Concept and mechanism
A vulnerability is a condition that may contribute to harm; risk also considers threat, likelihood, impact, and context. The same technical score in an isolated laboratory and a settlement service may require different priorities. Describe a scenario with asset, threat, conditions, event, and consequence. Record existing controls and evidence of effectiveness. Inherent risk represents a view without the controls considered; residual risk represents what remains after them. State the conventions used so two teams do not compare numbers built on different assumptions. An implementation plan is not yet an effective operational control.
Guided application
In a simplified analysis, €80,000 loss per occurrence and expected frequency of 0.25 per year yield €20,000 expected annual loss. This predicts neither a certain annual bill nor the full loss distribution. Use ranges, assumptions, and sensitivity analysis when data is weak. Insurance may transfer part of the financial consequence, conditional on coverage and exclusions; it does not itself restore a service or remove responsibilities. Before proposing treatment, connect estimates to business impact and approved limits. If a threat change alters likelihood, revisit the analysis while retaining the previous decision history.
An estimated reduction from €200,000 to €60,000 leaves €60,000 residual risk; €140,000 is the estimated reduction.
Common pitfalls
Technical score as complete risk; decimal places as confidence; insurance as elimination.
Related topics: Treat, monitor, and escalate risk · Develop the security program
A useful estimate shows context, assumptions, limits, and options.
Reference: Guide for Conducting Risk Assessments · CISM current outline before November 3, 2026