Memra

Likelihood, consequence, the risk matrix, and the five treatments

◈ 7 cards

Five likelihood levels against six consequence levels, the calibration rule that makes a rating defensible, why the same event rates differently at two organisations, and the five treatments — only two of which require costing a control.

Two scales, and they are not the same length

A risk is rated on two independent scales and the level is read off the intersection. Likelihood has five levels: rare, unlikely, possible, likely, almost certain. Consequence has six: insignificant, minor, moderate, major, catastrophic, doomsday. The asymmetry is deliberate and it is a favourite trip-up — five and six, not five and five. The sixth consequence level exists because there is a class of outcome that ends the organisation, and it needs a name of its own so that nobody averages it away.

Consequence levels are graded by three things together: the duration of disruption, the level of management intervention the event demands, and the extent of public or customer awareness. Those three are what turn an adjective into something two people can agree on.

The calibration rule

Here is the single most useful sentence in the chapter: a rating of Likely or higher implies the threat has occurred before. History is the evidence. If you rate a threat Likely and cannot point to a previous occurrence — here, or at a comparable organisation, or in a credible published incident set — you owe an explicit justification, and the only justification that works is a changed threat environment: a new vulnerability class, a newly published exploit, a change in who is targeting organisations like yours.

This rule is what makes a rating defensible rather than a mood. In an exam answer it converts a number into an argument, which is where the marks are. Say Possible, because malware has reached this network before but has never successfully executed on an endpoint and you have earned the rating. Say Likely, because malware is everywhere and you have not.

Consequence is measured at the organisation, not at the system

The same physical event rates differently at two organisations, and it must. A server destroyed by fire is Minor if its data is replicated to two other sites and a replacement is a purchase order away. The same server, destroyed by the same fire, is Catastrophic if it held the only copy of the customer database.

So consequence is not a property of the event. It is a property of what the event does to the organisation, which is exactly why the asset owners and management set it and the analyst does not. When you justify a consequence rating, justify it at the level of the organisation: what stops, for how long, who notices, and who has to be told.

Reading the matrix

Cross the two scales and every cell carries a level — Extreme, High, Medium or Low — and each level carries a defined management response. Extreme demands executive-level planning and a named owner. High needs management attention and a funded plan. Medium is handled by a specified responsible officer. Low is absorbed by routine procedures. The whole Doomsday column is Extreme regardless of likelihood, which is the matrix saying out loud that you do not get to discount an organisation-ending outcome because it is unlikely.

The matrix below is the one this course uses. Every organisation calibrates its own, and that is the point: the matrix is a policy decision made once, in advance, by management — and every subsequent rating follows from it mechanically. If you find yourself arguing about a risk level, you are usually really arguing about the matrix.

The five treatments

Once a risk is evaluated as unacceptable, there are exactly five things you can do about it.

  • Acceptance — knowingly carry the risk for business reasons. Legitimate, but it must be decided rather than defaulted into, and management owns the consequences.
  • Avoidance — do not undertake the activity at all. Do not accept card payments; do not offer the remote service.
  • Transfer — share responsibility with someone else through insurance, a contract or a partnership. Note that transfer moves financial consequence, and almost never moves reputational consequence or legal duty.
  • Reduce consequence — off-site backup, disaster recovery, replication, compartmentation. The event still happens; it hurts less.
  • Reduce likelihood — patching, firewalls, tokens, password policy, awareness training. The event happens less often; if it happens it hurts the same.

Only the last two require selecting and cost-justifying a specific control. Acceptance, avoidance and transfer are decisions; reduction is an engineering programme with a budget. That distinction is worth a mark on its own.

The trap: level is not priority

Risks are sorted in the register in decreasing order of level — and then management legitimately reorders them. A High risk with a two-hundred-pound fix is treated before a High risk that needs an eighteen-month disaster-recovery programme. A remote possibility of a fatality outranks an Extreme data risk, because no regulator will accept an organisation that ranked a potential death lower. Priority is a management judgement layered on top of the level, and saying so explicitly is where the marks are — an answer that treats the matrix output as the work plan has missed the step.

Worked example — rating the worm at Coldstream

The risk: an imported e-mail worm corrupts the integrity of Coldstream's student and payroll records.

Likelihood. Coldstream's mail gateway quarantines malicious attachments daily, so malware certainly reaches the institution. But no worm has executed on a records-service host: the servers are patched on a fortnightly cycle, records staff work from managed desktops, and macro execution is disabled by policy. The threat has arrived but has never landed. That is Possible — not Likely, because the calibration rule asks for a previous occurrence and there is not one; not Unlikely, because the vector is live and demonstrated every week.

Consequence. Ask what happens to Coldstream, not to a server. Corrupted transcripts stop degree conferrals and student funding confirmations. Corrupted payroll stops staff being paid. Both are visible to students, staff and the press within a day, and both demand executive intervention. Restoration is possible from nightly backups, so this is not organisation-ending — but it is weeks of reconciliation across two departments. Major.

Level. Possible × Major on the matrix below = Extreme.

Treatment. Two levers, chosen deliberately. Reduce likelihood by hardening the vector: attachment sandboxing at the gateway, macro policy enforcement, fortnightly patching held to. Reduce consequence by making restoration fast and certain: nightly backups held offline, quarterly tested restores, and records segregated from payroll so one corruption does not reach both. Note that we did not choose transfer: cyber insurance would pay for the reconciliation effort, but it will not confer a degree on time.

LikelihoodWhat the rating assertsEvidence it impliesRareonly in exceptionalcircumstancesno known occurrenceanywhere comparableUnlikelycould happen, but notexpectedoccurrences reported, noneherePossiblemight happen at some timethe vector is live here; ithas not landedLikelywill probably happen atsome timeit has happened here beforeAlmost certainexpected in mostcircumstancesit happens here routinelyLikely or higher implies prior occurrence — otherwise justify by a changed threatenvironment.
The right-hand column is the calibration rule in force. Likely and above are claims about history; if you cannot point to a previous occurrence you must justify the rating by a changed threat environment.
ConsequenceDisruptionInterventionneededWho noticesInsignificantnone worthmeasuringnonenobody outside theteamMinorhoursthe responsibleofficerthe affected usersModeratea day or twoa department headthe wholeorganisationMajorweeksexecutive attentioncustomers, pressCatastrophicmonthsthe wholeexecutive, fulltimeregulators,national pressDoomsdaythe organisationdoes not continueirrelevanteveryoneRated at the organisation, never at the system — the same fire is Minor or Catastrophic depending onwhat else holds the data.
Six levels against likelihood’s five — the asymmetry is examinable. Doomsday exists so that an organisation-ending outcome cannot be averaged away into Catastrophic.
InsigMinorModerMajorCatasDoomRareLLMMHEUnlikelyLLMHHEPossibleLLHEEELikelyMMHEEEAlmostcertainMHEEEEE extreme, H high, M medium, L low. The whole Doomsday column is Extreme at every likelihood.
The matrix IS the policy. Management calibrates it once, in advance; every later rating follows from it mechanically. Possible × Major = Extreme is the cell L13.3 lands on.
NORMAL ~/memra/learn/comp-400/likelihood-consequence-the-risk-matrix-and-the-five-treatments utf-8 LF