← Core Concepts

Core Concepts

Risk

Considering what could go wrong, how likely it is and the impact it could have.

Governance

The idea

Cybersecurity risk concerns potential harm arising from threats and vulnerabilities. Likelihood and impact help inform priorities; a risk score is an aid to judgement, not a precise prediction.

  • An asset is something valuable that needs protecting.
  • A threat has the potential to cause harm.
  • A vulnerability is a weakness that could be exploited.
  • A control helps modify the risk.

A fictional example

An unpatched internet-facing service may expose an organisation to compromise. The priority depends on the weakness, exposure, available exploitation and the consequences for the service and its users.

Responding to risk

Options include reducing, avoiding, sharing or accepting risk. Decisions should have an accountable owner. Remaining risk needs to be understood and reviewed when circumstances change.

Further reading

NIST glossary: risk.