Skip to main content

Security Risk

Connect a credible threat, likelihood, consequence, uncertainty, and stakeholder impact to an explicit risk decision.

Risk is a decision input

Security risk connects uncertainty about a harmful event to its effect on stakeholders and objectives. A useful assessment states the threat, affected assets, likelihood basis, potential impact, uncertainty, existing controls, and residual risk. A color or score without this basis hides the decision.

Estimate with evidence

Use available evidence: exposure, attacker capability, observed events, control tests, dependency history, recovery time, and consequence analysis. Separate likelihood from impact. State ranges or confidence when precise values are not supported.

Choose a treatment

A decision can avoid the activity, reduce likelihood or impact, transfer part of the consequence, or accept the residual risk. Name the owner, due date, monitoring signal, and trigger for review. Acceptance is an active decision, not an empty backlog item.

Failure and residual risk

Risk registers can become detached from system models and current controls. Relative scores can create false precision. Rare events can still need strong treatment when the impact is severe or recovery is poor. A control can shift risk to availability, privacy, or operations.

Pomerium boundary

Pomerium can change the likelihood or impact of unauthorized route access when it is correctly placed and operated. It does not decide the organization's risk tolerance. Assess direct upstream access, identity-source error, application authorization, service outages, logging exposure, and recovery as separate contributors.

Evaluation checklist

  • Is the risk tied to a credible threat and stakeholder impact?
  • Is the likelihood basis visible and separate from impact?
  • Are uncertainty and control assumptions recorded?
  • Does the treatment have an owner and review trigger?
  • Has residual risk been assessed after the control, not before it?

Sources and further reading

Keep learning

Security Engineering Foundations

Security Properties

Distinguish confidentiality, integrity, availability, authenticity, accountability, and privacy in a system claim.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo