Risk is the chance that something bad happens and how much it hurts. In security, risk combines three things: a threat, a vulnerability, and an impact. A ransomware crew is the threat. An unpatched server is the vulnerability. Lost revenue and downtime are the impact. Remove any one of the three and the risk disappears. Patch the server and the vulnerability is gone. Block the ransomware crew's infrastructure and the threat is reduced. Move critical data offline and the impact shrinks.
Risk is not binary. It exists on a spectrum. Some risks are acceptable. A small business might tolerate the risk of a website defacement. It cannot tolerate the risk of losing customer payment data. The difference is impact. Risk assessment quantifies that difference. It asks what could go wrong, how likely it is, and what it would cost. Then it compares the cost of the risk against the cost of mitigating it. Spending $100,000 to protect a $10,000 asset is not good risk management. Spending $10,000 to protect a $1 million asset is. The math is rarely precise, but the exercise forces prioritization. Not every risk can be eliminated. The goal is to understand which ones matter most.
Risk components
- Threat — who or what could cause harm
- Vulnerability — the weakness they could exploit
- Impact — the damage if they succeed
- Likelihood — the probability it happens
Risk is the language of business. Security teams that speak it get budgets. Ones that talk only about threats do not.
Comments (3)
Leave a comment