Impact and likelihood
Evaluating impact
Impact is “if this is real, how bad is it?” Four impact dimensions cover the typical impact picture. Each can be assessed independently; the combined view is what feeds the priority decision.
📁 Data sensitivity
Value and sensitivity of data involved (personal, financial, health). Exposure can lead to identity theft, fraud, legal consequences. Different categories (public → restricted) carry different risk weights when compromised. PII, PHI, payment card data, IP, and authentication credentials sit at the top tier.
Volume also matters. A breach of thousands of customer records is a different scale from a single record, even at the same classification.
⚙️ Operational disruption
How the event affects the organization’s ability to function. Direct availability issues, productivity losses, customer-facing service disruption. The criticality of affected systems to core business functions drives this.
Recovery time objectives (RTO) and recovery point objectives (RPO) anchor the operational evaluation. Threatening to exceed these thresholds raises priority materially.
📋 Regulatory & compliance
Industry and geography-specific legal obligations. GDPR, HIPAA, and PCI DSS each set notification timelines and define what constitutes a reportable incident; SOX and the SEC disclosure rule add financial-reporting and materiality obligations instead of breach-notification clocks. Events triggering reporting requirements typically represent elevated risk.
Different regulatory regimes have different thresholds for materiality and different notification clocks. Scope identified which apply; Risk decides whether the technical evidence meets the threshold.
🪞 Reputational
How the event affects stakeholder perceptions if it became public. Customer trust, partner relationships, investor confidence, market positioning. Reputational damage often outlasts direct operational impact and is harder to quantify and remediate.
Factors include visibility of affected systems, data sensitivity, the organization’s existing public profile, and whether the incident suggests negligence vs. sophisticated targeting.
Reading the impact picture
A useful sequencing: data sensitivity sets the floor. Operational disruption and reputational damage usually move together. Regulatory exposure is the multiplier, it can promote a medium-impact event to high based on notification triggers alone.
Evaluating likelihood
Likelihood is one question: how confident are we that this finding is real and malicious? Score it from evidence quality first: what the evidence supports is the ceiling, and the four factors below calibrate within it, never above it. Sophistication and historical frequency speak to whether the activity plausibly is an attack; exploitability and control coverage speak to whether the claimed attack could actually have succeeded here. No factor substitutes for evidence: an APT-plausible story with nothing validated is still Low. The separate question of whether a confirmed attack will continue or spread belongs to the exploitation & scope dimension of the RATM scoring model (covered on the framework page), not this axis.
One scoring rule prevents the quietest failure: unknown is not Low. Low means the evidence was examined and leans benign. When the evidence cannot be examined, because telemetry is missing, a source is unqueried, or a join failed, the likelihood floor is Medium and the gap goes in the open questions. The framework page’s reduction and override rules depend on this distinction: “checked and clean” and “could not check” must never land in the same matrix cell.
🎭 Threat actor sophistication
Skill level and resources behind the activity. An attack linked to an APT group is more targeted and harder to mitigate than an opportunistic attempt by a commodity actor. Custom tooling, multi-stage operations, and infrastructure investment raise the sophistication score.
🔓 Exploitability
Whether the attack targets known, easily exploitable vulnerabilities or requires advanced techniques. Public exploits, low complexity, and broad applicability raise likelihood of success. Compensating controls and patch status temper it.
📜 Historical incident frequency
Has the organization experienced similar incidents? Recurrence often signals persistent vulnerabilities or weaknesses. Frequency of past incidents is one of the strongest signals of future ones in the same category.
🛡️ Security control coverage
Effectiveness of firewalls, IDS, endpoint protection, identity controls. Gaps increase the chance of successful compromise; layered, well-maintained controls reduce it. The current state of compensating controls modifies the raw exploitability score.
Likelihood indicators at a glance
Evidence quality is the first row because it is the ceiling; the four calibration rows move the score within it, never above it. That is the framework page’s reduction rule, read as a table.
Common likelihood mistake
Letting impact drive likelihood. “This would be really bad, therefore it is probably real.” That is backwards. Evaluate likelihood from the evidence, impact from the potential consequences, and then combine them deliberately. Each dimension answers a different question.
Producing the verdict
The Risk output combines the two dimensions into a defensible priority. The verdict should include:
📊 Impact score
High / medium / low across the four impact dimensions, with a one-sentence rationale per dimension. The combined impact is the floor of the priority decision.
🎯 Likelihood score
High / medium / low, anchored on evidence quality and calibrated by sophistication, exploitability, and control coverage. Record the evidence-confidence level as its own named line, so a reviewer can tell “weak evidence” apart from “strong evidence of unlikely-malicious activity.”
🚦 Combined priority
From the triage matrix. Drives escalation timing and resource allocation. Not a number; a defended judgment with named inputs.
❓ Open questions
What the analyst could not resolve, and what new evidence would change the verdict. This is what makes the verdict defensible later.
Open questions are not weakness
Recording open questions is the difference between “the analyst was confident” and “the analyst knew what they did not know.” The latter is what survives audit, Post-Mortem The structured retrospective an organization runs after a closed incident: timeline, decisions, what worked, what failed, what the team learned. A good post-mortem points back at detection, process, or training gaps. A blameless one names the system, not the person. , and review. The former is what creates incident-response gaps months later when the open question turns out to have mattered.
Key Takeaway
Impact and likelihood are independent. Combine them deliberately. Record the rationale for each. The verdict is not a number; it is a defended judgment with named inputs the next analyst, the audit team, and the post-mortem can verify.