The problem of ever-evolving and growing risks never ceases to be an issue. Organizations in the oil and gas industry need to spend more and more money on protection, look for more qualified workers or train their staff on various innovations in this field. After many foreign vendors left the Russian market due to sanctions, threats that were minor have become more dangerous. Since even the most common risk in the form of, for example, a phishing link can become a big problem if it is partially disabled or there is no full protection of the functionality. Therefore, it is necessary to create their own software, their own methods of assessing risk events in information security, which will correspond to different areas of risk situations and at the same time have the quality of services, good functionality, not high cost and excellent quality. This article discusses a new unified method of information security containing the positive qualities of other methods and standards for assessing information security risks, but with the elimination of their shortcomings with the possibility of application in organizations of the oil and gas industry.