The method, in full.
Every assessment we run follows the same six stages and the same scoring model. This page sets out exactly how a number is arrived at, because a score you cannot interrogate is a score you cannot defend.
The scoring model
Risk is scored as likelihood multiplied by impact, each on a scale of one to five, giving a value out of twenty-five. The same scale is applied to every threat in every assessment, which is what makes two findings comparable, and what makes this year comparable to last.
The anchors below are the definitions we hold to. They are written down so that a score means the same thing when a different analyst applies it, and so that you can challenge a rating on its substance.
| Value | Rating | Definition |
|---|---|---|
| 5 | Almost certain | Expected to occur in most circumstances, or already observed in your environment. |
| 4 | Likely | Will probably occur, given known threat activity against comparable organizations. |
| 3 | Possible | Could occur at some point, and there is a credible path for it. |
| 2 | Unlikely | Could occur, but would require conditions that are not currently present. |
| 1 | Rare | Would require an exceptional combination of circumstances. |
| Value | Rating | Definition |
|---|---|---|
| 5 | Severe | Sustained outage, regulatory action, or material financial and reputational harm. |
| 4 | Major | Significant disruption or loss requiring executive involvement and disclosure. |
| 3 | Moderate | Contained disruption absorbed with existing resources and some cost. |
| 2 | Minor | Limited effect handled within normal operations. |
| 1 | Negligible | Little practical consequence to the business. |
The six stages
What happens at each stage, and what it produces.
Asset identification
We start from what your organization actually needs to protect, not from an inventory export. Through workshops with the people who run the systems, we map the data, processes and dependencies in scope and tie each one to the business value it carries. Anything that cannot be tied to value does not belong in the assessment.
Produces: Scoped asset register, each entry tied to the business function it supports
Threat modelling
We work through how each asset could realistically be attacked. STRIDE gives the structure, so spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege are each considered against every component. We then map the credible threats to MITRE ATT&CK techniques, which grounds the model in how adversaries actually operate rather than in speculation.
Produces: Threat catalogue mapped to STRIDE categories and ATT&CK techniques
Vulnerability analysis
Threats only matter where something can be exploited. We connect concrete weaknesses to the threats that would use them, drawing on your architecture, your configuration and your operating practice. Where you already hold scan or test results we use them, and where they are missing we say so rather than assuming the gap away.
Produces: Weaknesses linked to the specific threats that would exploit them
Inherent risk scoring
Each threat is scored on likelihood and impact, one to five, before any control is credited. Multiplying the two gives an inherent score out of twenty-five. Scoring before controls sounds academic, and it is the step most assessments skip, but without it you cannot show what your existing security actually buys you.
Produces: Inherent scores out of 25, with the reasoning recorded for each
Control mapping
We match mitigations to what you already run before recommending anything new. In most environments a meaningful share of the exposure closes through configuration, coverage or process changes to tools already licensed. New spend is recommended where it is genuinely required, and it is named as such.
Produces: Controls mapped to existing tooling, with gaps identified separately
Residual risk and roadmap
We re-score every threat with controls accounted for, producing the residual figure. The distance between inherent and residual is the measurable value of your security programme. What remains is sequenced into a roadmap ordered by risk reduction per unit of effort, so the first item on the list is the one that moves the number most.
Produces: Residual scores and a roadmap sequenced by risk reduction per unit of effort
Grounded in standards your auditors already recognise
We build on published frameworks rather than a proprietary scale, so the assessment speaks the same language as your auditors, your regulators and your partners.
Why traceability is the whole point
A risk score is an argument, not a measurement taken off an instrument. It carries weight only when the reasoning behind it is visible and can be challenged.
Every finding in our reports records what was assessed, which threat was modelled, what evidence supported the likelihood and impact ratings, and which control changed the residual figure. If your auditor asks why a risk is rated four rather than three, the answer is in the document.
This is also what makes reassessment worth doing. Because the method and the anchors do not move, a second assessment shows real change rather than a change of opinion.
Go deeper.
Three parts of the method, each set out on its own.
See the method applied to a real system.
Our satellite systems threat model is published in full, with the same structure we use for client work.