Concept and mechanism
A risk should describe asset, condition, event, and impact with reviewable assumptions. “Old server” is incomplete inventory rather than sufficient risk explanation. Quantitative assessments also depend on assumptions: per-event loss multiplied by expected frequency gives a mean value in the model, not a guaranteed prediction. High-impact risks and uncertainty do not disappear because the mean is low. Residual acceptance belongs to governance-defined authority with controls, limits, review, and treatment plan. A technician can supply evidence without being authorized to accept the impact.
Guided application
During procurement, confirm supplier evidence covers relevant service, period, and controls. An out-of-scope report does not demonstrate protection for a new service. For technical assessments, define targets, authorization, contacts, and stop conditions before testing; staging-production similarity does not expand authorization. Policy needs procedures specifying who does what and how completion is demonstrated. In committees, report exposure by criticality and due date: 95% patched can hide that every critical endpoint is among the remaining 5%. Reporting should support decisions about remaining risk.
In the simplified model, €20,000 per occurrence × 0.25 occurrences/year = €5,000/year expected. Also present uncertainty, relevant potential impact, and controls rather than only the number.
Common pitfalls
Accepting risk without authority; extrapolating assurance; testing outside scope; removing assets from the denominator; confusing mean with maximum.
Related topics: Controls, identity, and cryptography · Threats, exposure, and priority
A sound decision states scope, owner, evidence, and review conditions.
Reference: Guide for conducting risk assessments · SY0-701 V7