Risk Matrix: What It Is and Why It Falls Short for Cyber

A risk matrix plots risks against probability and impact. Read how to set one up and why cyber risks require more than just a colored box.
Paul Permentier
Co-Founder
8
Min reading
Table of contents

Risk matrix: what it is, how to build one and why it falls short for cyber risk

A risk matrix is a table in which you plot risks against likelihood and impact. One axis shows how likely a risk is, the other how large the loss would be if the risk occurred. Where the two axes intersect, you set the priority: low, medium, high or critical.

What is a risk matrix?

A risk matrix, also known as a risk assessment matrix or a probability and impact matrix, is a grid with likelihood on one axis and impact on the other. The most commonly used version is 5x5: five levels for likelihood, five for impact, 25 boxes in total. Each risk is scored on both axes and lands in a single box. That box gets a colour, from green for low risk to red for critical.

The method rests on the same premise as the international risk management standard ISO 31000: risk is a function of likelihood and impact. A risk matrix makes that premise visual and quick to use, without any calculation.

‍

‍

Why do organisations use a risk matrix?

A risk matrix provides an overview of dozens of risks side-by-side at a glance. That overview is exactly why the matrix is so frequently used in quality management, audits and compliance: it forces you to assess risks on the same two dimensions, rather than on gut feeling or whoever shouts the loudest for attention.

For cyber risk specifically, there is an additional legal reason. The Cyber Security Act (NIS2) requires organisations in 18 sectors to analyse cyber risks and take appropriate, proportionate measures with management approval. A risk matrix is a tool often used during the analysis. The NCSC therefore advises risk management as the foundation of every cybersecurity policy.

‍

Building a risk matrix in four steps

‍

Step 1: Identify risk scenarios.

A risk can only be scored if it is described clearly enough. A scenario requires four elements: a threat, an asset, a method by which the threat occurs, and an impact on the organisation. "Ransomware" is not a scenario. "Ransomware on the production environment via a phishing email, resulting in production downtime" is. If you prefer not to start from scratch, you can use the free scenario builder from Polar Risk to create scenarios according to this structure.

Step 2: Define your scales for likelihood and impact.

Establish in advance what "high" means on each axis, for example in terms of frequency (once a year, once every ten years) and damage category (production loss, reputational damage, fines). Without these definitions, everyone will score differently.

Step 3: Score the risks with a broad group.

One person can never oversee all risks. An IT manager sees different risks than an operations manager or a CFO. Therefore, score them together, not just from within the security department.

Step 4: Link measures and keep the matrix alive.

A score without follow-up action is just a paperwork exercise. Every risk in the red box needs an owner and a measure with a deadline. Repeat the exercise at least annually, as both threats and the organization are constantly changing.

‍

Example of a risk matrix

A simplified example of a 5x5 matrix, with impact on the vertical axis and likelihood on the horizontal axis:

‍

A ransomware scenario in the production environment would, for example, land on "Major" (impact) and "Medium" (likelihood): a High score. That specific word, "High," is where things often go wrong with cyber risks. More on that in the next two sections.

‍

Why a risk matrix often falls short for cyber risks

The ransomware scenario from the previous section can be made concrete. In the production environment, it has an annual probability of 13% and an expected downtime of approximately 14 days. Calculated out, the financial impact is about €2.4 million, with a range of €0.4 million to €7.1 million, depending on how quickly recovery succeeds and how much revenue is lost.

Another risk that happens to also score as "High" might actually result in a tenth of that amount in damages. The matrix treats them identically. For a boardroom discussion about budget, that is insufficient justification.

‍

From risk matrix to concrete figures: quantifying with FAIR

The FAIR method (Factor Analysis of Information Risk) is an internationally recognized method for quantifying cyber risks. With this method, you can calculate cyber risks based on objective data and express them in numbers. The result is not a color in a box, but an expected loss amount with a range, as in the ransomware example above.

Risk quantification is a specialized skill. It requires the same scenario structure as step 1 of the matrix (threat, asset, method, effect), but calculated with data instead of an estimate on a scale of one to five. More about the method can be found on the page about the FAIR methodology. If you want to quantify your own risks, read more about the Cyber Risk Assessment or, for a specific decision such as a cloud migration or acquisition, about Cyber Economics.

In 2024, 22% of Dutch organizations already suffered significant damage from a cyberattack (CBS, 2024), and the number of digital connections has tripled since 2019 (ENISA, 2024). The question, therefore, is not whether this "High" scoring risk will be on the list again next year, but what it will cost if things go wrong.

‍

Frequently asked questions about the risk matrix

What is a risk matrix?

A risk matrix is a table in which you plot risks against probability and impact, usually using five levels per axis. The point where probability and impact intersect determines the priority of the risk: low, medium, high, or critical.

What are the pros and cons of a risk matrix?

The advantage is speed: in an hour, you can have an overview of dozens of risks side by side. The disadvantage is that the scores are subjective and two risks with the same label can represent very different amounts of potential damage.

Which scale should you use for a risk matrix, 3x3 or 5x5?

5x5 is the most commonly used scale because it provides enough distinction between risks without overcomplicating the discussion. 3x3 works for a quick initial inventory, but often forces risks with very different impacts into the same category.

Is a risk matrix mandatory under NIS2/CBW?

The Cyber Security Act itself does not mandate a risk matrix. The law, which comes into effect on August 15, 2026, does require organizations to analyze cyber risks and take appropriate, proportionate measures with management approval. More information on the requirements can be found on the [NIS2/CBW](https://polarrisk.com/use-cases/nis2) page. A matrix can assist with the analysis, but without financial substantiation in euros, it does not meet the requirement to justify measures.

Is a risk matrix suitable for cyber risks?

It is suitable for an initial overview. It is not suitable for making decisions about budgets or measures, because the matrix does not provide a monetary value and therefore does not answer the question of whether an investment will pay for itself.

What is the difference between a risk matrix and quantitative risk analysis?

A risk matrix uses labels like high, medium, and low. Quantitative risk analysis, such as the FAIR method, calculates probability and impact into a monetary value with a range, allowing risks to be compared fairly against one another.

‍

Want to know the actual cost of your "High" scoring risks? Talk to an expert.

‍

‍

‍

Stay up to date

Sign up for the newsletter and receive our latest insights on cyber risk quantification.

By subscribing you agree to our privacy statement
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.