← Articles
RIPOSTE research · 2026

Cyber Risk = Threat × Vulnerability: How Risk Is Actually Assessed

Here is the single most useful idea in cyber security, and the one most often skipped: a vulnerability is not a risk. A scanner that hands you two hundred “vulnerabilities” has not told you your risk — it has told you two hundred things that might, or might not, matter. Working out which is the whole discipline, and it comes down to a simple relationship: risk is the product of threat and vulnerability.

A vulnerability is not a risk

A vulnerability is a weakness — an unpatched service, a weak configuration, an exposed login. On its own it is potential energy, not risk. A weakness no realistic attacker can reach, or would ever bother with, carries little real risk however alarming it looks in a scan; a modest weakness on your most exposed, most attractive system can carry a great deal. Treating every weakness as equally urgent is how organisations exhaust themselves fixing the wrong things while the real exposure sits untouched.

The two halves: threat and vulnerability

Risk lives at the meeting point of two questions. The vulnerability question: what weaknesses exist, and where? The threat question: who would want to exploit them, do they have the capability, and would they realistically try? Neither half is a risk by itself. A serious weakness with no credible threat against it, and a determined threat with no weakness to exploit, are both low risk. Risk is what you get when a real weakness meets a real, capable, motivated adversary.

Why a scanner only sees half the picture

An automated scanner is a vulnerability-finding machine, and a useful one — but it knows nothing about the threat half of the equation: who is actually operating against organisations like yours, what they are capable of, and what they are doing now. So it cannot tell a critical risk from a theoretical one; it grades weaknesses in isolation, by generic severity, not by whether they matter to you. That is why a raw scan is a to-do list without priorities, and why a human — with real threat intelligence — has to finish the job.

Likelihood and consequence, stated honestly

Assessing risk well means being honest about uncertainty. Two things drive it: how likely a weakness is to be exploited, and how bad it would be if it were. Good assessment expresses likelihood in calibrated language — from highly likely to unlikely, with a stated confidence — rather than false-precision scores or a blunt “critical.” It is the discipline of intelligence work: say what you assess, how strongly, and why, so a decision-maker can weigh it. “Assessed as likely to be exploited, with high confidence, because…” is worth far more than a red dot.

Bringing the halves together

The assessment that actually helps you is the one that fuses both halves: your specific weaknesses, read against the current, real-world threat picture for an organisation like yours. That fusion is what turns a finding into a risk — a judgement about whether, in your context, an adversary with the capability and the intent would realistically make this weakness count. It is also what lets you prioritise: fix the handful of things that are genuinely risky first, and treat the rest in proportion.

What this means for you

Do not measure a security assessment by how many findings it produces; measure it by how well it tells you which ones matter, and why. A short, prioritised list you can act on is worth more than a hundred-page catalogue nobody reads. And be wary of any tool or report that grades your weaknesses with no account of the threat against you — it is doing half the equation and calling it an answer.

How RIPOSTE assesses risk

This is the principle every one of our systems is built on. ForgeScore reads an organisation's exposure and expresses it as a calibrated, defensible risk judgement rather than a black-box number, and DarkRose keeps that judgement tied to the live threat picture — so a finding is only ever called a risk when a real adversary could realistically make it one. Information in, assessment out: your vulnerabilities, weighed against the threat that is genuinely yours.

Sources

  1. ISO 31000 — Risk management (International Organization for Standardization)
  2. ASD's ACSC Annual Cyber Threat Report 2024–25 (cyber.gov.au)
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us