Lessons · Cybersecurity · threat, vulnerability and risk
Threat, vulnerability, risk: three words that are not the same
A threat is something that could do harm, a vulnerability is a weakness it could use, and risk is how likely the harm is and how bad it would be, together.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
A director asks 'are we at risk from ransomware?' and the honest answer needs all three: yes it exists (threat), here is the unpatched server it could reach (vulnerability), and here is how likely and how costly (risk). Mixing them up is how budgets go to the wrong thing.
How to think about it
Name the threat as an actor or event. Name the vulnerability as a weakness you own. Then risk is the pair, measured: likelihood and impact.
Worked example
Threat: a criminal group that sends ransomware by emailOutside your control. It exists whether or not you have a weakness.
Vulnerability: a file server missing four months of patchesInside your control. It is the door the threat could use.
Risk: likely this year, and it would stop the warehouse for two daysThe threat meeting the vulnerability, weighed by chance and cost.
Remove the vulnerability and the risk drops; the threat staysYou patch the server. The criminals are still out there; they just have no door.
Your turn
A laptop has no disk encryption. Which of the three words is that?
no disk encryption is a
Solve one, graded on the server
The trap
Saying 'the risk is phishing'. Phishing is a threat. The risk is what phishing could cost you, given the weaknesses you have.