Skip to content

Risk Assessment & Treatment Methodology (Clause 6 & 8)

1. Overview

The organization uses a standard qualitative 5x5 Risk Matrix assessing Likelihood vs. Impact across Confidentiality, Integrity, and Availability (CIA).

$$\text{Risk Score} = \text{Likelihood (1–5)} \times \text{Impact (1–5)}$$


2. Scoring Criteria

Likelihood Scale

  1. Rare: Improbable, occurs once every 5+ years.
  2. Unlikely: Possible, but not anticipated (once every 2–3 years).
  3. Possible: Might occur at some point (annual frequency).
  4. Likely: Expected to occur multiple times per year.
  5. Almost Certain: Regular or continuous occurrence.
  1. Insignificant: Negligible operational drag; <£1,000 loss.
  2. Minor: Localized IT disruption; minor customer inconvenience; <£10,000.
  3. Moderate: Partial service outage; minor regulatory notice; £10,000–£50,000.
  4. Major: Significant customer downtime; material data breach; £50,000–£250,000.
  5. Catastrophic: Critical business paralysis; irreversible brand loss; >£250,000.

3. Risk Threshold & Treatment Options

Score Rating Required Action
1 – 6 Low Accept risk; monitor during periodic review.
8 – 12 Medium Mitigate; implement operational controls within 60 days.
15 – 25 High / Critical Immediate mitigation; executive sign-off required for any temporary acceptance.