Professor Sele
Lead Risk Assessment Specialist | SafeHaven Strategies

"Risk you haven't assessed is risk you've accepted by default."

Module 4

Impact and Consequence Analysis

Professor Sele: A risk with low likelihood but catastrophic consequences demands a different response than a risk with high likelihood but minor impact. Impact analysis gives you the language and the framework to make that distinction — and communicate it to the people who need to act on it.

Section 1 — Dimensions of Impact

When a security risk materialises, the consequences can affect four dimensions simultaneously: Human (injuries, deaths, psychological harm, staff turnover); Operational (disruption to normal business activities, loss of productivity, supply chain impact); Financial (direct losses such as theft and property damage, plus indirect losses such as business interruption, legal costs, and increased insurance premiums); and Reputational (damage to the client's public reputation, loss of client trust, media coverage).

The ESRA must assess impact across all four dimensions — a threat that causes no physical injury may still be catastrophic if it destroys the client's reputation or triggers a regulatory investigation.

Section 2 — Impact Rating Scale

A consistent impact rating scale lets you compare across categories. Catastrophic and Major are colour-coded so reviewers can see severity at a glance.

RatingHumanOperationalFinancialReputational
1 — NegligibleMinor injury, no medical treatmentMinimal disruption< $1,000 lossNo external awareness
2 — MinorMedical treatment requiredHours of disruption$1,000–$10,000Local awareness only
3 — ModerateHospitalisationDays of disruption$10,000–$100,000Regional media coverage
4 — MajorSerious injury or deathWeeks of disruption$100,000–$1MNational media coverage
5 — CatastrophicMultiple deathsOperations cease> $1MInternational coverage, regulatory action

Section 3 — Likelihood Rating Scale

Likelihood is rated on a parallel 1–5 scale so it can be combined with impact to produce a single, comparable risk score.

RatingDescriptionFrequency Indicator
1 — RareCould happen but hasn't in 5+ yearsLess than once every 5 years
2 — UnlikelyHas happened once or twice historicallyOnce every 2–5 years
3 — PossibleHas happened and could happen againOnce per year
4 — LikelyHappens regularly in similar environmentsSeveral times per year
5 — Almost CertainExpected to occur regularlyMonthly or more

Section 4 — Calculating the Risk Score

Risk Score = Likelihood Rating × Impact Rating. A score of 15–25 = Critical Risk; 9–14 = High Risk; 4–8 = Medium Risk; 1–3 = Low Risk.

This produces a risk score that is consistent, defensible, and comparable across different risk categories — enabling the team to rank risks objectively rather than by instinct.

Key Points
  • Impact must be assessed across all four dimensions: human, operational, financial, reputational
  • Use consistent rating scales for both likelihood and impact to enable objective comparison
  • Risk Score = Likelihood × Impact; scores from 1–25 map to Low/Medium/High/Critical
  • A low-likelihood but catastrophic-impact risk may rank higher than a frequent low-impact risk
  • Consistent rating methodology makes the risk register defensible in legal or audit contexts
Field Note · Professor Sele

"A client initially dismissed a risk I'd rated Critical because they said: 'That has never happened here.' I walked them through the impact analysis. If that specific risk materialised: three likely fatalities, operations suspended for 30 days minimum, $800,000 in direct costs, and international media coverage given the nature of the business. Likelihood 2 out of 5. Impact 5 out of 5. Risk score: 10 — High Risk. That conversation changed from 'it's never happened' to 'what do we do first?' Impact analysis turns gut feelings into decisions."

Knowledge Check

What is "impact analysis" in an ESRA?