Skip to content
atlas

Risk identification

The first step of a risk assessment - finding and writing down what could go wrong, to what, and why.

Draft - this entry has not been reviewed yet.

Formal

The part of risk assessment that finds, recognises and describes risks by listing the assets that matter, the threats that could harm them and the vulnerabilities those threats could use, before any rating is done.

In plain English

Like walking through a new flat before moving in and noting every loose wire, wobbly step and window that does not close - fixing comes later.

In practice

At a two-hour meeting in a brewery, staff from production, finance and IT write down their key systems and data and what could hit each one, from ransomware to a fire in the server room.

Why it matters

A risk that is never named is never handled, so the quality of the whole risk process depends on how wide this first search is.

Technical deep dive

ISO 31000:2018 clause 6.4.2 describes risk identification as finding, recognising and describing risks, and asks the organisation to consider, among other things, tangible and intangible risk sources, causes and events, threats and opportunities, vulnerabilities and capabilities, changes in context, emerging risks and the limits of its own knowledge. ISO/IEC 27005:2022 clause 7.2 narrows this to information security: risks associated with loss of confidentiality, integrity and availability are identified either through an event-based approach, starting from risk sources and high-level scenarios, or through an asset-based approach enumerating assets, threats and vulnerabilities in detail. The 2022 edition also introduced the term risk scenario, a sequence or combination of events leading from the initial cause to the unwanted consequence, in place of the older incident scenario.

The unit of output is a risk statement precise enough to be analysed. A usable pattern names the risk source or threat, the vulnerability or condition exploited, the affected asset and the business consequence, for example: a ransomware group exploits an unpatched VPN appliance, encrypts the ERP system and halts order handling. Statements such as "cyber attack" or "GDPR" are categories, not risks; they cannot be scored because they have no defined mechanism or consequence. Each identified risk is recorded in the risk register with an owner, even before analysis.

Coverage depends on sources and technique. Inputs typically include national threat assessments, sector warnings, frameworks such as MITRE ATT&CK, internal incident and near-miss history, audit and penetration-test findings, vulnerability scan results, supplier dependencies and interviews with process owners. ISO/IEC 31010:2019 catalogues techniques from brainstorming and structured interviews to the Delphi method, checklists, SWIFT (structured what-if) and bow-tie analysis. NIST SP 800-30 Rev. 1 Appendix D distinguishes adversarial, accidental, structural and environmental threat sources, a useful check that identification does not stop at attackers; NIS2 Art. 21(2) similarly requires measures based on an all-hazards approach, covering failures, errors and physical events as well as attacks.

The main failure modes are narrow participation, where an IT-only workshop misses process, supplier and people risks; availability bias, where last month's headline dominates; confusing controls that are missing with risks ("no SIEM" is a finding, not a risk); and treating identification as a one-time event instead of repeating it when systems, suppliers or the threat landscape change. Identification deliberately stops before rating, since scoring during brainstorming tends to shut down discussion of unlikely but severe scenarios.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Risk identification

Relationships

Sources & further reading

Standards & official texts

  • ISO 31000:2018 (6.4.2 - Risk identification)

Course material

  • Cyber Security Fast Track - Kursuskompendium, Modul 5

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.