CYBER SECURITY • GOVERNANCE, RISK, AND COMPLIANCE

Risk Assessment — Perform a basic risk assessment (assets, threats, vulnerabilities, controls) (conceptual)

Learn to systematically identify and evaluate cyber risks by mapping assets, threats, vulnerabilities, and controls.

Historical Context & Motivation

The practice of risk assessment did not originate in the digital world. Long before networked computers existed, engineers in the nuclear, aerospace, and financial industries developed systematic methods for identifying what could go wrong, how likely it was, and what the consequences might be. The insurance industry, dating back centuries, was arguably the first domain to formalize risk quantification — actuaries computed probabilities of loss events and priced policies accordingly. When computing systems became critical infrastructure in the late twentieth century, organizations recognized that the same disciplined thinking needed to be applied to information systems, where a single vulnerability could expose millions of records or halt business operations entirely.

The migration of risk assessment into cybersecurity was driven by a series of high-profile incidents and regulatory responses. As governments and enterprises began to depend on networked systems for everything from defense to commerce, ad-hoc security measures proved insufficient. Structured frameworks emerged to bring order to what had been a reactive, patchwork discipline, and the fundamental vocabulary of assets, threats, vulnerabilities, and controls became the lingua franca of information security risk management.

1983
TCSEC (Orange Book)
The U.S. Department of Defense publishes the Trusted Computer System Evaluation Criteria, one of the earliest formal frameworks for assessing the security posture of computing systems based on risk categories.
1996
NIST SP 800-12
NIST releases its foundational guide to computer security, establishing the risk management lifecycle — including identification of assets, threats, and vulnerabilities — as a core responsibility for federal agencies.
2002
NIST SP 800-30
NIST publishes the Risk Management Guide for Information Technology Systems, formalizing a step-by-step risk assessment methodology that becomes widely adopted across government and industry.
2009
ISO/IEC 27005
The International Organization for Standardization releases a dedicated standard for information security risk management, providing globally recognized guidelines for conducting risk assessments within an ISMS.
2018
NIST CSF v1.1 & GDPR
The updated NIST Cybersecurity Framework and the enforcement of the EU General Data Protection Regulation make risk assessment a legal and operational imperative for organizations worldwide.

Understanding this history reveals the central question that risk assessment seeks to answer: Given limited resources, how does an organization decide where to invest in security? Without a structured methodology, security teams either overspend on low-probability threats or remain blind to critical exposures. Risk assessment provides the analytical foundation for making these decisions rationally and defensibly.

Core Principles & Definitions

A risk assessment is fundamentally about establishing a causal chain: a threat agent exploits a vulnerability in an asset, producing an adverse impact, and controls are the mechanisms put in place to break or weaken that chain. The discipline rests on several foundational principles that, once internalized, make the entire process intuitive.

1

Asset Identification

An asset is anything of value to the organization: data, hardware, software, personnel, or reputation. You cannot protect what you have not inventoried, so asset identification is always the first step.
2

Threat Enumeration

A threat is any potential event or actor that could cause harm to an asset. Threats may be natural (earthquake, flood), human and intentional (hacker, insider), or human and accidental (misconfiguration, data entry error).
3

Vulnerability Analysis

A vulnerability is a weakness or gap in protections that a threat can exploit. An unpatched server, a lack of multi-factor authentication, or poor physical access controls are all examples. Without a matching vulnerability, a threat remains theoretical.
4

Control Selection

A control (or countermeasure) is a safeguard that reduces the likelihood or impact of a risk. Controls are categorized as preventive, detective, or corrective, and may be technical, administrative, or physical in nature.
5

Risk = Likelihood × Impact

Risk is the product of how probable a threat-vulnerability pair is to be exploited (likelihood) and the damage it would cause (impact). This relationship is the cornerstone of prioritization.
KEY TAKEAWAY
Think of risk assessment like a home security audit. Your assets are everything you value — your family, electronics, important documents. Threats include burglars, fires, and storms. Vulnerabilities are the unlocked back door, the expired smoke detector batteries, or the missing surge protector. Controls are the deadbolts you install, the smoke alarms you maintain, and the insurance policy you purchase. You do not invest in a reinforced vault for items of negligible value — you prioritize based on what matters most and what is most likely to go wrong.

Visual Explanation — The Risk Equation Chain

The relationship between assets, threats, vulnerabilities, and controls is best understood as a causal chain. The following diagram illustrates how a threat agent interacts with a vulnerability present in an asset, how that interaction produces risk, and how controls intervene at different points along the chain to reduce overall risk exposure.

