# What is Cyber Risk?

> Cyber risk is the effect of uncertainty on organizational objectives arising from digital technology, information, or dependence on connected services.

- Canonical URL: https://yellowcube.eu/glossary/cyber-risk/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Harm may include operational disruption, financial loss, safety impact, legal exposure, fraud, loss of intellectual property, or damage to customers and partners.

A useful cyber-risk statement describes a scenario rather than naming a weakness in isolation: a threat could exploit a condition affecting particular assets or services and cause defined business consequences. Likelihood and impact help estimate risk, but both contain uncertainty and should be supported by assumptions and evidence.

### Key points

- **Primary purpose:** Connect technical conditions to decisions about business and mission objectives.
- **Assessment inputs:** Critical services, assets, threats, vulnerabilities, existing controls, dependencies, likely consequences, and uncertainty.
- **Response options:** For negative cyber risks, accept, avoid, mitigate, share, or transfer. Positive enterprise-risk opportunities use different responses, such as realize or enhance.
- **Important distinction:** Vulnerability severity is not the same as risk; exposure, exploitability, business context, and compensating controls can change priority.
- **Important limitation:** A single numeric score can hide uncertainty and should not replace a documented scenario and accountable decision.

### Related terms

[Cybersecurity](<https://yellowcube.eu/glossary/cybersecurity/>) · [Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [Business impact analysis (BIA)](<https://yellowcube.eu/glossary/business-impact-analysis/>) · [Risk assessment](<https://yellowcube.eu/glossary/risk-assessment/>)

### Sources

[NIST IR 8286r1: Integrating Cybersecurity and Enterprise Risk Management](https://csrc.nist.gov/pubs/ir/8286/r1/final) · [NIST glossary: Risk](https://csrc.nist.gov/glossary/term/risk)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

