The method, in full.

Every assessment we run follows the same six stages and the same scoring model. This page sets out exactly how a number is arrived at, because a score you cannot interrogate is a score you cannot defend.

The scoring model

Risk is scored as likelihood multiplied by impact, each on a scale of one to five, giving a value out of twenty-five. The same scale is applied to every threat in every assessment, which is what makes two findings comparable, and what makes this year comparable to last.

The anchors below are the definitions we hold to. They are written down so that a score means the same thing when a different analyst applies it, and so that you can challenge a rating on its substance.

Likelihood anchors
ValueRatingDefinition
5Almost certainExpected to occur in most circumstances, or already observed in your environment.
4LikelyWill probably occur, given known threat activity against comparable organizations.
3PossibleCould occur at some point, and there is a credible path for it.
2UnlikelyCould occur, but would require conditions that are not currently present.
1RareWould require an exceptional combination of circumstances.
Impact anchors
ValueRatingDefinition
5SevereSustained outage, regulatory action, or material financial and reputational harm.
4MajorSignificant disruption or loss requiring executive involvement and disclosure.
3ModerateContained disruption absorbed with existing resources and some cost.
2MinorLimited effect handled within normal operations.
1NegligibleLittle practical consequence to the business.

The six stages

What happens at each stage, and what it produces.

01

Asset identification

We start from what your organization actually needs to protect, not from an inventory export. Through workshops with the people who run the systems, we map the data, processes and dependencies in scope and tie each one to the business value it carries. Anything that cannot be tied to value does not belong in the assessment.

Produces: Scoped asset register, each entry tied to the business function it supports

02

Threat modelling

We work through how each asset could realistically be attacked. STRIDE gives the structure, so spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege are each considered against every component. We then map the credible threats to MITRE ATT&CK techniques, which grounds the model in how adversaries actually operate rather than in speculation.

Produces: Threat catalogue mapped to STRIDE categories and ATT&CK techniques

03

Vulnerability analysis

Threats only matter where something can be exploited. We connect concrete weaknesses to the threats that would use them, drawing on your architecture, your configuration and your operating practice. Where you already hold scan or test results we use them, and where they are missing we say so rather than assuming the gap away.

Produces: Weaknesses linked to the specific threats that would exploit them

04

Inherent risk scoring

Each threat is scored on likelihood and impact, one to five, before any control is credited. Multiplying the two gives an inherent score out of twenty-five. Scoring before controls sounds academic, and it is the step most assessments skip, but without it you cannot show what your existing security actually buys you.

Produces: Inherent scores out of 25, with the reasoning recorded for each

05

Control mapping

We match mitigations to what you already run before recommending anything new. In most environments a meaningful share of the exposure closes through configuration, coverage or process changes to tools already licensed. New spend is recommended where it is genuinely required, and it is named as such.

Produces: Controls mapped to existing tooling, with gaps identified separately

06

Residual risk and roadmap

We re-score every threat with controls accounted for, producing the residual figure. The distance between inherent and residual is the measurable value of your security programme. What remains is sequenced into a roadmap ordered by risk reduction per unit of effort, so the first item on the list is the one that moves the number most.

Produces: Residual scores and a roadmap sequenced by risk reduction per unit of effort

Grounded in standards your auditors already recognise

We build on published frameworks rather than a proprietary scale, so the assessment speaks the same language as your auditors, your regulators and your partners.

NIST SP 800-30Guide for conducting risk assessments, and the backbone of how we score.
NIST SP 800-37Risk Management Framework, which structures how risk is governed over time.
NIST SP 800-53The security and privacy controls catalogue we map recommendations against.
NIST CSF 2.0Organises findings into functions that leadership reads without translation.
ISO/IEC 27005Information security risk management, aligning the work to the ISO 27001 world.
STRIDEA threat modelling method for categorising how a system can be attacked.
MITRE ATT&CKReal-world adversary tactics and techniques that ground the threat model.

Why traceability is the whole point

A risk score is an argument, not a measurement taken off an instrument. It carries weight only when the reasoning behind it is visible and can be challenged.

Every finding in our reports records what was assessed, which threat was modelled, what evidence supported the likelihood and impact ratings, and which control changed the residual figure. If your auditor asks why a risk is rated four rather than three, the answer is in the document.

This is also what makes reassessment worth doing. Because the method and the anchors do not move, a second assessment shows real change rather than a change of opinion.

See the method applied to a real system.

Our satellite systems threat model is published in full, with the same structure we use for client work.

Read the threat model