The causal chain shows a threat exploiting a vulnerability in an asset, producing impact. The central risk equation synthesizes likelihood and impact. Controls (preventive, detective, corrective) feed back to reduce the overall risk level.

Notice that the diagram positions controls as a feedback mechanism that acts on the risk equation from below. A preventive control (such as a firewall rule or an access policy) reduces likelihood by making it harder for the threat to reach the vulnerability. A detective control (such as an intrusion detection system or audit log) does not prevent the event but ensures rapid discovery, indirectly limiting impact through faster response. A corrective control (such as a disaster recovery plan or a patch deployment process) minimizes damage after the event has occurred. Effective risk management layers all three types — a concept known as defense in depth.

Mathematical & Analytical Framework

While many risk assessments in practice use qualitative rating scales (e.g., Low / Medium / High), the underlying logic is grounded in a semi-quantitative formula that makes prioritization transparent and repeatable. Understanding the mathematical structure clarifies why certain risks demand immediate attention while others can be accepted or deferred.

FUNDAMENTAL RISK EQUATION
Risk = Likelihood × Impact
Risk = the overall risk level (qualitative rating or numeric score). Likelihood = the probability that a given threat will exploit a given vulnerability (often rated 1–5). Impact = the severity of the consequence if the risk event materializes (often rated 1–5).

In quantitative analysis, likelihood can be expressed as an Annualized Rate of Occurrence (ARO) — the estimated number of times a threat event occurs per year. Impact is monetized as the Single Loss Expectancy (SLE), which represents the dollar cost of a single occurrence. Their product yields a powerful planning metric.

SINGLE LOSS EXPECTANCY
SLE = Asset Value × Exposure Factor
Asset Value (AV) = the monetary worth of the asset. Exposure Factor (EF) = the percentage of the asset lost in a single event (0.0–1.0).
ANNUALIZED LOSS EXPECTANCY
ALE = SLE × ARO
ALE = the expected annual financial loss from a specific risk. ARO = the estimated frequency of occurrence per year. This metric directly informs budget allocation: if a control costs less than the ALE it mitigates, it is generally cost-justified.
📊 Qualitative vs. Quantitative
In practice, many organizations use a qualitative approach with ordinal scales (e.g., 1–5) because precise probabilities and dollar values are difficult to establish for cyber events. The formulas above illustrate the quantitative approach. A hybrid — semi-quantitative — method is also common, where ordinal ratings are multiplied to produce a risk score used for prioritization without claiming actuarial precision.
RESIDUAL RISK
Residual Risk = Inherent Risk − Control Effectiveness
Inherent Risk = risk before any controls are applied. Residual Risk = the risk remaining after controls have been implemented. Management must decide whether the residual risk falls within the organization's risk appetite (the level of risk they are willing to accept).

Detailed Breakdown — The Risk Matrix & Threat Taxonomy

Once likelihood and impact have been rated for each identified risk scenario, the results are plotted on a risk matrix (also called a heat map). This two-dimensional grid provides an immediate visual prioritization, with the upper-right quadrant (high likelihood, high impact) demanding the most urgent attention. The matrix below uses a standard 5 × 5 format commonly found in NIST and ISO-aligned assessments.

A standard 5 × 5 risk matrix where each cell displays the product of Likelihood (vertical axis) and Impact (horizontal axis). Green cells represent low risk, amber is medium, orange is high, and deep red is critical. Risk scenarios plotted in the upper-right demand immediate action.

The matrix makes it immediately clear that a risk with Likelihood = 3 and Impact = 5 (score 15) demands more attention than one with Likelihood = 5 and Impact = 2 (score 10), even though the latter is more frequent. This multiplicative relationship ensures that catastrophic but rare events are not underweighted — a crucial property when dealing with cyber threats such as ransomware attacks or major data breaches, which may occur infrequently but carry devastating consequences.

Threat Taxonomy

Common threat categories used in risk assessments
CategoryExamplesMotivation / Cause
NaturalEarthquake, flood, hurricane, wildfireEnvironmental — uncontrollable but predictable in certain regions
Human — IntentionalHackers, nation-state actors, insider threats, hacktivistsFinancial gain, espionage, ideology, revenge
Human — AccidentalMisconfigured server, accidental data deletion, phishing clickNegligence, lack of training, fatigue, complexity
Environmental / TechnicalPower outage, hardware failure, software bugInfrastructure degradation, supply chain issues

Worked Example — Assessing Risk for a University Web Application

Consider a university's student records web application that stores names, grades, Social Security numbers, and financial aid data. We will walk through a basic risk assessment for this system using the qualitative 5 × 5 matrix and then compute the quantitative ALE for one specific scenario.

