Risk

18th December 2019 | Cybrary Risk

Intersection of Threats, Assets, and Vulnerabilities is your Risk

Intersection of Threats, Assets, and Vulnerabilities is your Risk

Risk is the potential for an unwanted or adverse outcome resulting from an incident, event, or occurrence, as determined by the likelihood that a particular threat will exploit a particular vulnerability, with the associated consequences.

Risk is the combination of threats and vulnerabilities to an asset. Risk is calculated in business by looking at three different categories. 

  • ARO– Annual Rate of Occurrence (Chance that incident will happen)
  • SLE– Single Loss Expectancy (Dollar amount expected to lose if incident is to occur)
  • ALE– Annual Loss Expectancy (How much should be budgeted for incident)

The Annual Loss Expectancy is calculated by using this formula: ARO x SLE = ALE

  • Example: 50% chance that a ransomware attack occurs that would cost the company $1,000,000 if attack were to occur. 
  • ARO x SLE = ALE -> (0.5) x (1,000,000) = $500,000 -> $500,000 is the Annual Loss Expectancy

Source: DHS Risk Lexicon, NIPP and adapted from: CNSSI 4009, FIPS 200, NIST SP 800-53 Rev 4, SAFE-BioPharma Certificate Policy 2.5

Related Terms: Threat, Vulnerability

To learn more about cyber risk, watch this short video:

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

MongoBleed: Why 87,000 Databases Had Their Front Doors Wide Open (And How to Close Yours)

MongoBleed: Why 87,000 Databases Had Their Front Doors Wide Open (And How to Close Yours)

Remember Heartbleed? That security nightmare from a few years back that made everyone panic about their...

Read more
QR Codes Are Back (They Still Want Your Password)

QR Codes Are Back (They Still Want Your Password)

Remember 2020? We scanned QR codes for everything. Restaurant menus. Parking meters. That awkward moment at a...

Read more
AI-Powered Phishing Kits Are Game-Changing, In a Very Bad Way

AI-Powered Phishing Kits Are Game-Changing, In a Very Bad Way

Phishing emails used to be easy to spot. Bad grammar. Weird links. Obvious scams. Those days are...

Read more