Identifying Risk in Daily Operations
Risk is not a vague concept; it is a calculable value:
Risk = Likelihood × Impact
-
Likelihood:
The probability that a specific threat will exploit a vulnerability.
(e.g., The likelihood of a phishing email is High). -
Impact:
The magnitude of harm that could result.
(e.g., The impact of a ransomware infection is Critical). -
Risk Acceptance vs. Mitigation:
Companies cannot eliminate all risk. They must decide which risks to accept
(low impact / low likelihood) and which to mitigate
(high impact / high likelihood) through controls such as
Multi-Factor Authentication (MFA) or encryption.