Skip to content
Getting Digital

Security Risk Assessment

Also: risk assessment, risk analysis, risk management, risk register, risk appetite

A security risk assessment identifies the threats to an organisation's assets, estimates how likely each is and how much harm it would do, and ranks them so that limited effort goes where it reduces the most harm.

Our take. Risk assessment is the discipline that stops security from being a list of everything anyone is afraid of. Its output is not a heat map; it is a set of decisions, each with a name against it, about what to fix, what to accept and what to insure. A register nobody has made a decision from is a spreadsheet of anxieties.

An organisation cannot protect everything equally, and pretending otherwise protects the wrong things. A risk assessment makes the trade-offs explicit. It lists the assets that matter, the threats to each, and the weaknesses those threats could use; it estimates, for each combination, how likely it is and how bad it would be; and it produces a ranked list from which someone with authority decides what to do. The estimates are rough, the ranking is disputable, and the exercise is still worth more than any alternative, because the alternative is spending the budget on whatever was in the news.

ResponseMeaningWhen it fits
MitigateAdd a control that lowers likelihood or impactThe common case: the fix costs less than the expected harm
AcceptDecide to live with it, and record who decided and until whenThe harm is small, or the fix costs more than it saves
TransferInsure it, or contract it to a party who bears itRare, large losses that a premium can cover; outsourcing that moves the exposure
AvoidStop doing the thing that creates the riskThe activity is not worth its exposure, which is asked less often than it should be

Likelihood and impact are estimated, not measured, and the honest methods say so. Qualitative scales, low to high, are quick and consistent enough to rank; quantitative methods put currency figures on expected loss and are harder, more contestable and far more persuasive to the people who hold budgets. Either way the point is the ranking and the decision, and the decision has to be owned. A risk that is accepted by nobody in particular has not been accepted; it has been ignored with paperwork. The governance-tier security credentials test this as their central skill: put the decision where the accountability sits, in language the business owner can accept or refuse.

Registers decay. Threats change, systems are replaced, the person who accepted a risk leaves, and the register keeps saying what it said the year it was written. A useful register has a review date on every line, an owner who still works there, and a link from each mitigation to something you can check happened. The audit certifications test the ability to evidence exactly that: not that a risk was assessed, but that the control the assessment demanded operated and someone can prove it.

In practice

A company's register lists sixty risks, all rated medium or high, with a heat map on the cover and no decisions inside. A new security lead reduces it to the twelve that concern systems handling customer or payment data, estimates a rough expected annual loss for each, and takes the list to the leadership team with a proposed response for every line. Four are mitigated with controls that cost less than the estimated loss; six are accepted in writing by the executive who owns the affected process, with a review in a year; one is transferred to cyber insurance after checking the policy actually covers it; one, a legacy file-transfer service nobody could name a user for, is switched off. The heat map is gone. The decisions exist.

Often confused with

Threat Modelling
Threat modelling asks how one system's design could be attacked; risk assessment asks, across the whole organisation, which threats deserve the budget. The model supplies threats to the assessment; the assessment decides which of them to spend on.
Vulnerability Management
Vulnerability management handles specific technical flaws as they are found. Risk assessment operates a level up, deciding how much a class of flaw matters and how quickly it must be fixed, which sets the policy the vulnerability process follows.
Penetration Testing
A penetration test produces evidence of what an attacker could do. A risk assessment uses that evidence, with likelihood and impact, to decide what to do about it. Test results without an assessment are findings without priorities.

Key takeaways

  • Rank threats by likelihood and impact so limited effort goes where it reduces the most harm.
  • Four responses: mitigate, accept, transfer, avoid. Each needs a named owner.
  • Registers decay; every line needs a review date, a living owner and a checkable control.

Certifications that test this

Vendor exams whose syllabus covers this concept — facts, cost and a preparation path on each page.

More courses from these shelves

A rotating selection from the course directory, drawn from the subcategories where this concept is taught rather than picked for it. Details, price and the provider link are on the course page.

ISO/IEC 42001: Artificial Intelligence Management System

ISO/IEC 42001: Artificial Intelligence Management System is a comprehensive course designed for professionals looking t…

Udemy

C_THR82: SuccessFactors Performance & Goals Implementation

Are you ready to pass the SAP Certified Associate - SAP SuccessFactors Performance and Goals (C_THR82) exam and take yo…

Udemy

Networking Full Course & Network + certification

This Class of Full Networking Fundamentals, will be fully illustrated with video lessons and sample to which it will ma…

Udemy

Python And Django Framework For Beginners Complete Course

Learn Python From Scratch Beginner to Expert Python.Start from the Python basics and go all the way to creating your ow…

Udemy

The Ultimate AWS Networking Training Course: All In One

Unlock the Future of Cloud: Master AWS Networking and Propel Your Career Forward!In a world powered by the cloud, Amazo…

Udemy

Salesforce Certified Data Cloud Consultant Practice Exams

Get certified with Salesforce Data Cloud Consultant certification by practicing actual exam type questions. This Course…

Udemy

FAQ

Qualitative or quantitative risk assessment?
Qualitative to rank quickly and consistently; quantitative when you need to persuade someone with a budget, because an expected loss in currency is harder to wave away than a red cell. Most mature programmes start qualitative and quantify the top of the list.
Who should own a risk?
The person accountable for the business process it threatens, not the security team. Security can estimate and recommend; only the owner of the process can accept its exposure or fund its mitigation, and a risk accepted by security on the business's behalf has not really been accepted.
How often should the register be reviewed?
Each line on its own date, set when the decision was made, and the whole register at least annually or when something material changes: a new system, a new regulation, an incident. A register reviewed only when the auditor arrives describes the organisation as it was at the last audit.

Sources

The primary text this definition rests on. Read it before you trust ours.

Last reviewed 13 September 2026 · Getting Digital