EN - FR - DE - ES - IT - PT -

LexiconDream

🎲 Risk

The potential for loss or damage when a threat exploits a vulnerability.

Risk

Risk is the chance that something bad happens and how much it hurts. In security, risk combines three things: a threat, a vulnerability, and an impact. A ransomware crew is the threat. An unpatched server is the vulnerability. Lost revenue and downtime are the impact. Remove any one of the three and the risk disappears. Patch the server and the vulnerability is gone. Block the ransomware crew's infrastructure and the threat is reduced. Move critical data offline and the impact shrinks.

Risk is not binary. It exists on a spectrum. Some risks are acceptable. A small business might tolerate the risk of a website defacement. It cannot tolerate the risk of losing customer payment data. The difference is impact. Risk assessment quantifies that difference. It asks what could go wrong, how likely it is, and what it would cost. Then it compares the cost of the risk against the cost of mitigating it. Spending $100,000 to protect a $10,000 asset is not good risk management. Spending $10,000 to protect a $1 million asset is. The math is rarely precise, but the exercise forces prioritization. Not every risk can be eliminated. The goal is to understand which ones matter most.

Risk components

Risk is the language of business. Security teams that speak it get budgets. Ones that talk only about threats do not.

Comments (3)

  1. New to markets
    Is there a simple way to compare risk across different asset types?
  2. Financial advisor
    Possibility of loss or missing returns. Measuring it properly is harder than most people expect.
  3. Investor
    Higher potential reward usually comes with more of this. Balancing the two is the constant job.

Leave a comment