What Is a Bow-Tie Risk Analysis? Simple Example for Non-Engineers
On November 15, 2013, attackers broke into Target Corporation’s network using credentials stolen from … Read more
Risk assessment is where risk management stops being abstract. It is the structured process of identifying what could go wrong, estimating how likely it is and how much it would hurt, and deciding whether the residual exposure is acceptable. Done well it produces decisions; done badly it produces a colour-coded spreadsheet nobody reads.
Every credible assessment rests on three choices you make before you score anything: the scales you use for likelihood and impact, whether you are scoring inherent or residual risk, and who owns the judgement. Get those wrong and the numbers are noise.
This is the largest section on the site, covering qualitative and quantitative methods, risk matrices and their well-documented weaknesses, control effectiveness testing, scenario analysis, and sector-specific assessments from cyber to supply chain. It connects directly to enterprise risk management for the governance layer above it, RCSA for the self-assessment variant used in financial services, key risk indicators for the monitoring that follows an assessment, and risk appetite for the thresholds that decide what "acceptable" actually means.
On November 15, 2013, attackers broke into Target Corporation’s network using credentials stolen from … Read more
The 5×5 Risk Matrix vs 4×4 Risk Matrix debate comes down to one practical … Read more
Most risk matrices are theatre. They give boards a green-amber-red quilt that feels rigorous, … Read more
When Pacific Gas & Electric filed for Chapter 11 bankruptcy in January 2019, its … Read more
FTC Safeguards Rule Compliance is a critical obligation for financial institutions, and recent enforcement … Read more
Key Takeaways The global credit risk assessment market reached $9.55 billion in 2025 and … Read more
Key Takeaways Companies spend an average of $1.4 million annually to meet SOX Section … Read more
Key Takeaways The TNFD framework, published in September 2023, provides 14 disclosure recommendations across … Read more
Key Takeaways Scope 3 financed emissions (GHG Protocol Category 15) represent over 99% of … Read more
Key Takeaways # Takeaway 1 NIST CSF 2.0 is a voluntary, flexible cybersecurity framework … Read more
Key Takeaways ✓ Third-party breaches doubled from 15% to 30% of all incidents in … Read more
Key Takeaways If you only read one section, read this. What Is AI Bias … Read more