Guided assessment
Walk through six steps to add a new risk to the register — pick a scenario, name the threat and vulnerability, rate impact and likelihood, decide the treatment, and formalize.
Choose a scenario
Every scenario below comes from things that genuinely go wrong in small and mid-size organizations. Pick one that feels close to home.
Name the threat and the weakness
A threat is what could cause harm. A vulnerability is the weakness that lets it. It takes both to make a risk.
Rate impact and likelihood
One scale for everything: 1, 2 or 3. Rate the impact on each of the three things security protects — confidentiality, integrity, availability — then rate how likely the whole thing is.
| Value | Impact means… | Likelihood means… |
|---|---|---|
| 1 · Low | Minor harm. Little cost or disruption — absorbed in normal work. | Unlikely. No history; would need unusual conditions. |
| 2 · Medium | Noticeable harm. Real cost or downtime — recoverable with effort. | Possible. Happens in the industry; could happen to you this year. |
| 3 · High | Serious harm. Major financial, legal or reputational damage. | Expected. Happens often, or conditions strongly favour it. |
Review the raw risk
Raw risk is your exposure before you change anything: impact × likelihood, where impact is the highest of your C, I and A ratings.
Score 1–2 · Low · 3–4 · Medium · 6–9 · High
— Rate impact & likelihood to see the predicted raw risk —
Decide the treatment
Four legitimate options. The only wrong move is not choosing.
Act on your decision
What this step asks for depends on the treatment you chose.