Skip to main content
Module 2~8 min

Assessing Risk

Security teams can't eliminate every possible danger, so they focus on understanding and managing risk instead.

What You'll Learn

  • What risk means in a security context
  • How likelihood and impact relate to risk
  • Why organizations prioritize risks

What Risk Means

Risk describes the potential for loss or harm when a threat exploits a vulnerability. It's typically thought of as a combination of how likely something is to happen and how much damage it would cause.

Prioritizing Risk

Because no organization has unlimited resources, security teams prioritize the risks that are both likely and damaging, addressing those first.

Example

A rare but catastrophic risk and a common but minor risk might both get attention, but a common and catastrophic risk would typically be addressed first.

Key Concepts

RiskLikelihoodImpact

Key Takeaways

  • Risk combines the likelihood of an event with its potential impact
  • Organizations prioritize risks rather than trying to eliminate everything
  • The most likely and damaging risks are usually addressed first

Knowledge Check

Risk is typically thought of as a combination of what two factors?

Risk is typically thought of as a combination of what two factors?