How a risk score is reached.
Risk is likelihood multiplied by impact, each on a scale of one to five, giving a value out of twenty-five. The same scale is applied to every threat, which is what makes two findings comparable and this year comparable to last.
Two numbers, not one.
The single most common mistake in risk work is scoring once. We score every threat before controls and again after them, because the distance between the two is the only honest measure of what your security actually buys.
Before controls
The score a threat carries with nothing in place to stop it. This is the step most assessments skip.
After controls
The score once the controls you have, and those we recommend, are credited. This is what you decide to accept.
The value of security
Inherent minus residual is what your investment removed, expressed as a number a board can read.
Try it.
Pick a likelihood and an impact. The cell and the score resolve the way they would in a register.
The anchors are written down.
A score means the same thing when a different analyst applies it, and you can challenge a rating on its substance.
| Value | Meaning |
|---|---|
| 5 | Almost certain, or already observed here |
| 4 | Likely, given known activity against peers |
| 3 | Possible, with a credible path |
| 2 | Unlikely under current conditions |
| 1 | Rare, requiring exceptional circumstances |
| Value | Meaning |
|---|---|
| 5 | Severe, sustained or material harm |
| 4 | Major, needing executive involvement |
| 3 | Moderate, absorbed with some cost |
| 2 | Minor, handled in normal operations |
| 1 | Negligible business consequence |
See the whole method.
The scoring model is one stage of six. The methodology page sets out how a finding gets from an asset to a ranked risk.