Skip to content
atlas

Risk heat map

Also known as: heat map, risk matrix

A colour-coded grid that places each risk by how likely and how harmful it is, so the worst stand out in red.

Draft - this entry has not been reviewed yet.

Formal

A chart with chance of happening along one side and size of harm along the other, where each risk is placed and the cells are coloured from green to red by overall level.

In plain English

Like a traffic light for dangers, showing at a glance which ones need action now and which can wait.

In practice

At a pension fund's board meeting, the head of security shows a heat map where phishing sits in the red corner and a flooded server room sits in yellow.

Why it matters

Managers rarely read long risk lists, but a single picture lets them agree quickly on where to spend.

Technical deep dive

A risk heat map is the visual form of the consequence/likelihood matrix described in ISO/IEC 31010:2019 as a risk assessment technique. Typical layouts are 3×3, 4×4 or 5×5, with each axis level defined by anchored descriptors: likelihood as frequency bands ("less than once in ten years", "several times a year") and consequence as thresholds per impact type (money lost, hours of outage, number of records exposed, regulatory action). The colour of each cell is a policy decision, not a calculation; it encodes the risk criteria and should line up with the documented risk appetite, so that "red" means the same thing as "outside appetite, treatment required". NIST SP 800-30 Rev. 1 Appendix I gives an example of such a lookup from likelihood and impact levels to an overall risk level.

The most common implementation multiplies ordinal scores, likelihood 1-5 times impact 1-5. This treats ordinal labels as ratio numbers, which they are not: the gap between "rare" and "unlikely" is not the same as between "likely" and "almost certain". The product also has only 14 distinct values between 1 and 25, and identical scores hide very different profiles: a 5×1 nuisance and a 1×5 catastrophe both score 5. Many organisations therefore use asymmetric matrices where high-impact columns turn red at lower likelihood, or define cell colours directly instead of from products.

Louis Anthony Cox Jr.'s paper "What's Wrong with Risk Matrices?" (Risk Analysis, 2008) formalised the limits: range compression puts quantitatively very different risks in the same cell, cell boundaries can rank a smaller risk above a larger one, and when frequency and severity are negatively correlated a matrix can do worse than random prioritisation. Placement is also subjective, so two assessors routinely put the same scenario in different cells. A heat map therefore supports discussion and triage but does not compute risk, and it cannot aggregate: ten yellow risks sharing one dependency may be worse than a single red one.

Good practice is to plot each risk twice, inherent and residual, with an arrow showing the effect of treatment; to show trend since the previous report; to keep a written rationale behind every placement; and to switch to quantitative analysis for the few risks where a large investment decision depends on the ranking.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Risk heat map

Relationships

Requires
Risk

Sources & further reading

Standards & official texts

  • ISO/IEC 27005:2022

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.