CYBERSECURITY

Cybersecurity risk matrix.

A cybersecurity risk matrix compares threats using two simple measures: how likely they are and how much harm they could cause. It helps a team turn a long risk register into a focused conversation about priorities. List concrete scenarios, such as ransomware or an exposed service, rather than vague labels like security risk. Agree on the scoring definitions before placing any item, since different people can interpret likelihood and impact differently. The matrix should lead to action: a control, an owner, and a review date for the highest risks. Update it after material system, supplier, or threat changes, or after a significant incident.

UPDATED 2026-09-24
TYPEMatrix
EXAMPLECybersecurity risk matrix.
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

A security team needs to decide which threats to address first.

Key decisions

  • Set scales: Define impact and likelihood before plotting risks.
  • Rank treatment: Address the risks in the high-impact, likely area first.
  • Assign owners: Give every priority risk a mitigation owner.

When to reuse this

Use this for a short, reviewable list of risks rather than a full threat model.

FAQ

Frequently asked questions

What is a cybersecurity risk matrix?01
It plots security scenarios by likelihood and potential impact.
Which risks should be treated first?02
Start with risks that are both likely and high impact.
Is a risk matrix a threat model?03
No. It prioritizes risks; a threat model analyzes attack paths and controls in more detail.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.