Risk Assessment: SQL Injection Attack on Student Records System
1
Step 1 — Identify the AssetThe primary asset is the student records database. It contains personally identifiable information (PII) for approximately 30,000 students. We estimate the asset value at AV = $3,000,000, reflecting the cost of regulatory fines, notification, credit monitoring, and reputational damage if the data is fully compromised.
Asset: Student Records Database — AV = $3,000,000
2
Step 2 — Identify the ThreatThe threat scenario we focus on is a SQL injection attack carried out by an external attacker seeking to exfiltrate student PII. According to the OWASP Top 10, injection flaws remain among the most prevalent web application vulnerabilities. The threat agent is classified as Human — Intentional with a financial motivation (selling data on the dark web).
Threat: SQL Injection by external attacker (Human — Intentional)
3
Step 3 — Identify the VulnerabilityA code review reveals that the web application uses dynamic string concatenation to build SQL queries rather than parameterized queries or prepared statements. Additionally, there is no Web Application Firewall (WAF) filtering inbound requests. These are the exploitable vulnerabilities.
Vulnerabilities: (1) No parameterized queries, (2) No WAF
4
Step 4 — Rate Likelihood and Impact (Qualitative)Given that SQL injection is well-understood, automated scanning tools exist, and the application lacks basic defenses, we rate Likelihood = 4 (Likely). The impact of a full PII breach including SSNs for 30,000 students warrants Impact = 5 (Critical). Risk Score = 4 × 5 = 20, placing this scenario firmly in the Critical zone of our risk matrix.
Qualitative Risk Score = 4 × 5 = 20 → Critical
5
Step 5 — Compute Quantitative ALEAssuming a successful SQL injection would compromise roughly 60% of the database before detection (Exposure Factor = 0.6), the Single Loss Expectancy is SLE = $3,000,000 × 0.6 = $1,800,000. If we estimate that such an attack is attempted successfully about once every two years, ARO = 0.5. Therefore, ALE = $1,800,000 × 0.5 = $900,000 per year.
ALE = $1,800,000 × 0.5 = $900,000/year
6
Step 6 — Recommend ControlsWe recommend three layered controls: (1) Preventive — refactor all database queries to use parameterized statements and deploy a WAF; (2) Detective — implement database activity monitoring and anomaly-based alerting; (3) Corrective — establish an incident response plan with data breach notification procedures. The combined annual cost of these controls is estimated at $150,000, well below the $900,000 ALE, making the investment strongly justified.
Control cost ($150K/yr) < ALE ($900K/yr) → Investment justified. Residual risk significantly reduced.

Strengths, Limitations, and Comparisons

No methodology is without trade-offs. Understanding the strengths and limitations of the basic risk assessment approach is essential for applying it appropriately and knowing when more sophisticated techniques are warranted.

Strengths and limitations of basic risk assessment
AspectStrengthsLimitations
SimplicityEasy to understand and communicate to non-technical stakeholders, including executives and board members. A 5 × 5 matrix is immediately intuitive.Oversimplification may obscure nuances — e.g., a score of 12 from (3×4) vs. (4×3) may represent very different scenarios.
ScalabilityCan be performed quickly on a small system or expanded to cover an entire enterprise, adapting the depth of analysis to available resources.At enterprise scale, the number of asset-threat-vulnerability combinations can become unwieldy without tooling and automated discovery.
Quantitative RigorThe ALE formula provides a clear economic basis for control investment decisions and links security spending to business value.Accurate probability and dollar-impact data for cyber events is notoriously difficult to obtain, making quantitative results uncertain.
SubjectivityQualitative ratings are fast and do not require actuarial data, enabling rapid triage.Ratings depend on the assessor's experience and biases. Two teams may rate the same scenario differently without calibration.
Temporal CurrencyAssessments provide a snapshot that informs immediate prioritization and resource allocation.The threat landscape changes rapidly; assessments become stale unless revisited periodically (at least annually or after significant changes).
KEY TAKEAWAY
Think of a basic risk assessment as analogous to a structural engineering survey of a building. It identifies which beams are under the most stress and where the cracks are widest, enabling the owner to allocate repair funds efficiently. It does not, however, predict exactly when or how a beam will fail — that requires advanced finite element modeling (the cybersecurity analogue being continuous threat modeling and red-team exercises). The survey remains invaluable because it converts an overwhelming set of unknowns into a prioritized, actionable list.

