Understanding cybersecurity risk starts with understanding how risk is modeled.
In this Back to Basics, we’ll explore the fundamental building blocks of risk modeling, clarifying the role of threats, vulnerabilities, predisposing conditions, threat scenarios, likelihood, and impact. Mastering these concepts is essential for performing accurate and consistent risk assessments.
Threat
Everything starts with a threat.
A threat is any event or circumstance that has the potential to cause harm to an organization. This harm may result from unauthorized access, disclosure, modification, destruction of information, or disruption of services.
A threat does not exist on its own—it originates from a threat source. A threat source may be intentional, such as a cybercriminal or nation-state actor, or unintentional, such as human error, equipment failure, or natural disasters.
Vulnerability
A threat alone does not create risk.
For a threat to have an impact, it must exploit a vulnerability—a weakness in technology, processes, people, or governance.
Vulnerabilities are often associated with missing or ineffective security controls, but they can also emerge over time as technologies evolve, business processes change, or new threats appear. This is why cybersecurity risk assessment is a continuous activity rather than a one-time exercise.
Predisposing Conditions
Not every factor that influences risk is a vulnerability.
A predisposing condition is any characteristic of the organization or its environment that increases or decreases the likelihood that a threat event will succeed.
For example, hosting a data center in a flood-prone region increases exposure to natural hazards, while operating an isolated system with no Internet connectivity significantly reduces exposure to external cyber attacks.
Predisposing conditions provide context to the risk assessment and explain why identical vulnerabilities may present very different levels of risk across organizations.
Threat Scenarios
Real-world risks rarely result from a single event.
A threat scenario describes the sequence of events through which one or more threat sources exploit vulnerabilities to produce an adverse outcome.
Rather than evaluating isolated weaknesses, threat scenarios help analysts understand how multiple events can combine to create significant business impact. They also make risk assessments easier to communicate because they tell a coherent story.
Likelihood
Likelihood estimates how probable it is that a threat scenario will occur.
For intentional attacks, likelihood is typically influenced by three factors:
Intent – Does the attacker want to target the organization?
Targeting – Is the organization actually a likely target?
Capability – Does the attacker possess the skills and resources required?
For non-malicious events, such as equipment failures or natural disasters, likelihood is generally estimated using historical data, statistics, and environmental factors.
Risk models also distinguish between the likelihood that a threat event will occur and the likelihood that it will actually produce adverse consequences.
Impact
Impact measures the potential consequences if a threat scenario succeeds.
The consequences may include financial loss, operational disruption, legal or regulatory penalties, reputational damage, or harm to individuals.
Organizations typically evaluate impact using business impact analyses, security classifications, privacy assessments, and predefined impact criteria aligned with their risk appetite.
Bringing Everything Together
These concepts are closely connected.
A threat source initiates a threat, which exploits one or more vulnerabilities. Predisposing conditions influence the probability of success, while threat scenarios describe how events unfold over time. The resulting likelihood and impact ultimately determine the level of cybersecurity risk.
Understanding these building blocks is the foundation of every effective risk assessment, regardless of the framework or methodology being used.
This article is based on the CSFaaS risk model, which is primarily aligned with NIST SP 800-30 Rev.1, ISO/IEC 27005, and ISO 31000, while incorporating practical concepts and taxonomies from ENISA and VERIS.
Sources & further reading
- NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments
- NIST SP 800-39 – Managing Information Security Risk: Organization, Mission, and Information System View
- ISO/IEC 27005:2022 – Information security, cybersecurity and privacy protection — Guidance on managing information security risks
- ISO 31000:2018 Risk management — Guidelines
- VERIS - The Vocabulary for Event Recording and Incident Sharing
