Impact
Also known as: consequence
How much harm an event would do to the business if it actually happened - in money, time, trust or safety.
Draft - this entry has not been reviewed yet.
Formal
The size of the damage to an asset or to the business when a threat succeeds, usually rated on a scale from minor to severe as one of the two parts of risk.
In plain English
Spilling coffee on a napkin and spilling it on your laptop are equally likely - but one hurts far more.
In practice
A Danish water utility rates a day without its control system as severe, because homes may lose clean water, while a broken office printer is rated minor.
Why it matters
Rating the harm lets leaders spend their limited money on protecting what would hurt most to lose.
Technical deep dive
ISO/IEC 27005:2022 uses "consequence" for the outcome of an event affecting objectives, and ISO 31000 treats risk as the combination of likelihood and consequence; "impact" is the more common word in NIST and everyday usage. Impact is assessed per scenario, not per asset in isolation: the same database has a very different impact if it is leaked, silently altered or unavailable for a week. Good methods therefore rate impact separately for confidentiality, integrity and availability, and across several dimensions such as financial loss, operational disruption, legal and regulatory exposure, reputation, and health and safety, taking the worst dimension as the result.
Qualitative scales are the norm. FIPS 199 defines low, moderate and high as limited, serious and severe or catastrophic adverse effects on operations, assets or individuals; most organisations use four- or five-point scales with written anchors, for example "more than 1 % of annual revenue" or "service unavailable to citizens for more than 24 hours". Without such anchors, scores drift between assessors and ordinal numbers get multiplied as if they were measurements, a well-known weakness of heat maps. Quantitative methods such as FAIR instead estimate loss magnitude as a distribution, split into primary loss (response, replacement, lost productivity) and secondary loss (fines, litigation, customer churn), and combine it with loss event frequency by Monte Carlo simulation.
Impact over time is the domain of the business impact analysis in ISO 22301. It establishes for each activity how harm grows with the length of an outage, and derives the maximum tolerable period of disruption (MTPD), from which RTO and RPO are set with a margin. A system with modest impact after an hour may be critical after three days, for example payroll just before pay day.
Regulation turns impact into thresholds. Under GDPR Art. 33 and 34 the test is the risk to the rights and freedoms of natural persons, not to the organisation, so a breach that costs the company nothing can still require notification to Datatilsynet and to data subjects. NIS2 Art. 23(3) defines a significant incident as one that has caused or can cause severe operational disruption or financial loss, or considerable material or non-material damage to others, and Commission Implementing Regulation (EU) 2024/2690 adds quantified criteria for certain digital providers. Impact is independent of likelihood: a rare event with catastrophic impact such as a destructive attack on a water utility may need more treatment than a frequent nuisance, and controls may reduce either factor, for example backups reduce impact while patching reduces likelihood.
What to learn first
Everything this builds on, foundations first.
Relationships
- Part of
- Risk
- Requires
- Asset
- Unlocks
- Business impact analysis (BIA)Qualitative risk analysisQuantitative risk analysisRiskRisk assessmentRisk transfer
- Caused by
- Security incident
- Used with
- Likelihood
Sources & further reading
Standards & official texts
- ISO/IEC 27005 - Information security risk management · ISO
Course material
- Cyber Security Fast Track - Ordliste (Risiko)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…