Network Functions Virtualization (NFV) helps service providers become more agile and reduce their costs. However, NFV’s new architecture, operations, and openness create new security challenges. This paper discusses a risk identification methodology, followed by a careful review of the top five security risks when migrating services to NFV. The intent is to provide security practitioners with a basis for developing a documented risk dashboard in order to bring down the overall security risk to an acceptable level when migrating to NFV.