Risk profile
The overall picture of which dangers an organisation faces and how serious they are, given its size, sector, data and systems.
Draft - this entry has not been reviewed yet.
Formal
A description of the full set of risks an organisation carries at a point in time - shaped by its sector, size, critical assets, the outside services it relies on and its threat landscape - used to decide which controls come first.
In plain English
Like packing for a trip - a week of camping by the sea and a weekend in a city hotel call for very different bags, even for the same traveller.
In practice
A small dental clinic with patient records and one server has a very different profile from a wind turbine maker with factories and suppliers worldwide, so the two start with different CIS Controls.
Why it matters
Copying another organisation's plan wastes money; knowing your own profile lets limited resources go where they matter most.
Technical deep dive
ISO Guide 73:2009 (since replaced by ISO 31073:2022) defines a risk profile simply as a description of any set of risks, which may cover the whole organisation, part of it or some other defined scope. COSO's 2017 enterprise risk management framework gives the concept more structure: a risk profile is a composite view of the type, severity and interdependencies of risks at a given level of the entity, which can be plotted against performance to show how much risk is being taken for a given outcome and compared with appetite and capacity. The essential point is that a profile is a statement of fact about the present, whereas appetite is a statement of intent. The gap between the two is what drives treatment priorities.
A profile is more than the sum of individual register entries. Aggregation exposes concentrations and correlations that individual ratings hide: several medium risks that all depend on one identity provider, one managed service provider or one cloud region can together represent a single severe scenario. Useful profiles therefore show dependency concentration, top scenarios by expected and tail loss, the distribution of residual ratings, and trends since the previous period, not just a count of red and amber cells.
The external drivers are sector, size, geography, regulatory status, public visibility and the value of the organisation's data or services to attackers. Sector matters because threat actors specialise: state-linked espionage concentrates on government, defence, research and critical infrastructure, while financially motivated ransomware is largely opportunistic and hits whatever is exposed. NIS2 Art. 21(1) builds this into law by requiring proportionality to take account of the entity's degree of exposure to risk, its size and the likelihood and severity of incidents, including their societal and economic impact. Cyber insurers construct a comparable external profile during underwriting from questionnaires and scans of internet-facing assets.
The profile determines which baseline makes sense. CIS Controls v8 encodes this through Implementation Groups: IG1 is a set of 56 safeguards described as essential cyber hygiene for organisations with limited IT resources, and IG2 and IG3 add safeguards for organisations with more complex environments, higher sensitivity data or targeted threats, up to all 153 in IG3. The term should not be confused with Organizational Profiles in NIST CSF 2.0, which describe current and target states of cybersecurity outcomes rather than a set of risks, although a CSF target profile is usually derived from the risk profile.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk assessment
- →Risk profile
Relationships
- Requires
- Risk assessment
- Don't confuse with
- Risk appetite
- Used with
- Threat landscapeCIS Controls
Sources & further reading
Standards & official texts
- NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 4
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…