-employed people, that internal contrast is naturally missing. People are the central factor here — which is why Beraterium takes on the role of discussion partner, bringing pushback and additional examples instead of only listening.

How Till and Peter recognise a successful risk analysis

Completeness of the list is not the benchmark — what matters is what was not on anyone's radar before. Time and again, two or three points surface that nobody had considered: from missing first-aid certification despite a legal requirement, to an uninsured studio fire.

Another recurring pattern: self-employed people or founders realise during the workshop that they lose a third of their working time to tasks that have nothing to do with their actual core work. Insights like that change decisions immediately — long before any measure is even implemented.

Clarity itself is already a result. Anyone who knows what can genuinely harm their business no longer has to live with a vague "it could happen" — they can hold every business decision up against four clear questions: What does this get me? How high is the risk? What can I lose? What can I gain? That is risk management in the practical sense — not theory for a drawer, but a basis for faster, safer decisions.

What is still coming in the second phase

Assessment is not the end of the work — it is where the real work starts. Once the portfolio stands, the next question is how identified risks turn into effective measures: who decides what is even feasible? Who implements it? And how does that differ between a two-person startup and a mid-market company with several departments?

Till and Peter deliberately leave that open for a dedicated episode. The reason is substantive, not dramatic: prioritising measures does not mean working through as many points as possible — it means finding the few that actually work, a topic that deserves its own depth rather than a quick mention at the end of a methodology episode.

Conclusion: Clarity as the first step toward more room to act

It is not the size of the question catalogue that decides the quality of a risk analysis — it is whether the questions fit the company and whether they turn into a scenario that can actually be discussed. For startups and solo founders, that means concretely: fewer questions, more depth, and Beraterium itself as sparring partner at the table.

What concretely becomes of the identified risks — who decides what is feasible and who implements it — Till and Peter deliberately save for a dedicated episode, because that second step deserves just as much substance as the analysis itself.

Next step: If you want to see what your own set of baseline risks, industry risks and probing questions would look like, the right entry point is the 4-week risk check for startups or the 2-week risk compass for solo self-employed people — both starting with a free intro call.

This text was created with AI assistance and editorially reviewed.

Risk Radar Podcast

🎧 Watch the full podcast episode here:

Watch on

Frequently asked questions

What is the difference between baseline risks, industry-specific risks and probing questions?

Baseline risks are the same for every company, such as IT outage or losing a key person. Industry-specific risks depend on the business model. Probing questions target blind spots that rarely get raised openly.

How many questions does a risk analysis need for solo self-employed people?

For solo founders and small startup teams, a tailored set of 12 to 14 questions is enough, compared with around 100 items for larger mid-market companies with several departments.

Why does Beraterium assess a hazard only after building a scenario, not directly?

An abstract term like "cyberattack" is hard to translate into currency and probability. Only a concrete, discussed scenario makes the damage amount and frequency tangible and comparable.

What are probing questions in risk management?

Probing questions make up the last third of a risk set and deliberately target what usually gets skipped — reputational damage, weaponised attachments, or knowledge that leaves the company with one person.

Who should take part in a risk analysis roundtable?

Ideally around five people from different areas such as leadership, accounting, sales or warehouse. For solo self-employed people and small teams, Beraterium itself takes on the role of the second and third perspective.

When is a risk analysis successful from Beraterium's perspective?

When at least one point surfaces that nobody had considered before, and when it leaves more clarity about potential damage. Long term, success also shows up as saved costs or higher productivity.

What happens after the risk analysis with the risks that were found?

A second phase turns the assessed risks into concrete, prioritised measures — a few effective ones, not a long symbolic list. Till and Peter cover that implementation phase in a dedicated future episode of Risk Radar.

Clarify risks in your business?

Book a free intro call – 30 minutes, no obligation.

Book a free intro call