Fundamentals
How likely it is that a threat uses a vulnerability, combined with how bad the damage would be.
Formal
A measure of possible harm that combines the likelihood of a threat using a vulnerability with the impact on the organisation if it does. Once rated, each risk is treated - reduced, transferred, avoided or accepted.
In plain English
Like deciding whether to insure a bike - you weigh how often bikes get stolen round here against how much a new one would cost.
In practice
The IT security team of a Danish municipality rates “ransomware on the file server” as likely and severe, so it lands in the red corner of the heat map and gets budget first.
Why it matters
Money and time are limited; thinking in risk lets an organisation spend them on what could really hurt, not on whatever sounds scariest.