Connection to Advanced Risk Management Frameworks

The basic risk assessment you have learned — identifying assets, threats, vulnerabilities, and controls, then rating risk using a likelihood × impact matrix — represents the foundational layer of a much richer discipline. As organizations mature, they adopt comprehensive frameworks that embed this assessment process within broader governance and continuous-improvement cycles. Understanding how your work fits into these frameworks prepares you for real-world security roles.

Basic vs. advanced risk management approaches
ConceptBasic Risk AssessmentAdvanced / Enterprise Approach
ScopeSingle system or applicationEnterprise-wide risk register spanning all business units (NIST RMF, ISO 27001)
MethodologyQualitative 5×5 matrix or simple ALE calculationBayesian networks, Monte Carlo simulations, FAIR (Factor Analysis of Information Risk) for probabilistic modeling
LifecyclePeriodic snapshot (annual or project-based)Continuous monitoring with automated threat intelligence feeds and real-time risk dashboards
Risk TreatmentAccept, mitigate, transfer, or avoidSame four options, but with formal risk treatment plans, KRI (Key Risk Indicator) tracking, and board-level risk appetite statements
Threat ModelingInformal threat enumerationStructured methodologies: STRIDE, PASTA, attack trees, MITRE ATT&CK mapping

Frameworks such as the NIST Risk Management Framework (RMF) formalize the assessment within a six-step lifecycle: Categorize, Select, Implement, Assess, Authorize, and Monitor. The FAIR model replaces ordinal scales with probability distributions, allowing risk to be expressed as a range of potential financial losses with associated confidence intervals. These advanced approaches build directly on the conceptual foundations covered in this lesson — asset valuation, threat-vulnerability pairing, and the fundamental risk equation remain unchanged. What evolves is the precision, automation, and organizational integration of the analysis.

🚀 Looking Ahead
In subsequent courses, you will explore topics such as threat modeling (STRIDE), security control frameworks (NIST 800-53), and quantitative risk analysis (FAIR). Each of these builds on the four-component mental model — assets, threats, vulnerabilities, controls — that you now understand.

Practice Problems

PROBLEM 1CONCEPTUAL
Explain why a threat without a corresponding vulnerability does not constitute a risk. Use the example of a sophisticated nation-state hacking group targeting a completely air-gapped system with no network connectivity.
PROBLEM 2BASIC CALCULATION
A company's email server has an asset value of $500,000. A ransomware attack is estimated to destroy 40% of the data (EF = 0.4) and occurs approximately once every five years (ARO = 0.2). Calculate the Single Loss Expectancy (SLE) and the Annualized Loss Expectancy (ALE).
PROBLEM 3INTERMEDIATE
An e-commerce company identifies three risk scenarios for its payment processing system: (A) DDoS attack — Likelihood 4, Impact 3; (B) Insider data theft — Likelihood 2, Impact 5; (C) Software misconfiguration — Likelihood 5, Impact 2. Using a 5 × 5 risk matrix, rank these scenarios by risk score and explain which should receive the highest control investment and why.
PROBLEM 4APPLIED
You are the security analyst for a hospital network. The CIO asks you to perform a basic risk assessment for the hospital's Electronic Health Records (EHR) system. Identify at least two assets, two threats, two vulnerabilities, and two controls. Then construct a mini risk register with qualitative risk scores for two distinct risk scenarios.
PROBLEM 5CRITICAL THINKING
A startup CTO argues: 'Risk assessments are a waste of time for our 10-person company. We should just implement best practices — strong passwords, patching, and a firewall — and skip the formal assessment.' Construct a rigorous argument for why even a small organization benefits from a structured risk assessment, and identify at least one scenario where blindly following best practices without assessment could lead to a misallocation of security resources.

Lesson Summary

A basic risk assessment is a structured process that identifies what an organization values (assets), what could harm those assets (threats), the weaknesses that threats exploit (vulnerabilities), and the safeguards deployed to reduce risk (controls). Risk is evaluated through the fundamental equation Risk = Likelihood × Impact, which can be applied qualitatively using a 5 × 5 risk matrix or quantitatively using metrics such as SLE, ARO, and ALE. The output is a prioritized risk register that guides resource allocation.

Controls are categorized as preventive (reducing likelihood), detective (enabling rapid discovery), and corrective (minimizing damage after an event), and effective security layers all three in a defense-in-depth strategy. After controls are applied, residual risk must fall within the organization's risk appetite. This foundational methodology scales from a single web application to enterprise-wide governance, and it forms the basis for advanced frameworks including NIST RMF, ISO 27005, and FAIR.

Varsity Tutors • Cyber Security • Risk Assessment — Perform a basic risk assessment (assets, threats, vulnerabilities, controls) (conceptual)