If you're doing risk assessments, you're probably basing your strategy on data classification. This makes a lot of sense you want to protect your critical data, and worry less about the non-critical items. Except, how do you know where your critical data is?
There's several options, one of which is using a product to scan your shares and servers for restricted data types like credit card numbers, social security numbers, etc. An even more advanced solution would be to install a network device, such as an Imperva appliance to search for critical data types. This will allow you to detect systems that contain the data, and perform a more exhaustive risk assessment. In addition, you'll have the ability to prevent the sharing of that data to untrusted networks if needed.