Is starting to ask questions about risks better than turning a blind eye on them?
Does your risk register contain a list of control gaps, of vulnerabilities or other issues? Have you thought of a list of uncertain future events?
Risks should focus on impact to business objectives and business opportunities.
Risks should be brought to the attention of decision makers in order to ignite appropriate actions.
One could start of with a qualitative method to determine if a threat to business objectives require attention, say a more detailed analysis.
For those that meet the threshold, go perform detailed analysis.
Analysis provides context, which should be relevant information to decision makers.