Skip to content

Assessment workflow and risk scoring

Define components, capabilities, tools, goals, constraints, interactions and trust boundaries. Select the closest canonical architecture pattern.

For each canonical threat:

  • Confirm applicability.
  • Describe the specific asset and path.
  • Identify actors, prerequisites and vulnerabilities.
  • State the credible consequence.

Trace how a compromise can move between layers. Record entry point, intermediate transitions, final impact and independent break points.

Score likelihood and impact from 1 to 5. State whether the scores represent inherent or residual risk.

Define preventive, detective, response and recovery controls, accountable owner, target date, dependencies and acceptance authority.

Validate controls through evidence and testing. Monitor changing threats, system behaviour, exceptions and architecture changes. Reassess continuously.

ScoreLabelPractical anchor
1RareRequires exceptional access or conditions; no credible recent path; strong controls tested
2UnlikelyFeasible but constrained; limited exposure; several effective independent controls
3PossibleCredible conditions exist; similar attacks occur; control coverage is mixed or partly tested
4LikelyExposed path, capable actor or frequent precursor; important controls are weak or untested
5Almost certainActive exploitation, repeated events or near misses; trivial path; controls absent or bypassed

Likelihood should consider:

  • External and internal exposure.
  • Attacker access and capability.
  • Frequency and opportunity.
  • Known techniques and threat intelligence.
  • Complexity and prerequisites.
  • Strength and independence of preventive and detective controls.
  • Test results and prior incidents.
  • Change rate and time-to-detection.

Do not reduce likelihood merely because a policy exists.

ScoreLabelPractical anchor
1NegligibleLocal, short-lived and easily reversible; no sensitive data or consequential decision
2MinorLimited operational or data effect; manageable recovery; low external consequence
3ModerateMaterial disruption, privacy issue, financial loss or affected individuals; containable
4MajorSerious legal, customer, security, safety or business harm; broad or difficult recovery
5SevereCatastrophic, irreversible or systemic harm; critical infrastructure, life safety or fundamental rights

Assess impact across:

  • Confidentiality, integrity and availability.
  • Privacy and fundamental rights.
  • Safety and physical consequences.
  • Financial loss and fraud.
  • Legal, regulatory and contractual duties.
  • Customer and public harm.
  • Mission and operational continuity.
  • Reputation and market integrity.
  • Blast radius, persistence, detectability and reversibility.

Use the highest credible consequence, not an average of unrelated outcomes.

Raw risk = likelihood × impact

Raw productSeverityGamut band
1–41Low
5–92Moderate
10–143Elevated
15–194High
20–255Critical

Examples:

  • Likelihood 2 × impact 4 = 8 → Moderate.
  • Likelihood 3 × impact 4 = 12 → Elevated.
  • Likelihood 4 × impact 5 = 20 → Critical.
  • Inherent risk assumes current controls have not yet reduced the threat.
  • Residual risk considers controls only where their design and operation are evidenced.

Record which basis is being used. Do not mix inherent likelihood with residual impact or call a control-maturity score “risk”.

Gamut uses maxima for MAESTRO roll-up:

  • A section’s risk is its highest scored threat, not its average.
  • A system’s posture is its highest scored threat.
  • The workspace view reports the worst system and distribution of each assessed system’s worst-case band.

This prevents one Critical threat from being diluted by many Low threats.

Unscored threats do not count as Low. Coverage is displayed separately.

BandExpected response
LowConfirm baseline controls and monitor material change
ModerateDocument proportionate treatment, owner and review date
ElevatedActively reduce risk and validate prevention, detection, response and recovery
HighTreat before broader deployment unless formally accepted by authorised risk ownership
CriticalContain or pause the capability pending effective treatment or exceptional executive acceptance

Before accepting a score, confirm:

  1. The scenario names real components.
  2. Likelihood cites exposure and control evidence.
  3. Impact describes a credible outcome.
  4. The score basis is inherent or residual.
  5. Missing information has not been converted into a low score.
  6. A failed test or open finding is reflected.
  7. Cross-layer amplification is considered.
  8. The risk owner can understand and challenge the rationale.

Rescore after:

  • Control implementation or retesting.
  • Model, data, tool, provider or architecture change.
  • New vulnerability or threat intelligence.
  • Incident, near miss or detected abuse.
  • Increased autonomy or privilege.
  • Deployment into a more sensitive environment.
  • New regulatory or contractual exposure.
  • Risk acceptance expiry.