A matrix helps organize judgment
A risk matrix places a scenario against likelihood and consequence bands. It can help people compare their concerns and agree which decisions need attention. It becomes misleading when the colors appear more certain than the evidence behind them.
NIST SP 800-30 discusses qualitative and quantitative assessment approaches and uncertainty.1 Your choice should fit the information available and the decision being made. A five-point scale does not create precise probabilities or financial estimates by itself.
Before designing a matrix, decide what it should support. Prioritizing a small operational backlog is different from deciding whether to accept a potentially severe safety event. One matrix may not be appropriate for both.
Define the assessment boundary
State the activity, scenario and horizon. “Likelihood next quarter” and “likelihood over five years” are different questions. A matrix without a horizon invites owners to answer whichever version they find easiest.
Name the consequence dimensions that matter: service interruption, financial effect, privacy, safety, contractual exposure or customer harm. Explain whether the overall consequence follows the highest applicable dimension or another agreed method. Do not bury a severe impact by averaging it with less consequential dimensions.
Record the treatment stage. Current residual risk reflects controls currently operating. Target risk reflects a future state after proposed improvements. Place them in different fields so a planned control cannot improve today's rating.
An illustrative three-band matrix
This is an original fictional design for discussion, not a recommended universal scale. A business would need to adapt the bands, criteria and authorities to its own activity.
| Consequence / likelihood | Lower likelihood | Plausible | More likely |
|---|---|---|---|
| Limited consequence | Routine owner review | Routine owner review | Planned improvement |
| Significant consequence | Planned improvement | Management decision | Priority management decision |
| Severe consequence | Escalate for explicit decision | Escalate for explicit decision | Immediate escalation |
Here the cells direct a decision process rather than merely display a color. “Escalate” means a named authority receives the scenario, assumptions and proposed response. It does not automatically mean the activity must stop; that decision requires the relevant authority and circumstances.
Define consequence in business language
For a customer-support service, a limited consequence might be a short interruption recoverable through existing procedures. A significant consequence could affect a contractual response commitment. A severe consequence could involve a sustained inability to serve customers or another material exposure.
Replace these descriptions with your own approved thresholds and obligations. If financial values are used, explain the currency, period and estimation basis. If several effects differ, record them individually before selecting an overall band.
Define likelihood with reasons
Use observations such as incident history, exposure, dependency changes and control evidence. If reliable probabilities are unavailable, do not label a band “exactly 10%” merely to make it look quantitative.
An owner might record “plausible during the next quarter because this dependency has failed twice, and the corrective action is unverified.” Another may record “lower likelihood based on a tested alternate arrangement, with limited data about an extended outage.” The narrative explains both the rating and its limits.
Why multiplying scores can mislead
Suppose a team uses likelihood and consequence scales from one to five. A likelihood of two multiplied by consequence five produces ten. Likelihood five multiplied by consequence two also produces ten.
Those scenarios can require very different responses. A frequent minor delay may warrant operational improvement; a less frequent severe event may require leadership acceptance or a mandatory safeguard. Equal products do not establish equal importance.
The scale is also ordinal: five means a higher band than four, not necessarily a consequence exactly 25% greater. Treating those labels as measured quantities can introduce false precision. If multiplication is retained for sorting, show the underlying bands and apply separate escalation rules.
Worked example: two service interruptions
This fictional company depends on a ticketing tool and a payment-processing service. Its horizon is the next quarter.
| Scenario | Estimated band | Why the response differs |
|---|---|---|
| Ticketing tool slows briefly during peak demand | More likely, limited consequence | Staff can use a tested temporary process; improvement can be scheduled |
| Payment service becomes unavailable before an important cutoff | Lower likelihood, severe consequence | Current fallback is unverified; leadership needs a decision and a checked response |
If both receive the same numeric product, the team should not place them in an identical work queue. The matrix must preserve the payment cutoff consequence, evidence gap and escalation requirement.
NIST IR 8286A Revision 1 supports documenting scenarios and their estimates in a risk register.2 Keep that scenario record behind the matrix so a reviewer can inspect what the cell represents.
Add confidence and a sensitivity check
Confidence describes how well the evidence supports the estimate. The evidence-collection checklist can help record source, coverage and limitations. It should not be mixed into the risk score without a clear method. Use a brief explanation: “low confidence because the supplier has not provided outage-duration information.”
Then vary a material assumption. If the payment interruption lasts two hours instead of one day, does the response change? If the fallback handles half the transactions rather than all, is it still acceptable?
Record the assumption range and decision effect. When the same response is appropriate across plausible estimates, spending weeks debating a score may add little value. When the decision changes, better evidence may be the most important next action.
Verify controls before lowering the rating
A control's existence and its effectiveness are different questions. A recovery policy may define a target while a restore exercise reveals that essential configuration is missing.
NIST SP 800-53A describes examining, interviewing and testing as assessment methods.3 Use an appropriate method to check a claimed control. Do not require a destructive production test; choose a safe, authorized way to establish the relevant evidence.
Record scope, date, result and exceptions. If the control is untested, show that uncertainty. If a treatment is incomplete, keep the current rating and proposed target separate until the evidence supports a change.
Make the matrix accessible and explainable
Use text labels such as “management decision” alongside colors. A grayscale printout or a reader with color-vision differences should retain the meaning. Show the band definitions near the matrix and preserve the assessment date.
Assign review responsibility for inconsistent ratings. When two owners rate similar exposures differently, discuss the assumptions rather than force superficial agreement. A documented difference may be reasonable when scope or consequences differ.
Review checklist before adoption
Confirm that the matrix has:
- A stated activity and time horizon.
- Written likelihood and consequence definitions.
- A rule for multiple consequence dimensions.
- Separate current and target states.
- Reasons and evidence for each estimate.
- Confidence notes and material assumptions.
- Escalation rules for severe or constrained exposures.
- Named authority for acceptance decisions.
- Review dates and change triggers.
- Text meanings that remain readable without color.
Use the matrix to improve the quality of decisions, then judge it by those decisions. A precise-looking dashboard is less valuable than a modest scoring method that exposes uncertainty and directs accountable action.
Sources and references
-
NIST. Guide for Conducting Risk Assessments, SP 800-30 Revision 1 (2012-09). Risk-assessment guidance originally developed for federal information systems; business examples here are an adaptation. ↩
-
NIST. Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management, IR 8286A Revision 1 (2025-12-18). Current revision supports scenario-based risk registers and likelihood/impact estimates; supersedes the 2021 publication. ↩
-
NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩

