TechKnowSurge
ISC2 CISSP 1.9 CompTIA Security+ 5.2 NIST CSF ID.RA-05 NIST 800-53 RA-3
VideoSecurityFree

Risk Analysis

Risk analysis determines the severity of identified threats by measuring their likelihood and potential impact, helping organizations prioritize which risks demand the most immediate attention. The two primary approaches are quantitative analysis, which assigns numerical values and dollar amounts to risks, and qualitative analysis, which uses descriptive ratings such as low, medium, or high.

Complete this video to capture a CTF flag worth 1 point.

About this video

After risks to an organization have been identified, the next step is determining how severe each one actually is. Risk analysis provides that measurement by evaluating two core factors for every identified risk: the likelihood that the risk will materialize and the impact it would have if it did. Scoring risks against those two dimensions produces a ranking that helps organizations focus their limited time and resources on the threats that matter most. There are two distinct methodologies for conducting this analysis. Quantitative risk analysis works with hard numbers, calculating a risk's value by multiplying its probability, expressed as a percentage, by its potential financial impact, expressed as a dollar amount. The result is a concrete monetary figure attached to each risk, making it straightforward to compare threats and justify spending on controls. Qualitative risk analysis instead uses descriptive ratings, categorizing likelihood and impact as low, medium, or high rather than precise figures. While qualitative results are less precise, they are often faster to produce and still provide enough structure to populate a risk register and support decision-making. Understanding the difference between these two approaches also clarifies an important terminology distinction: probability refers to a specific numerical value assigned to the chance of an event occurring, while likelihood is a broader, ratings-based term used in qualitative assessments. In practice the two words are often used interchangeably, but recognizing the technical distinction helps when working within formal risk management frameworks or interpreting documentation that uses both terms.

What you'll learn

What's covered

Risk Analysis

Aligned to

ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA Security+
5.2 Explain elements of the risk management process
NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
NIST 800-53
RA-3 Risk Assessment

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Quantitative Risk Analysis
A risk analysis method that assigns numerical values — such as probability percentages and monetary loss estimates — to risks in order to prioritize them and justify the cost of controls. It produces metrics like Single Loss Expectancy and Annualized Loss Expectancy.
Qualitative Risk Analysis
A risk analysis method that uses descriptive ratings such as low, medium, or high to assess the likelihood and impact of risks without assigning specific monetary values.
Likelihood
A descriptive rating used in qualitative risk analysis to estimate how probable it is that a risk event will occur, typically expressed as low, medium, or high.
Impact
The potential consequence or damage to an organization if a risk event occurs, expressed qualitatively or as a monetary value.

Topics

Risk Analysis Quantitative Risk Analysis Qualitative Risk Analysis Risk Management Cybersecurity

Transcript

Why we analyze risk

Once we start understanding the risks to a company, we need to understand the depth of each one of those risks. How risky is each one of those risks? The way we do that is through risk analysis.

Once we've identified the risks there are to the company, we now have a list of risks. The next step would be to analyze those risks and look for the impact that those risks have. In the end, what we really want to do is have a way to be able to recognize what is our top risk.

So in this case right here, we see that risk number one is a 10 out of 10 on whatever scoring system that we're using. Risk two is just five out of 10, risk three is just three out of 10, we have an eight out of 10, a two out of 10, and another five out of 10. So we need a way to be able to understand the depth of these risks so we understand which ones we really need to focus on.

Risk analysis could take two different forms: quantitative risk analysis or qualitative risk analysis.

Quantitative and qualitative data, from a different context

Let's take a look at the difference between quantitative data and qualitative data from a different context. Let's say I've just delivered a class and I want to see how effective that class was, so I'm going to ask all the students to fill out a class survey. In this class survey I have several categories that they're going to rate on how they felt like it was, from a scale from 1 to 5, one being terrible to five being great. They're going to rate each one of these categories however they feel at how well it went. Then what they'll do is write in some comments, some data about how they felt and some feedback: maybe something they really liked about the course, maybe something that they thought could be changed about the course.

Quantitative data has to deal with numbers. Quantity, quantitative, there's a relationship there, and it has to deal with numbers. At the top here we have a bunch of numbers, a scale of 1 to 5. So when students rate this from 1 to 5, now we can tally this up, we can actually create a running total. We can see how many students rated it as a five, how many as a four, how many as a three, how many as a two, how many as a one. We can even add that all up, divide by the number of students there are, and come up with a full-on rating. So maybe this is 4.51, is what the course overall was scored at, and so now we have a quantity associated with it. We have quantitative data.

Quantitative data can help identify areas of the course that may need to be improved. For instance, maybe the activities in the course were rated on average really low. Now what we can do is say, well, this activities part of this has been rated really low, we need to focus on it.

The problem with quantitative data, though, is it doesn't really tell us what's wrong with it. Did they not like the format of it? Was it hard to read? Was it just activities that didn't really apply to what they were studying? Was it just activities that were really poorly written and generated a lot of confusion? So what was wrong with the activities?

Well, that's where qualitative data comes into place. When we get qualitative data, and that's what we get down in the comments, now we can understand, oh, they didn't like the activities just because they weren't given enough time to complete those activities.

So quantitative data lets us know how much or how many. It gives us numbers and stats, we can do statistical analysis on it, we can start trend lines and see if we're trending up or trending down. But qualitative data really answers that question, why.

Applying both to risk

When it comes to risk, we could perform both qualitative analysis on it or quantitative analysis on it. One way to do quantitative analysis on it is just measure things: the probability, which is a percentage, times the impact, which is a dollar amount. We can come up with then an end dollar amount that's associated with this risk analysis here.

Versus qualitative, where we look at likelihood times impact. They're not really dealing with numbers, but we're kind of rating. What we're doing is going through a rating process of, what is the likelihood that something's going to happen, or what is the impact going to be.

This could go into our risk register. So in this case right here we have the likelihood and the impact, where we would put in maybe the likelihood is high but the impact might be low, and so now we have some information going in here with the likelihood and impact. If it was quantitative, now we have dollar amounts that are associated with these risks. For instance, maybe this right here is a $100,000 risk, or maybe this one right here is a $10,000 risk, and so we'd actually have dollar amounts that are associated with the risk.

Likelihood versus probability

I will call out this terminology, likelihood versus probability. Likelihood would be something that we're going to rate, where we may have a low, a medium or a high rating with likelihood, where probability is an actual number that we assign, a probability that something would happen. So that's the difference in this terminology here, but really these terms can be used interchangeably for the most part.

I'll also give a brief mention that, although the way risk management defines what qualitative data is, I actually disagree with it. I think it's mislabeled. I'll explain that a little bit more in another lesson on qualitative.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →