What is a risk analysis?
A risk analysis is the part of risk management where you assess risks based on probability and impact. This step follows the risk identification phase—where you map out which risks exist in the first place—and precedes the selection of mitigation measures. Without a risk analysis, that choice is just guesswork: you wouldn't know which risk carries the most weight.
Risk analysis is one of the steps within the broader, ongoing process that ranges from identification to monitoring. Many risk analysis methods assess a risk based on the likelihood or frequency of a scenario and its consequences. ISO 27005 is one of the standards that provides guidance for this.
An important prerequisite for analyzing a risk is that it must be described clearly and precisely. A useful scenario contains four elements: a threat, an asset, the method by which the threat occurs, and the impact on the organization. "Ransomware" is not a scenario. "Ransomware in the production environment via a phishing email, resulting in production downtime" is. If you prefer not to start from scratch, use the free Polar Risk scenario builder to draft scenarios using this structure.
This structure works well for cyber risks and many other operational and security risks. The difference lies in the threats and assets you input, not in the method itself. Organizations that compare multiple risk analyses usually quickly discover that unstructured risks are difficult to compare, and that a shared structure per scenario makes comparison possible.
Why is a risk analysis important?
An organization never has the budget or time to address every conceivable risk. A risk analysis is a tool for making decisions based on probability and impact, rather than on gut feeling or whoever shouts the loudest in the room. The NCSC positions risk analysis as a key component of digital security risk management: only when you know which risk is the most significant do you know where your first euro should be spent.
A risk analysis also serves an internal function that is often overlooked: it provides IT, security, and the business with a common language. Without an analysis, every department defends its own risks based on personal perception, and the person who shouts the loudest usually wins, not the one with the greatest risk. Furthermore, a risk analysis from two years ago tells you little about today. Systems, suppliers, and threats change faster than most organizations update their risk registers.
Performing a risk analysis in five steps
Step 1: Inventory your most important business processes. Map out the services and supporting assets that truly matter: customer data, the ERP system, the webshop that generates revenue. Not everything is a crown jewel, and a risk analysis that tries to cover everything at once will never get anywhere. Be sure to involve multiple departments: an IT manager will view different assets as critical compared to an operations manager or a CFO.
Step 2: determine the relevant risk scenarios. Describe which threats are relevant for each service, and formulate them as a scenario using the four elements from the previous section: threat, asset, method, and impact. A vague threat leads to a vague analysis. Expect multiple scenarios per service: a production environment is at risk from ransomware, but equally from a vulnerability at a supplier.
Step 3: estimate the probability. How often is this scenario expected to occur per year? Use historical data where available (incident logs, threat reports) and market data where data is missing. Define in advance exactly what "high" or "low" means, otherwise everyone will score differently. Do this with a broad group: one person can never oversee all risks and will also score based on their own bias.
Step 4: estimate the impact. What does it cost if the scenario occurs? Think in categories: production loss, recovery costs, revenue loss, fines, and reputational damage. Where possible, work with a range (minimum, maximum, most likely) instead of a single amount. For cyber risks specifically, the FAIR method breaks this down into direct and indirect losses, which is covered later in this post.
Step 5: prioritize and link measures. For every risk, there are four paths: accept, mitigate, transfer (for example, via insurance), or avoid. A score without follow-up action is just a paperwork exercise: every risk above the agreed threshold gets an owner and a measure with a deadline. Repeat the entire exercise at least annually, because both threats and the organization are constantly changing.
Qualitative versus quantitative risk analysis
A risk analysis can be performed qualitatively, semi-quantitatively, or quantitatively. The difference lies in how you express probability and impact. A qualitative risk analysis works with labels: low, medium, high, often placed in a risk matrix . A quantitative risk analysis calculates probability and impact into figures: a percentage probability per year and an expected loss amount, using a range instead of a single number.
Qualitative labels are difficult to compare. Two risks that both score "high" can, in reality, differ by a factor of ten in expected damage. For a director managing a budget, that is insufficient justification: a director can weigh an investment against an amount, not against a color.
Risk quantification is a specialized skill. It is not an Excel exercise you just quickly do on the side: the FAIR method works with probability distributions (minimum, maximum, most likely value), not with an educated guess on a scale of one to five. The following example shows what that difference yields in practice.

Case study: risk analysis of a ransomware scenario
Imagine: cybercriminals launch a ransomware attack on the ERP system of a manufacturer, ACME Industries, via a phishing email, resulting in production downtime. Qualitatively, this scenario scores "High" (impact) and "Medium" (likelihood): a High score. That is the conclusion where most risk matrices stop.
Quantitatively, the analysis goes a step further. The scenario has an annual probability of 9% and an expected downtime of approximately 14 days. The expected financial loss if the scenario occurs is approximately €2.4 million, with a range of €0.4 million to €7.1 million. Because the frequency of the scenario is also modeled, the annual financial risk exposure can then be determined. It is precisely this combination of frequency and loss magnitude that makes different scenarios financially comparable.
Another risk that also happens to score "High" might actually result in a tenth of that amount in damages. Without the quantitative step, both risks appear identical on the list, and the budget might go to the wrong risk first.
Disadvantages of qualitative scores
Qualitative risk scores are susceptible to cognitive bias and differences between assessors. Two professionals may interpret the same scenario differently and therefore arrive at a different score, especially when scoring criteria are not sufficiently concrete. Extensive research has been conducted on cognitive bias when estimating cyber risks, with the same conclusion every time: different assessors consistently score the same risk differently.
There is also a practical side to it: once a risk is labeled "High," it rarely leaves the risk register on its own, even after the underlying situation has long since changed. A label is simply easier to apply than it is to challenge again.
This is exactly why the scoring criteria from step 3 are so important. Define for the entire group what "high" means in terms of frequency and damage category before the scoring begins. If you don't, the risk analysis will ultimately measure the risk perception of whoever happened to be at the table, rather than the risk itself.
Quantifying risk analysis with the FAIR method
The FAIR method (Factor Analysis of Information Risk) is an internationally recognized method for quantifying cyber risks. The core formula: risk is the result of threat frequency, vulnerability, and impact. Threat frequency and vulnerability together determine the Loss Event Frequency, how often a loss is expected to occur. The Loss Magnitude adds up direct losses (recovery, downtime) and indirect losses (fines, liability).
FAIR does not work with a single seemingly exact number, but makes uncertainty explicit. Inputs are based where possible on internal incident data, external sources, and historical information, supplemented by substantiated expert estimates when data is lacking. By simulating scenarios multiple times using Monte Carlo simulations, a distribution of possible outcomes is created instead of a single point estimate.
Gartner recognizes that quantification improves communication with executives, PwC sees clear business value in it, and the World Economic Forum calls it a way to transform cybersecurity from a cost center into a growth enabler. This addresses what most practical risk analyses are missing: not the identification of risks, but the translation into a monetary figure that a board member can use to make a decision.
If you would like to have your own risks quantified in this way, read on about the Cyber Risk Assessment, a 4 to 8-week process that identifies cyber risks and translates them into euros, or about Cyber Economics, a 2 to 4-week process for targeted quantification regarding a single strategic decision, such as a cloud migration, acquisition, or insurance choice. Both processes follow the same four phases: intake, data collection, analysis, and a board-ready report. Read more here about how Polar Risk uses FAIR.
Risk analysis and ISO 27001
After defining the scope, ISO 27001 mandates a risk analysis as the starting point for an ISMS: only based on the outcome do you choose which control measures from Annex A are actually necessary, as documented in the Statement of Applicability. Without a risk analysis, that choice cannot be justified to a certification body, and that is typically the first thing auditors ask for during a certification audit.
The standard itself does not prescribe a specific method. An ISO 27001 risk analysis may be qualitative, using a risk matrix for example, as long as the scoring criteria are established in advance and applied consistently. For organizations that also need to translate the outcome into euros for the board—for instance, when making an investment decision regarding a new security measure—the quantitative variant using FAIR is the addition that the standard does not enforce, but practice demands.
Risk analysis and the Cyber Security Act (NIS2/Cbw)
The Cyber Security Act, which came into effect on August 15, 2026, requires organizations in 18 sectors to analyze cyber risks and take appropriate and proportionate measures based on those findings, with board approval and attention to supply chain risks. More about the full requirements can be found on the page about NIS2/Cbw.
The Cybersecurity Act does not prescribe a specific method for risk analysis. However, organizations must be able to demonstrate that their measures are appropriate for the risks and proportionate to the potential consequences. A qualitative or semi-quantitative analysis can provide a useful basis for this. For major investment decisions, financial risk quantification can strengthen the justification, as it allows executives to compare risk, the cost of measures, and residual risk within the same financial context.
Frequently asked questions about risk analysis
What is a risk analysis?
A risk analysis is the step in which you determine the likelihood of a risk occurring and what the consequences would be. This is done either qualitatively, using labels such as high or low, or quantitatively, using a percentage and an expected financial loss.
What is the difference between a qualitative and a quantitative risk analysis?
A qualitative risk analysis uses labels such as low, medium, and high. A quantitative risk analysis calculates probability and impact into an annual percentage and an expected loss amount, using a range rather than a single figure.
What are the steps of a risk analysis?
The five steps are: determine what you want to protect, map out the threats for each asset, estimate the probability, estimate the impact, and assign measures and an owner to each risk based on those findings. Reassess risks periodically and whenever relevant circumstances change.
What is the difference between risk analysis and risk management?
Risk analysis is the step where you estimate the probability and impact of each risk. Risk management is the entire, ongoing process surrounding it: identifying, analyzing, selecting measures, and monitoring.
Is a risk analysis mandatory under NIS2/CBW?
Yes, for organizations in the 18 sectors covered by the Cybersecurity Act. The law, which comes into effect on August 15, 2026, requires a risk analysis as the basis for appropriate and proportionate measures that have received management approval.
How often should you repeat a risk analysis?
At least annually, and immediately following any major change: a new system, a reorganization, an acquisition, or an incident. Both threats and the organization itself are constantly changing, and a two-year-old risk analysis says little about today's situation.






