TechKnowSurge
ISC2 CISSP 1.9 CompTIA Security+ 5.2 NIST CSF ID.RA-05 NIST 800-53 RA-3 NIST CSF GV.RM-06
VideoSecurityFree

Qualitative Risk Analysis

Qualitative risk analysis uses descriptive ratings like low, medium, and high to assess the likelihood and impact of risks, offering a faster alternative to number-based quantitative methods. A risk matrix can then be used to compare and prioritize risks based on where they fall across those rating scales.

Complete this video to capture a CTF flag worth 1 point.

About this video

Risk analysis generally falls into two broad categories: quantitative and qualitative. Quantitative analysis produces precise numerical outputs — typically by multiplying the probability of an event by its financial impact to arrive at a dollar figure — which allows for highly granular comparison and statistical treatment. Qualitative analysis trades that precision for accessibility, replacing exact figures with descriptive rating scales that are faster to apply and require less data to produce. In a standard qualitative risk framework, each identified risk is rated on two dimensions: likelihood and impact. Likelihood is typically expressed on a scale from rare to certain, while impact ranges from negligible to severe. These two ratings are then mapped onto a risk matrix, a grid that assigns a combined priority score to every likelihood-impact pairing. Risks that fall into high-likelihood, high-impact zones are flagged as critical and addressed first, while low-likelihood, low-impact risks receive lower priority. This structure allows organizations to compare risks that might otherwise seem difficult to rank against each other. There is an ongoing debate within the broader research and analysis community about whether this method is truly qualitative. Because likelihood and impact ratings can be converted to numbers and used for statistical comparison, the approach behaves more like quantitative research in practice. Within the cybersecurity industry, however, this rating-based method is the accepted definition of qualitative risk analysis, and that convention holds across professional certifications and standard frameworks. Understanding both the practical application of the method and its definitional boundaries within the field is essential for practitioners working in security risk management.

What you'll learn

What's covered

Qualitative Risk Analysis

Aligned to

ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA Security+
5.2 Explain elements of the risk management process
NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
NIST 800-53
RA-3 Risk Assessment

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Qualitative Risk Analysis
A risk analysis method that uses descriptive ratings such as low, medium, or high to assess the likelihood and impact of risks without assigning specific monetary values.
Quantitative Risk Analysis
A risk analysis method that assigns numerical values — such as probability percentages and monetary loss estimates — to risks in order to prioritize them and justify the cost of controls. It produces metrics like Single Loss Expectancy and Annualized Loss Expectancy.
Likelihood
A descriptive rating used in qualitative risk analysis to estimate how probable it is that a risk event will occur, typically expressed as low, medium, or high.
Impact
The potential consequence or damage to an organization if a risk event occurs, expressed qualitatively or as a monetary value.
Risk Matrix
A grid used in qualitative risk analysis that maps likelihood against impact to prioritize risks and determine which require the most urgent attention.

Topics

Qualitative Risk Analysis Risk Matrix Risk Assessment Likelihood And Impact Risk Prioritization Cybersecurity Risk Management

Transcript

Quantitative versus qualitative

When we're doing risk analysis we have a couple of different options. We have quantitative risk analysis, which would be coming up with some sort of number to represent the risk. One example of this is the probability from a percent standpoint times the impact from a dollar amount, and then we would come up with an actual dollar amount that that risk has associated with it. This is a great method to do it because it gets really granular — we actually have dollar amounts that are attached to it.

Qualitative risk analysis can be easier to implement. Quantitative is much more complex in figuring out what the probability is going to be and what the total impact is going to be from a monetary standpoint. But from a quality standpoint, what we can do is just rate things as a low, medium or high to get the amount of likelihood, and do the same thing for the impact that would have, and then we would have a different way to compare these different risks.

Do realize that there are different methodologies, or different ways, that we can actually do qualitative risk assessment. We're not going to get into all of them. In fact, we're just going to cover one that I created for some of the businesses I worked with.

Rating likelihood and impact

To start with, we would take each individual risk and do a qualitative risk analysis on it. A qualitative risk analysis would be: what is the likelihood of it? I have a one through five rating of this, one being rare, two being unlikely, three being possible, four being likely and five being certain. Times the impact, which would be negligible versus minor versus moderate, major or severe. So now we have a way to rate what is the likelihood something's going to happen.

For instance, let's say an earthquake is going to happen. Well, in the area where I live it's likely to happen at some point in time, but I'm just not quite sure when it's going to happen, so I would probably rate that as likely. And then also, what is the impact going to be? Well, what we're going to get could be very severe actually, or it could be just kind of moderate, and so maybe what I do is I rate this as major. If it's likely and major, that's going to be much more something I want to tackle and figure out sooner rather than later than something that's going to be unlikely and minor.

The risk matrix

Now, this method of risk measurement can be kind of a problem: how do you compare one risk to another? Let me give you an example. Let's say I have one risk that's rated as unlikely to happen, but if it were to happen it would be major, versus another risk, risk number two, that is likely to happen but if it were to happen it would be minor. How do I compare these two?

This is where I could create a risk matrix, where I have the likelihood — something's rare, unlikely, possible, likely or certainty — and then I could also have the impact: severe, major, moderate, minor or negligible. Within this I can then assign different ratings. So if something were to be possible and major, maybe this gets a higher rating here than something that is going to be moderate and possible, or moderate or minor and likely.

So here's where that is filled out. Now we have what is going to be critical that we address here: things that are going to be likely and severe, or certainty and severe, or major and certainty. Those are the things that are critical and we want to address that, or the possibility is high there, or the severity is medium there. So this is a risk matrix that we can use to then do a grading on these risks.

My opinion on the terminology

Now I'm going to give my opinion. What I just described is considered the definition of qualitative risk analysis from the cybersecurity community — we consider that qualitative. However, I don't really consider it a qualitative measurement. I still consider it a quantitative measurement.

If you were with me in one of my other lessons where I described a class survey where you're rating the class on a terrible, bad, okay, good or great, this is quantitative measurements that could actually be turned into numbers for you to measure it, and qualitative data were the actual comments of what needs to be changed. Somebody could — there could be lots of scores low for an activity, but you wouldn't really know why. You know that there's work that needs to be done there, but you really wouldn't know what kind of work until you read the comments and realized, well, you didn't give them enough time for those activities so they didn't care for it.

So in most other quantitative and qualitative analysis that I've done, this would actually be considered quantitative research, because I could actually assign numbers to this — one, two for medium, three for high and four for critical — and I can at least do some sort of statistical analysis on this. Granted, not to the same level as actually going with the dollar amounts and the probability of a percent, but I still can do statistical analysis on this, making this quantitative analysis, not qualitative.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →