A qualitative risk assessment rates each IT risk on named likelihood and impact scales, without putting a currency value on them, then reads the pair against a risk-level matrix. Define the scale wording first, rate every threat event across the seven infrastructure domains, and record the result as a register entry with an owner.
Attackers held access to SimonMed Imaging’s network from January 21 to February 5, 2025, fifteen days that ended with the records of 1,275,669 patients in the hands of the Medusa ransomware group. The Scottsdale provider confirmed names, birth dates, medical record numbers, and driver’s license numbers were taken.
The intrusion arrived through a compromised vendor connection, which is a line item on any qualitative risk assessment that covers the remote access domain. Medusa claimed 212 gigabytes left the network and demanded a million dollars. A rated register entry for that connection would have carried an owner and a review date.
| The Bottom Line |
| A qualitative risk assessment rates likelihood and impact on published wording, then reads the pair against a risk-level matrix to produce a register entry with an owner and a deadline. |
| NIST SP 800-30 Revision 1 publishes the scales in Appendices G, H, and I, including the five likelihood bands, the five impact bands, and the likelihood-by-impact risk table. |
| Attackers held access to SimonMed Imaging from January 21 to February 5, 2025, and 1,275,669 patient records were taken through a vendor connection. |
| The New York Attorney General settled with an Albany accounting firm for $60,000 in October 2025 over unencrypted Social Security numbers, a ratable exposure nobody had scored. |
| Run the qualitative risk assessment across all seven IT infrastructure domains, because a rating without a domain cannot be routed to the person who can fix it. |
| Switch from qualitative risk assessment to a quantitative model such as FAIR only when several risks tie at the top and a budget decision needs a number in dollars. |
This guide gives the qualitative risk assessment scales themselves. Most articles on the subject tell you to assign high, medium, or low without ever defining what those words mean, which is how two analysts rate the same server differently. The wording below comes from NIST SP 800-30 Revision 1 and can be used as written.
What a Rated IT Risk Register Must Contain
Start from the output, because the scale you choose only matters if the qualitative risk assessment produces an entry someone can act on. A finished line has a threat source, a threat event, the affected domain, a likelihood rating, an impact rating, the resulting risk level, the controls already in place, and a named owner.
| Register field | What it holds | Worked entry for a vendor connection |
| Threat source | Who or what initiates | External group with ransomware capability |
| Threat event | What they do | Credential misuse on a third-party maintenance connection |
| Domain | Which of the seven | Remote access |
| Overall likelihood | From the likelihood tables | Very High |
| Level of impact | From the impact table | Very High |
| Level of risk | Read from the matrix | Very High |
| Existing controls | What already reduces it | Vendor agreement, connection logging |
| Owner and date | Who acts, by when | Infrastructure lead, 30 days |
NIST SP 800-30 Revision 1 supplies templates for exactly this in Appendix I, Tables I-5 and I-7, one for adversarial threats and one for everything else. ISO/IEC 27005:2022, the fourth edition published in October 2022, leaves the scale wording to you but expects it written down before rating starts.
The column most registers omit is the domain. Without it, a rating cannot be aggregated, and the person who owns remote access never learns that three of the top five entries belong to them. The key elements of a risk register post covers the remaining columns.
Why Unrated Risks Become Enforcement Actions
New York Attorney General Letitia James announced a $60,000 settlement with the Albany accounting firm Wojeski and Company on October 20, 2025, after ransomware exposed the unencrypted Social Security numbers of 4,993 New Yorkers. The firm waited until November 2024 to notify, about sixteen months after the first incident.
James said companies must do more to protect customer data and that her office would not hesitate to hold them to account. Unencrypted identifiers on a shared drive with weak access control are not a subtle finding; they are a Very High impact rating waiting to be written down.

Figure 1. Fifteen days of access through a vendor connection, and the record count that followed. Source: HIPAA Journal reporting on SimonMed Imaging.
The economics favor running the qualitative risk assessment early. IBM put the average cost of a breach at $4.44 million globally in 2025 and a record $10.22 million in the United States, with a lifecycle of 241 days from identification to containment. A qualitative risk assessment costs a few days of a senior analyst.
The 2026 Verizon Data Breach Investigations Report found 31 percent of breaches now start with vulnerability exploitation and 48 percent involve a third party, a 60 percent rise on the previous year. Sixty-two percent involved a human element, which puts the user domain near the top of most registers.
Patching has slowed. The same report put the median time to full patching at 43 days, up from 32, and found organizations remediated only 26 percent of the defects in the CISA Known Exploited Vulnerabilities catalog during the year, down from 38 percent.

Figure 2. Four of these five bars describe threat events a domain owner can be handed and asked to rate. Source: Verizon 2026 Data Breach Investigations Report.
Availability carries its own numbers. The Uptime Institute reported that 57 percent of respondents put their most recent major outage above $100,000, and for the second year running one in five exceeded $1 million. ISACA found 55 percent of security teams understaffed.
| Organization | What was exposed | Domain it came through | The entry a rated register would carry |
| SimonMed Imaging, January 2025 | 1,275,669 patient records, 212 GB claimed | Remote access, vendor connection | Very High risk, multifactor and segmentation with a 30-day clock |
| Wojeski and Company, settled October 2025 | Unencrypted SSNs of 4,993 New Yorkers | System and application, shared storage | Very High impact on plaintext identifiers, encryption inside 30 days |
| Lexington-Richland School District Five, June 2025 | Names, birth dates, SSNs of over 31,000 people | LAN and system, district servers | High risk on server access, quarterly review of privileged accounts |
The third row is Lexington-Richland School District Five in South Carolina, where attackers reached district servers on June 3, 2025 and exposed names, birth dates, and Social Security numbers of more than 31,000 people. A parent, Tommy Sevilla, filed a class action on September 22.
The Qualitative Risk Assessment Scales, Written Out
Here are the qualitative risk assessment scales. NIST SP 800-30 Revision 1 publishes them in Appendices G, H, and I, with a qualitative band, a semi-quantitative range, and wording for each level. Adopt them as written or edit the descriptions to your environment, but publish the wording before anyone rates anything.
| Likelihood | Score | NIST wording, non-adversarial (Table G-3) | How it reads on an IT estate |
| Very High | 96-100 (10) | Almost certain to occur, or occurs more than 100 times a year | An internet-facing service scanned and probed daily |
| High | 80-95 (8) | Highly likely, or occurs 10 to 100 times a year | Phishing reaching staff inboxes most weeks |
| Moderate | 21-79 (5) | Somewhat likely, or occurs 1 to 10 times a year | A vendor account used without a review step |
| Low | 5-20 (2) | Unlikely, less than once a year but more than once in ten | A restore failure found during backup testing |
| Very Low | 0-4 (0) | Highly unlikely, less than once every ten years | Simultaneous physical loss of two data centers |
Two of the five bands do the most damage when misused. Moderate becomes the default for anything the team has not investigated, and Very Low gets applied to events that have already happened elsewhere in the sector. Test both against the frequency wording.
| Impact | Score | NIST wording, condensed (Table H-3) | What it looks like on an IT estate |
| Very High | 96-100 (10) | Multiple severe or catastrophic adverse effects on operations, assets, individuals, or other organizations | Mass record loss with regulatory notification and clinical or trading disruption |
| High | 80-95 (8) | A severe or catastrophic effect: loss of a primary function, major asset damage, major financial loss, or serious harm to individuals | A core application offline for days, or identifiers exposed |
| Moderate | 21-79 (5) | A serious effect: significant degradation of capability, significant asset damage or financial loss, harm short of life-threatening | A department-level outage, or a contained data exposure |
| Low | 5-20 (2) | A limited effect: noticeably reduced effectiveness, minor damage, minor financial loss, minor harm | A single team inconvenienced for hours |
| Very Low | 0-4 (0) | A negligible adverse effect | A logged event with no operational consequence |
NIST separates two likelihood questions: how likely the event is to start, and how likely it is to cause harm if it does. Table G-5 combines them into an overall likelihood, which is the value that enters the risk matrix. Teams that skip this step overrate events their controls already stop.

Figure 3. The qualitative risk assessment matrix, showing the level of risk for every likelihood and impact pair. Source: NIST SP 800-30 Revision 1, Appendix I, Table I-2.
Read the grid from Table I-2 in one direction only. Likelihood cannot rescue a Very Low impact, which is why the entire left column stays Very Low, and impact alone cannot produce a High rating without at least Moderate likelihood. The asymmetry is deliberate; keep it when you adapt the table.
Rating the Seven Domains of an IT Infrastructure
Scales need a scope, and the seven-domain model splits an estate into parts that different people own. Working through user, workstation, LAN, LAN-to-WAN, WAN, remote access, and system and application domains stops the qualitative risk assessment from becoming a list of whatever the security team thought of that morning.
| Domain | Threat events to rate | Usual owner | Evidence to pull |
| User | Credential sharing, social engineering, policy breach | HR and service desk | Phishing test results, joiner and leaver records |
| Workstation | Malware, unpatched endpoints, lost devices | Endpoint team | Patch compliance report, device inventory |
| LAN | Lateral movement, rogue devices, flat segments | Network team | Segmentation diagram, switch configuration review |
| LAN-to-WAN | Perimeter misconfiguration, exposed services | Network security | Firewall rule review, external scan results |
| WAN | Carrier outage, denial of service, link failure | Network team | Outage log, circuit diversity evidence |
| Remote access | Vendor credential misuse, absent multifactor | Infrastructure lead | Access list, session logs, vendor agreements |
| System and application | Data exposure, injection, privilege escalation | Application owners | Vulnerability scan, access review, audit findings |
Pull evidence per domain before rating it, because the rating is only as good as what sits behind it. Ticket counts, patch reports, failed login volumes, vendor access logs, and prior audit findings are all available inside a day in most organizations.
Ask each domain owner for the same five items, so that ratings across domains rest on comparable evidence. An owner who argues well should not outscore an owner who prepared badly. The list below takes an hour per domain to assemble:
- Incidents and near-misses touching the domain in the last 12 months, with dates.
- Open audit findings and their age, including any repeat findings.
- The patch or change backlog, with the oldest outstanding item named.
- Every account and connection reaching the domain from outside it.
- The controls claimed for the domain, and the date each was last tested.
The remote access and system and application domains produce the highest ratings in most qualitative risk assessments we run, which matches the 48 percent third-party involvement in the Verizon figures. The user domain follows, and the WAN domain is usually overrated because carrier redundancy already covers it.
A Qualitative Risk Assessment Scored End to End
Take the SimonMed pattern and score it. The threat source is an external group with ransomware capability, the threat event is credential misuse on a vendor connection, and the affected domain is remote access. Every rating below comes from the tables above.
The qualitative risk assessment applies to a diagnostic imaging network of the same shape and is not a reconstruction of SimonMed’s own register, which is not public. The reported facts set the likelihood and impact anchors; the treatment rows describe what we would write for a client.
| Step | Question | Rating | Reason |
| 1. Likelihood of initiation | How often do external groups target imaging providers this way? | High (8) | Sector-wide ransomware activity, phishing arriving weekly |
| 2. Likelihood of adverse impact | If a credential works, does harm follow? | Very High (10) | The vendor path reaches clinical systems without a segmentation step |
| 3. Overall likelihood (Table G-5) | Combine steps 1 and 2 | Very High | High initiation against Very High likelihood of impact |
| 4. Level of impact (Table H-3) | What is the effect if it happens? | Very High | Mass patient record loss, notification duty, clinical disruption |
| 5. Level of risk (Table I-2) | Read likelihood against impact | Very High | Very High likelihood, Very High impact |
| 6. Existing controls | What already reduces it? | Partial | Contract and logging in place, no multifactor on the connection |
| 7. Treatment | What happens now | Multifactor and segmentation, 30 days | Owner: infrastructure lead, reported to the risk committee |

Figure 4. The same network scored across all seven domains, which is what makes the register routable. Source: riskpublishing.com worked example on the NIST scales.
Scored across all seven domains, the same network produces one Very High, two High, one Moderate, and three Low ratings, which is the distribution that makes a register useful. A qualitative risk assessment where everything comes out High tells the board nothing and gets the whole document ignored.
From Rating to Treatment, and When to Switch to Dollars
A rating that does not change a deadline is decoration. Map each level to a required action, an approval level, and a clock, then hold the clock. NIST CSF 2.0, published in February 2024, puts this under the GOVERN function it added, alongside the ID.RA risk assessment category.
| Risk level | Required action | Who approves | Clock |
| Very High | Stop, compensate, or isolate; plan the same day | CIO and risk committee | Plan in 24 hours, closed in 30 days |
| High | Funded remediation with a named owner | CIO | 90 days |
| Moderate | Scheduled into the next change cycle | Domain owner | 6 months |
| Low | Accept, with the entry left open | Domain owner | Reviewed at the next annual pass |
| Very Low | Accept and record | Domain owner | Reviewed at the next annual pass |
Switch to dollars when the rating stops discriminating. Once three items sit at Very High and the budget covers one, FAIR gives loss event frequency and loss magnitude in currency, which is the number a board can act on. Qualitative rating stays the filter that decides what to quantify.
Treatment choices need a control catalog behind them, and CIS Controls v8.1 sorts its eighteen controls into three implementation groups by resource level, which gives a small IT team a defensible starting set. Reopen a rating between annual cycles when any of the following happens:
- A vendor gains, changes, or loses access to any domain.
