As a following step to risk assessment, we provide recommendations to organisations for the selection of the most appropriate security and privacy controls, indicating optimization practices, in order to minimize the expected damage. In this context, the service assures an acceptable risk level for the cooperating stakeholders. Besides, the proposed system promotes the necessary defensive capabilities and provides a rational decision-making to help stakeholders determine which security controls must be implemented to encounter the identified security issues and cyber-risks.