A **risk** is anything that can impact the confidentiality, integrity, or availability of an asset. A basic formula for determining the level of risk is that risk equals the likelihood of a threat.
There are different factors that can affect the likelihood of a risk to an organisation’s assets, including:
- **External risk**: Anything outside the organisation that has the potential to harm organisational assets, such as threat actors attempting to gain access to private information
- **Internal risk**: A current or former employee, vendor, or trusted partner who poses a security risk
- **Legacy systems**: Old systems that might not be accounted for or updated, but can still impact assets, such as workstations or old mainframe systems. For example, an organisation might have an old vending machine that takes credit card payments or a workstation that is still connected to the legacy accounting system.
- **Multiparty risk**: Outsourcing work to third-party vendors can give them access to intellectual property, such as trade secrets, software designs, and inventions.
- **Software compliance/licensing**: Software that is not updated or in compliance, or patches that are not installed in a timely manner
- **Intellectual property**: (IP) theft risks occur when a company possesses trade secrets or other proprietary information that, if disclosed, could compromise the organisation's business advantage.
One way to interpret risk is to consider the potential effects that negative events can have on a business. Another way to present this idea is with this calculation:
$Likelihood \times Impact = Risk$
Risk assessments may be performed in several ways:
- **One-time** risk assessments offer the organisation a point-in-time view of its current risk state. They may be done *in response to a security incident, at the request of management*, or at any other time when the organisation wants a snapshot of its risk profile.
- **Ad hoc** risk assessments are conducted *in response to a specific event or situation, such as a new project, technology implementation, or significant change in the business environment*. These assessments are often performed quickly to address a particular concern or set of circumstances.
- **Recurring** risk assessments are performed at regular intervals, such as *annually or quarterly*. These assessments are meant to track the evolution of risks over time, monitor changes in the risk profile, and ensure that risk management practices are adapting to new threats and vulnerabilities.
- **Continuous** risk assessments involve *ongoing monitoring and analysis of risks*. This can include automated systems that constantly scan for new threats or changes in the risk environment, as well as regular reviews and updates to the risk management strategy. Continuous risk assessment enables organisations to respond more quickly and effectively to emerging risks.
In general, we calculate risk in this field to help:
- Prevent costly and disruptive events
- Identify improvements that can be made to systems and processes
- Determine which risks can be tolerated
- Prioritise the critical assets that require attention