The operational dependency of internet cafes (gaming centers) on Information Technology (IT) infrastructure creates significant risk exposure to business continuity and data security. Cybernetic PC Gaming, a gaming service provider in Bandung, faces challenges in the form of cyber threats and physical disruptions that have the potential to damage its reputation and financial standing. This study aims to identify, analyze, and evaluate the level of information security risk by applying the National Institute of Standards and Technology (NIST) Special Publication 800-30 framework. The research method employed is descriptive qualitative, encompassing the nine stages of risk management, from system characterization to mitigation results documentation. The study successfully identified five primary risk profiles. Based on risk matrix calculations, two threats were classified at a "High" level: power outages lacking adequate backup power support and the risk of malware infection from customers downloading harmful files. Meanwhile, internet connection disruptions, natural disasters, and hardware dust accumulation were rated at a "Moderate" level. As a solution, this research formulates strategic control recommendations, including the procurement of a backup generator, internet service provider (ISP) redundancy, and the implementation of web filtering and enterprise-grade antivirus software. In conclusion, the systematic application of the NIST 800-30 standard can transform risk management at Cybernetic PC Gaming from a reactive to a proactive approach, thereby ensuring operational resilience and sustainable protection of digital assets.