Current risk is the level of risk that remains once existing controls and mitigation measures are taken into account: the residual risk in today's operating environment, reflecting the effectiveness and maturity of the controls already in place. It is assessed in the Current Risk tab of the risk.
1. Current Risk Statement
A concise summary of the risk scenario in its present state, considering the defences already in place, and a foundation for evaluating further mitigation.
Example: "While multi-factor authentication (MFA) has been implemented on most critical systems, some legacy systems remain unprotected, posing an ongoing risk of unauthorised access."
2. Current Risk Strength
The controls and practices currently working in your favour: what today's environment already does well against this risk.
Example: "MFA and centralised logging are enforced on all internet-facing systems."
3. Current Risk Weakness
The deficiencies or gaps in existing controls, processes or practices that keep the risk from being fully mitigated, pinpointing where improvement is required.
Example: "Insufficient monitoring and alerting mechanisms reduce the ability to detect unauthorised access attempts in real time."
4. Current Risk Opportunity
The potential benefits of improving or optimising the existing controls: value, resilience or better strategic alignment.
Example: "Enhancing real-time monitoring and implementing advanced analytics could improve threat detection and reduce incident response times."
5. Summary
| Field | Focus | Purpose |
|---|---|---|
| Current Risk Statement | The risk with existing controls applied | Understand the residual risk |
| Current Risk Strength | Controls already working | Recognise effective defences |
| Current Risk Weakness | Gaps in existing controls | Identify limitations to fix |
| Current Risk Opportunity | Gains from improving controls | Enhance resilience and value |
6. Impact Type
Select the relevant Impact Type(s) from your predefined catalogue: financial loss, operational disruption, legal implications, reputational damage, data breach and any other dimension your workspace defines. Categorising the impact clarifies the potential consequences, helps prioritise responses, and aligns the assessment with your organisation's strategic objectives and risk appetite.
7. Risk matrix
After defining the Impact Type, determine the Current Risk level using the risk matrix.
1. Likelihood Level
Begin by defining the likelihood of the risk materialising.
Note: Likelihood = Threat x Vulnerability. Select the threat level and the vulnerability level; the matrix derives the likelihood score.
2. Risk Exposure
Note: Risk = Likelihood x Impact. Select the impact; the risk level is placed automatically on the matrix.
The likelihood and risk exposure model is taken from NIST 800-161r1, section D.4.1.7 "Risk Response Analysis", page 227, extended from 4 to 5 levels. Your workspace's matrix dimensions are configurable in Settings, Risk Matrix.