Skip to content
atlas

Don't confuse these

Risk vs Threat

Why they differ

A threat is what could happen; risk also weighs how likely it is and how much it would hurt.

Risk

Fundamentals

How likely it is that a threat uses a vulnerability, combined with how bad the damage would be.

Formal

A measure of possible harm that combines the likelihood of a threat using a vulnerability with the impact on the organisation if it does. Once rated, each risk is treated - reduced, transferred, avoided or accepted.

In plain English

Like deciding whether to insure a bike - you weigh how often bikes get stolen round here against how much a new one would cost.

In practice

The IT security team of a Danish municipality rates “ransomware on the file server” as likely and severe, so it lands in the red corner of the heat map and gets budget first.

Why it matters

Money and time are limited; thinking in risk lets an organisation spend them on what could really hurt, not on whatever sounds scariest.

Threat

Fundamentals

Anything that could harm the organisation - an attacker, a careless mistake, a fire or a power cut.

Formal

Any person, event or circumstance with the potential to cause harm to information or systems by damaging their confidentiality, integrity or availability. A threat does harm only when it meets a weakness it can use.

In plain English

Like a burglar in the neighbourhood or a storm in the forecast - it has not hurt you yet, but it could.

In practice

A Danish shipping company lists its threats - criminal groups sending phishing mails, staff mistakes, a supplier's remote access and flooding of the basement server room.

Why it matters

You cannot guard against what you have not named; knowing the threats tells you what to prepare for and what to ignore.

Shared connections

Atlas is in beta.