Qualitative risk analysis uses descriptive ratings like low, medium, and high to assess the likelihood and impact of risks, offering a faster alternative to number-based quantitative methods. A risk matrix can then be used to compare and prioritize risks based on where they fall across those rating scales.
Qualitative Risk Analysis
When we're doing risk analysis we have a couple of different options. We have quantitative risk analysis, which would be coming up with some sort of number to represent the risk. One example of this is the probability from a percent standpoint times the impact from a dollar amount, and then we would come up with an actual dollar amount that that risk has associated with it. This is a great method to do it because it gets really granular — we actually have dollar amounts that are attached to it.
Qualitative risk analysis can be easier to implement. Quantitative is much more complex in figuring out what the probability is going to be and what the total impact is going to be from a monetary standpoint. But from a quality standpoint, what we can do is just rate things as a low, medium or high to get the amount of likelihood, and do the same thing for the impact that would have, and then we would have a different way to compare these different risks.
Do realize that there are different methodologies, or different ways, that we can actually do qualitative risk assessment. We're not going to get into all of them. In fact, we're just going to cover one that I created for some of the businesses I worked with.
To start with, we would take each individual risk and do a qualitative risk analysis on it. A qualitative risk analysis would be: what is the likelihood of it? I have a one through five rating of this, one being rare, two being unlikely, three being possible, four being likely and five being certain. Times the impact, which would be negligible versus minor versus moderate, major or severe. So now we have a way to rate what is the likelihood something's going to happen.
For instance, let's say an earthquake is going to happen. Well, in the area where I live it's likely to happen at some point in time, but I'm just not quite sure when it's going to happen, so I would probably rate that as likely. And then also, what is the impact going to be? Well, what we're going to get could be very severe actually, or it could be just kind of moderate, and so maybe what I do is I rate this as major. If it's likely and major, that's going to be much more something I want to tackle and figure out sooner rather than later than something that's going to be unlikely and minor.
Now, this method of risk measurement can be kind of a problem: how do you compare one risk to another? Let me give you an example. Let's say I have one risk that's rated as unlikely to happen, but if it were to happen it would be major, versus another risk, risk number two, that is likely to happen but if it were to happen it would be minor. How do I compare these two?
This is where I could create a risk matrix, where I have the likelihood — something's rare, unlikely, possible, likely or certainty — and then I could also have the impact: severe, major, moderate, minor or negligible. Within this I can then assign different ratings. So if something were to be possible and major, maybe this gets a higher rating here than something that is going to be moderate and possible, or moderate or minor and likely.
So here's where that is filled out. Now we have what is going to be critical that we address here: things that are going to be likely and severe, or certainty and severe, or major and certainty. Those are the things that are critical and we want to address that, or the possibility is high there, or the severity is medium there. So this is a risk matrix that we can use to then do a grading on these risks.
Now I'm going to give my opinion. What I just described is considered the definition of qualitative risk analysis from the cybersecurity community — we consider that qualitative. However, I don't really consider it a qualitative measurement. I still consider it a quantitative measurement.
If you were with me in one of my other lessons where I described a class survey where you're rating the class on a terrible, bad, okay, good or great, this is quantitative measurements that could actually be turned into numbers for you to measure it, and qualitative data were the actual comments of what needs to be changed. Somebody could — there could be lots of scores low for an activity, but you wouldn't really know why. You know that there's work that needs to be done there, but you really wouldn't know what kind of work until you read the comments and realized, well, you didn't give them enough time for those activities so they didn't care for it.
So in most other quantitative and qualitative analysis that I've done, this would actually be considered quantitative research, because I could actually assign numbers to this — one, two for medium, three for high and four for critical — and I can at least do some sort of statistical analysis on this. Granted, not to the same level as actually going with the dollar amounts and the probability of a percent, but I still can do statistical analysis on this, making this quantitative analysis, not qualitative.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →