In today’s digital-first world, cybersecurity isn’t just an IT concern—it’s a core business issue. The financial, operational, and reputational risks associated with cyber threats are real and growing. But how do you assess and manage these risks effectively?
Different frameworks, such as those from ISACA, NIST, and others, use slightly different equations to assess cyber risk. But the core concept remains the same: risk is driven by a combination of likelihood, impact, and controls. The specific equations may differ, but they all account for these same key variables.
For the purposes of this article, we won’t get too bogged down in which equation is “correct”—instead, we’ll focus on understanding the key variables that drive risk assessment, so the next time you meet with your CISO, you’ll understand exactly why you’re paying $$$ for an Endpoint Detection and Response (EDR) solution. 😂
Risk Equation Examples: Different Frameworks, Same Core Variables
Here are some variations of risk equations from prominent frameworks:
- ISACA: ISACA presents a risk equation where Risk = Likelihood × Impact, focusing on the probability of a threat and the potential damage it could cause.
This formula emphasizes the need to consider both the likelihood of a threat exploiting a vulnerability and the resulting impact on the organization.
- NIST: The NIST Cybersecurity Framework also follows a similar concept but with a slight variation: Risk = Threat × Vulnerability × Impact × Likelihood – Controls This equation adds more detail by incorporating threats and vulnerabilities into the formula, giving a fuller picture of the risk landscape. It also highlights the role of controls in mitigating risk.
- Factor Analysis of Information Risk (FAIR): FAIR, a risk framework developed for the IT and cybersecurity industries, uses a more quantitative approach: Risk = (Asset Value × Threat Event Frequency × Vulnerability) × (Impact) FAIR focuses on assessing risk in monetary terms, making it easier for organizations to understand the financial implications of cybersecurity events.
- ISO 27001: The ISO/IEC 27001:2013 standard, which provides guidelines for information security management, uses a risk assessment equation that combines threats, vulnerabilities, and impacts, but also includes a factor for controls, similar to NIST’s framework.
While the specific risk equation might vary across frameworks, all of these models consider the same key variables that influence cybersecurity risk: threats, vulnerabilities, impact, likelihood, and controls.
Understanding the Key Variables
So, what do these variables mean for your organization? Let’s break them down:
1. Threat
A threat refers to any potential cause of harm. It could be a cybercriminal, a disgruntled employee, or even an external disaster like a natural event. Understanding the nature of the threat helps you assess how likely it is to impact your organization.
Example: A hacker exploiting an unpatched software vulnerability is a threat to your organization’s data.
2. Vulnerability
A vulnerability is a weakness in your systems, processes, or people that could be exploited by a threat. These could be outdated software, weak passwords, or inadequate employee training. Identifying and addressing vulnerabilities is crucial to reducing risk.
Example: An unpatched operating system on an employee’s workstation creates a vulnerability that a cybercriminal could exploit.
3. Impact
Impact is the potential damage to your organization if a cyber event occurs. This can include financial losses, operational disruption, reputational harm, or regulatory penalties. The higher the potential impact, the more critical it is to address vulnerabilities and threats.
Example: A data breach exposing customer information could result in regulatory fines, legal costs, and severe damage to your brand’s reputation.
4. Likelihood
Likelihood refers to the probability that a specific threat will exploit a vulnerability. This is often informed by historical data, threat intelligence, and the industry landscape. Assessing likelihood allows you to understand how probable an attack is.
Example: If your industry is frequently targeted by phishing attacks, the likelihood of such an attack succeeding increases.
5. Controls
Now here’s the part that helps reduce your risk: controls. These are the safeguards or countermeasures implemented to minimize the likelihood and impact of cyber incidents. Controls are where the money goes. These are the investments you’re approving, and understanding them is crucial to justifying those expenditures.
Types of Controls
- Preventive Controls: Designed to stop incidents before they happen by addressing vulnerabilities and preventing exploitation.
Examples: Firewalls, encryption, multi-factor authentication (MFA), employee security awareness training.
- Detective Controls: Help identify and alert you to incidents as they occur. While they don’t prevent incidents, they help you respond quickly to minimize damage.
Examples: Endpoint Detection and Response (EDR) systems, Security Information and Event Management (SIEM) tools, network traffic analysis, real-time monitoring.
- Corrective Controls: Steps taken after an incident to minimize its impact and restore systems to normal.
Examples: Incident response plans, data backup and recovery, system patching, and restoration procedures.
- Compensating Controls: When primary controls cannot be implemented, compensating controls act as alternatives to reduce risk to an acceptable level.
Examples: Manual oversight when automated systems can’t be deployed, additional user verification processes, or increased monitoring in place of network segmentation.
Why This Matters for the Board
When your CISO presents the case for a new security investment—like an EDR solution—it’s important to understand that these are critical detective controls designed to detect malicious activity on endpoints in real time. The likelihood of a breach is increasing as attacks become more sophisticated, and without the right controls, the impact of an attack could be devastating. Investing in tools like EDR systems helps reduce both the likelihood and the impact, ultimately reducing overall risk.
As a board member, understanding these key variables allows you to make more informed decisions when it comes to approving budgets for cybersecurity initiatives. These are not just costs—they are investments in protecting the future of your organization.

