← CISM: manage security, risk, and incidents
03 / 8 · 30 MIN

Assess risk and uncertainty

Interpret exposure, controls, and estimates without overstating precision.

Concept and mechanism

A vulnerability is a condition that may contribute to harm; risk also considers threat, likelihood, impact, and context. The same technical score in an isolated laboratory and a settlement service may require different priorities. Describe a scenario with asset, threat, conditions, event, and consequence. Record existing controls and evidence of effectiveness. Inherent risk represents a view without the controls considered; residual risk represents what remains after them. State the conventions used so two teams do not compare numbers built on different assumptions. An implementation plan is not yet an effective operational control.

Guided application

In a simplified analysis, €80,000 loss per occurrence and expected frequency of 0.25 per year yield €20,000 expected annual loss. This predicts neither a certain annual bill nor the full loss distribution. Use ranges, assumptions, and sensitivity analysis when data is weak. Insurance may transfer part of the financial consequence, conditional on coverage and exclusions; it does not itself restore a service or remove responsibilities. Before proposing treatment, connect estimates to business impact and approved limits. If a threat change alters likelihood, revisit the analysis while retaining the previous decision history.

IN PRACTICE

An estimated reduction from €200,000 to €60,000 leaves €60,000 residual risk; €140,000 is the estimated reduction.

Common pitfalls

Technical score as complete risk; decimal places as confidence; insurance as elimination.

Related topics: Treat, monitor, and escalate risk · Develop the security program

Take this idea with you

A useful estimate shows context, assumptions, limits, and options.

Create account

Reference: Guide for Conducting Risk Assessments · CISM current outline before November 3, 2026