Harm may include operational disruption, financial loss, safety impact, legal exposure, fraud, loss of intellectual property, or damage to customers and partners.
A useful cyber-risk statement describes a scenario rather than naming a weakness in isolation: a threat could exploit a condition affecting particular assets or services and cause defined business consequences. Likelihood and impact help estimate risk, but both contain uncertainty and should be supported by assumptions and evidence.
Key points
Primary purposeConnect technical conditions to decisions about business and mission objectives.
Assessment inputsCritical services, assets, threats, vulnerabilities, existing controls, dependencies, likely consequences, and uncertainty.
Response optionsFor negative cyber risks, accept, avoid, mitigate, share, or transfer. Positive enterprise-risk opportunities use different responses, such as realize or enhance.
Important distinctionVulnerability severity is not the same as risk; exposure, exploitability, business context, and compensating controls can change priority.
Important limitationA single numeric score can hide uncertainty and should not replace a documented scenario and accountable decision.