- A CISA advisory names a product running in the estate.
- Patching for a domain slips past the 43-day median.
- An incident or near-miss occurs anywhere in the domain.
- A control listed against the entry fails its test.
Where Qualitative Risk Assessments Break Down
Seven failures account for most of the bad registers we are asked to rebuild, and all seven are visible in a ten-minute read of the spreadsheet. The table pairs each with the correction, and none of the corrections takes longer than a working day.
| Failure | How it shows up | Correction |
| Undefined bands | High, Medium, and Low with no wording behind them | Publish the NIST descriptions before anyone rates |
| Everything rated High | No spread across the register | Apply the frequency test in the likelihood table |
| One likelihood question | Initiation and impact likelihood merged into a guess | Rate both, then combine with Table G-5 |
| No domain column | Ratings cannot be routed to anyone | Make the seven domains a required field |
| Ratings without evidence | No incident, audit, or log cited | Add an evidence column and reject blank entries |
| A static register | The same ratings as last year | Attach the reopen triggers to each entry |
| Quantifying too early | Dollar models built for every risk | Quantify only what the scale leaves tied at the top |
The first and the last are the expensive ones. Undefined bands make every other column unreliable, and premature quantification burns weeks of analyst time on risks that a published scale would have separated in an afternoon. Fix those two before touching the others.
Common Qualitative Risk Assessment Questions Practitioners Ask
What is a qualitative risk assessment for an IT infrastructure?
A qualitative risk assessment for an IT infrastructure rates each threat event on named likelihood and impact scales with published wording, then reads the pair against a risk-level matrix. The output is a register entry per domain with an owner and a deadline. NIST SP 800-30 Revision 1 supplies the scales.
How do you rate likelihood in a qualitative risk assessment?
In a qualitative risk assessment, rate likelihood twice: how likely the threat event is to start, and how likely it is to cause harm if it starts. Combine the two with the NIST Table G-5 grid to get overall likelihood. Anchor each band to a frequency, such as ten to one hundred times a year for High.
What scales should a qualitative risk assessment use?
A qualitative risk assessment should use five bands, Very Low through Very High, with published wording for likelihood, impact, and the resulting risk level. The NIST SP 800-30 Revision 1 appendices give all three, with semi-quantitative ranges from 0 to 100 if you need a number. Edit the descriptions to your environment, then freeze them.
How is a qualitative risk assessment different from a quantitative one?
A qualitative risk assessment produces ordered ratings; a quantitative one produces money. Qualitative rating is faster and covers the whole estate, which makes it the filter. Quantitative models such as FAIR then price the few risks that stay tied at the top, where a budget decision needs a number.
Who should take part in an IT infrastructure risk assessment?
A qualitative risk assessment session needs the owner of each domain, an analyst who prepared the evidence, and someone who can approve a deadline. The user domain needs a service desk voice, and the system and application domain needs whoever runs the vendor connections. ISACA reported 55 percent of security teams understaffed, so keep the session to two hours.
How often should a qualitative risk assessment be repeated?
Repeat a qualitative risk assessment annually at minimum, and reopen individual entries on triggers between cycles. Vendor access changes, a CISA advisory naming a product you run, a patch backlog past the 43-day median, and any incident in the domain all justify a rerun of that entry.
Can a qualitative risk assessment satisfy an auditor?
Yes. A qualitative risk assessment satisfies an auditor when the scale wording is published, each rating cites evidence, and the treatment deadlines were met. Auditors challenge the rating method rather than the rating, so a documented scale and a dated register carry more weight than a heat map. ISO/IEC 27005:2022 expects the criteria to be defined in advance.
The Road to 2028: Continuous Ratings and Quantified Loss
Annual qualitative risk assessment is losing to continuous rating. Vulnerability feeds, vendor access logs, and patch backlogs now update daily, and a register refreshed once a year is out of date within weeks. The scales stay the same; the cadence and the evidence behind them change.
Regulators are asking for the qualitative risk assessment method. The New York settlement turned on unencrypted data and access control, both of which are ratable items, and the Verizon finding that 48 percent of breaches now involve a third party puts vendor connections in every examiner’s first question.
By 2028 we expect most mid-sized programs to run qualitative risk assessments continuously and quantify only the top handful, with NIST CSF 2.0 governance evidence attached to each. The organizations that get there first will be the ones that wrote their scale wording down this year.
Send us your current register and the scale you rate against, and we will tell you which entries would survive an examiner and which would not. The qualitative risk assessment and rebuild formats sit on our advisory services page; and the contact page reaches us directly.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.