How a risk score is reached.

Risk is likelihood multiplied by impact, each on a scale of one to five, giving a value out of twenty-five. The same scale is applied to every threat, which is what makes two findings comparable and this year comparable to last.

Two numbers, not one.

The single most common mistake in risk work is scoring once. We score every threat before controls and again after them, because the distance between the two is the only honest measure of what your security actually buys.

Inherent

Before controls

The score a threat carries with nothing in place to stop it. This is the step most assessments skip.

Residual

After controls

The score once the controls you have, and those we recommend, are credited. This is what you decide to accept.

The gap

The value of security

Inherent minus residual is what your investment removed, expressed as a number a board can read.

Try it.

Pick a likelihood and an impact. The cell and the score resolve the way they would in a register.

Likelihood

Impact

9Elevatedlikelihood 3 x impact 3

The anchors are written down.

A score means the same thing when a different analyst applies it, and you can challenge a rating on its substance.

Likelihood
ValueMeaning
5Almost certain, or already observed here
4Likely, given known activity against peers
3Possible, with a credible path
2Unlikely under current conditions
1Rare, requiring exceptional circumstances
Impact
ValueMeaning
5Severe, sustained or material harm
4Major, needing executive involvement
3Moderate, absorbed with some cost
2Minor, handled in normal operations
1Negligible business consequence

See the whole method.

The scoring model is one stage of six. The methodology page sets out how a finding gets from an asset to a ranked risk.

Back to methodology