Activity 2 · CySA+ v4
Qualitative risk analysis
Use evidence and agreed criteria to describe a risk, explain its priority, and assess what remains after a proposed security control.
Understand the model
Qualitative risk analysis uses descriptive categories such as Low, Moderate, and High. Analysts consider the threat, weaknesses, existing controls, and business consequences, then apply a consistent set of rating criteria.
Likelihood
How likely is the defined scenario to happen and cause harm within the assessment period? Consider relevant incidents, threat activity, exploitable weaknesses, and how well existing controls work.
Impact
How serious would the consequences be if the scenario occurred? Consider effects on services, information, people, reputation, and obligations.
Risk rating
The category found where the likelihood row and impact column meet in the agreed matrix. It helps prioritise discussion and action; it does not calculate a monetary loss or an exact probability.
Residual risk
The risk remaining after controls. Assess both likelihood and impact again, using evidence of what the controls actually change. A proposed control gives an estimated future residual risk until its effectiveness is verified.
Agree the criteria first
For this activity, assess one scenario over the next 12 months. Use these simplified criteria and the CyberCorps teaching matrix below. Organisations define scales and matrix rules to fit their own context and risk tolerance.
| Rating | Likelihood | Impact |
|---|---|---|
| Low | Plausible but not expected over the next 12 months. | Limited local disruption or minor information harm, manageable through routine response. |
| Moderate | Credible and could occur over the next 12 months. | Meaningful disruption or information harm requiring specialist response. |
| High | Expected over the next 12 months, based on available evidence. | Major disruption or serious information harm. |
Make your judgement traceable
Record the scenario, assessment period, evidence, assumptions, confidence, risk owner, and review date. When assessors disagree, compare their reasoning against the criteria. A High rating is an ordered category; it is not a claim that the risk is twice as large as Moderate.
A compromised staff account
A customer support team uses an application containing sensitive customer records. Staff accounts currently use passwords alone. The scenario is: an attacker compromises a staff account and accesses customer records during the next 12 months.
Rate the current likelihood: High
In this example, recent investigations have found stolen staff credentials and repeated targeted phishing, while control checks confirm password-only access. The assessors judge the harmful scenario to be expected under the current conditions.
Rate the impact: High
A compromised account can access a large set of sensitive customer records. Disclosure could seriously harm customers and the organisation. This meets the activity’s High impact criteria.
Find the baseline risk: High
Follow the High likelihood row to the High impact column in the teaching matrix. Their intersection gives a High risk rating.
Assess the proposed control: Moderate projected residual risk
The team proposes phishing-resistant multi-factor authentication and removal of legacy authentication paths. For this exercise, assume verified coverage and effective enforcement would support a Low likelihood rating. The impact stays High because an account compromise could still expose the same records. Low likelihood with High impact gives Moderate projected residual risk in this matrix.
Decide what happens next
The lower rating depends on the stated assumptions. Check enrolment, bypass and recovery paths, and evidence that the control works before adopting it as the current rating. The risk owner then decides whether the remaining risk is acceptable under the organisation’s criteria, or whether further treatment is needed. Set an owner and review date for the agreed actions.