"Risk you haven't assessed is risk you've accepted by default."
Impact and Consequence Analysis
Professor Sele: A risk with low likelihood but catastrophic consequences demands a different response than a risk with high likelihood but minor impact. Impact analysis gives you the language and the framework to make that distinction — and communicate it to the people who need to act on it.
Section 1 — Dimensions of Impact
When a security risk materialises, the consequences can affect four dimensions simultaneously: Human (injuries, deaths, psychological harm, staff turnover); Operational (disruption to normal business activities, loss of productivity, supply chain impact); Financial (direct losses such as theft and property damage, plus indirect losses such as business interruption, legal costs, and increased insurance premiums); and Reputational (damage to the client's public reputation, loss of client trust, media coverage).
The ESRA must assess impact across all four dimensions — a threat that causes no physical injury may still be catastrophic if it destroys the client's reputation or triggers a regulatory investigation.
Section 2 — Impact Rating Scale
A consistent impact rating scale lets you compare across categories. Catastrophic and Major are colour-coded so reviewers can see severity at a glance.
| Rating | Human | Operational | Financial | Reputational |
|---|---|---|---|---|
| 1 — Negligible | Minor injury, no medical treatment | Minimal disruption | < $1,000 loss | No external awareness |
| 2 — Minor | Medical treatment required | Hours of disruption | $1,000–$10,000 | Local awareness only |
| 3 — Moderate | Hospitalisation | Days of disruption | $10,000–$100,000 | Regional media coverage |
| 4 — Major | Serious injury or death | Weeks of disruption | $100,000–$1M | National media coverage |
| 5 — Catastrophic | Multiple deaths | Operations cease | > $1M | International coverage, regulatory action |
Section 3 — Likelihood Rating Scale
Likelihood is rated on a parallel 1–5 scale so it can be combined with impact to produce a single, comparable risk score.
| Rating | Description | Frequency Indicator |
|---|---|---|
| 1 — Rare | Could happen but hasn't in 5+ years | Less than once every 5 years |
| 2 — Unlikely | Has happened once or twice historically | Once every 2–5 years |
| 3 — Possible | Has happened and could happen again | Once per year |
| 4 — Likely | Happens regularly in similar environments | Several times per year |
| 5 — Almost Certain | Expected to occur regularly | Monthly or more |
Section 4 — Calculating the Risk Score
Risk Score = Likelihood Rating × Impact Rating. A score of 15–25 = Critical Risk; 9–14 = High Risk; 4–8 = Medium Risk; 1–3 = Low Risk.
This produces a risk score that is consistent, defensible, and comparable across different risk categories — enabling the team to rank risks objectively rather than by instinct.
- •Impact must be assessed across all four dimensions: human, operational, financial, reputational
- •Use consistent rating scales for both likelihood and impact to enable objective comparison
- •Risk Score = Likelihood × Impact; scores from 1–25 map to Low/Medium/High/Critical
- •A low-likelihood but catastrophic-impact risk may rank higher than a frequent low-impact risk
- •Consistent rating methodology makes the risk register defensible in legal or audit contexts
"A client initially dismissed a risk I'd rated Critical because they said: 'That has never happened here.' I walked them through the impact analysis. If that specific risk materialised: three likely fatalities, operations suspended for 30 days minimum, $800,000 in direct costs, and international media coverage given the nature of the business. Likelihood 2 out of 5. Impact 5 out of 5. Risk score: 10 — High Risk. That conversation changed from 'it's never happened' to 'what do we do first?' Impact analysis turns gut feelings into decisions."
What is "impact analysis" in an ESRA?