All CySA+ v4 activities

Activity 2 · 15–20 minutes

In this activity

Activity 2 · CySA+ v4

Qualitative risk analysis

Use evidence and agreed criteria to describe a risk, explain its priority, and assess what remains after a proposed security control.

01 · Understand

Understand the model

Qualitative risk analysis uses descriptive categories such as Low, Moderate, and High. Analysts consider the threat, weaknesses, existing controls, and business consequences, then apply a consistent set of rating criteria.

Likelihood

How likely is the defined scenario to happen and cause harm within the assessment period? Consider relevant incidents, threat activity, exploitable weaknesses, and how well existing controls work.

Impact

How serious would the consequences be if the scenario occurred? Consider effects on services, information, people, reputation, and obligations.

Risk rating

The category found where the likelihood row and impact column meet in the agreed matrix. It helps prioritise discussion and action; it does not calculate a monetary loss or an exact probability.

Residual risk

The risk remaining after controls. Assess both likelihood and impact again, using evidence of what the controls actually change. A proposed control gives an estimated future residual risk until its effectiveness is verified.

Agree the criteria first

For this activity, assess one scenario over the next 12 months. Use these simplified criteria and the CyberCorps teaching matrix below. Organisations define scales and matrix rules to fit their own context and risk tolerance.

Teaching criteria for likelihood over the next 12 months and impact if the scenario occurs.
RatingLikelihoodImpact
LowPlausible but not expected over the next 12 months.Limited local disruption or minor information harm, manageable through routine response.
ModerateCredible and could occur over the next 12 months.Meaningful disruption or information harm requiring specialist response.
HighExpected over the next 12 months, based on available evidence.Major disruption or serious information harm.

Make your judgement traceable

Record the scenario, assessment period, evidence, assumptions, confidence, risk owner, and review date. When assessors disagree, compare their reasoning against the criteria. A High rating is an ordered category; it is not a claim that the risk is twice as large as Moderate.

02 · Follow the example

A compromised staff account

A customer support team uses an application containing sensitive customer records. Staff accounts currently use passwords alone. The scenario is: an attacker compromises a staff account and accesses customer records during the next 12 months.

  1. Rate the current likelihood: High

    In this example, recent investigations have found stolen staff credentials and repeated targeted phishing, while control checks confirm password-only access. The assessors judge the harmful scenario to be expected under the current conditions.

  2. Rate the impact: High

    A compromised account can access a large set of sensitive customer records. Disclosure could seriously harm customers and the organisation. This meets the activity’s High impact criteria.

  3. Find the baseline risk: High

    Follow the High likelihood row to the High impact column in the teaching matrix. Their intersection gives a High risk rating.

  4. Assess the proposed control: Moderate projected residual risk

    The team proposes phishing-resistant multi-factor authentication and removal of legacy authentication paths. For this exercise, assume verified coverage and effective enforcement would support a Low likelihood rating. The impact stays High because an account compromise could still expose the same records. Low likelihood with High impact gives Moderate projected residual risk in this matrix.

Decide what happens next

The lower rating depends on the stated assumptions. Check enrolment, bypass and recovery paths, and evidence that the control works before adopting it as the current rating. The risk owner then decides whether the remaining risk is acceptable under the organisation’s criteria, or whether further treatment is needed. Set an owner and review date for the agreed actions.

Qualitative risk matrix

Compare likelihood and impact before and after a proposed control. Use the same scenario and the next 12 months as the assessment period.

This CyberCorps teaching matrix is a custom example, not an official NIST matrix. Low, Moderate, and High order priorities; they do not measure monetary loss or assign a numerical probability.

Before the proposed control

Expected over the next 12 months, based on available evidence.

Major disruption or serious information harm.

After the proposed control

Plausible but not expected over the next 12 months.

Major disruption or serious information harm.

Baseline risk · Before
High
High likelihood with high impact.
Projected residual risk · After
Moderate
Low likelihood with high impact.

Locate both assessments

Rows show likelihood; columns show impact. The Before and After labels mark your selections. Both labels appear together when the selections share a cell.

CyberCorps teaching matrix · illustrative qualitative categories
Likelihood ↓ / Impact →Low impactModerate impactHigh impact
Low likelihood

Low risk

Low risk

Moderate risk

After
Moderate likelihood

Low risk

Moderate risk

High risk

High likelihood

Moderate risk

High risk

High risk

Before

Lower residual risk category

The proposed control lowers the risk category in this teaching example. Confirm the supporting evidence and have the risk owner assess whether the residual risk is acceptable.

After-control ratings are projections. Verify that the control is implemented and effective before adopting a projected rating as the current risk assessment.

A category does not automatically authorise acceptance. Record the evidence, uncertainty, risk owner, and agreed review or treatment decision.

Before: High likelihood and High impact gives High risk. After: Low likelihood and High impact gives Moderate risk. The residual risk category is lower.

03 · Experiment

Try it yourself

Use the matrix to explore these questions. Select Reset worked example before each one, then open the answer to check your reasoning.

1. What if the control only reduces likelihood to Moderate?

Set after-control likelihood to Moderate and keep impact High. Residual risk remains High in this matrix. A control may improve the underlying situation without moving it into a different risk category.

2. What if access restrictions also reduce the impact?

Keep after-control likelihood Low and change impact to Moderate. The matrix gives Low residual risk. This would require evidence that limiting access meaningfully reduces the consequences. The label alone does not authorise acceptance.

3. Does High to Moderate tell you the percentage reduction?

No. These are qualitative categories with no fixed numerical distance between them. Record the change in likelihood, impact, and evidence. Use a suitable quantitative model if you need a monetary loss estimate or financial comparison.

Further reading

Connect this activity to your learning