Cybersecurity risk matrix.
A cybersecurity risk matrix compares threats using two simple measures: how likely they are and how much harm they could cause. It helps a team turn a long risk register into a focused conversation about priorities. List concrete scenarios, such as ransomware or an exposed service, rather than vague labels like security risk. Agree on the scoring definitions before placing any item, since different people can interpret likelihood and impact differently. The matrix should lead to action: a control, an owner, and a review date for the highest risks. Update it after material system, supplier, or threat changes, or after a significant incident.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
A security team needs to decide which threats to address first.
Key decisions
- Set scales: Define impact and likelihood before plotting risks.
- Rank treatment: Address the risks in the high-impact, likely area first.
- Assign owners: Give every priority risk a mitigation owner.
When to reuse this
Use this for a short, reviewable list of risks rather than a full threat model.
Frequently asked questions
What is a cybersecurity risk matrix?
Which risks should be treated first?
Is a risk matrix a threat model?
More cybersecurity examples
Try the diagram makers.
Tweak it with chat, export PNG/SVG, or fork it for your own use case.