Security Risk Assessment & Risk Decision
Security Risk Assessment defines the process of evaluating vulnerability, determining Likelihood and Impact, calculating Risk, and producing decision-ready outputs that support Acceptable Risk decisions. Risk is derived from validated threat scenarios (Layer 2) and assessed through Prevention Vulnerability (Likelihood driver) and Mitigation Vulnerability (Impact…

- Delivery
- Online
- Duration
- Self-paced online
- Assessment
- Scenario-based assessment
- Course application
- Apply for this course
What you will learn and demonstrate.
Course Overview
Security Risk Assessment defines the process of evaluating vulnerability, determining Likelihood and Impact, calculating Risk, and producing decision-ready outputs that support Acceptable Risk decisions.
Risk is derived from validated threat scenarios (Layer 2) and assessed through Prevention Vulnerability (Likelihood driver) and Mitigation Vulnerability (Impact driver). Likelihood and Impact are determined using structured, traceable methodology supported by evidence and consistency checks.
Risk outputs define current and projected risk levels and support prioritization, resource allocation, and operational decision-making. Residual Risk is evaluated in relation to activity criticality to support Acceptable Risk decisions.
All outputs must remain evidence-based, consistent, and traceable, ensuring that risk assessments are defensible and aligned with SMART, Operational Security Planning (OSP), and Security & Crisis Management (SSCM).
Capability Development Chain
Threat Scenario → Prevention Vulnerability → Likelihood → Mitigation Vulnerability → Impact → Risk Level → Residual Risk → Acceptable Risk Decision
Participants shall
assess vulnerabilities separately (no retrofitting)
determine Likelihood using threat + prevention gaps
determine Impact using personnel, operations, mitigation gaps
calculate risk using structured matrix
validate outputs through consistency checks
define residual risk after measures
support leadership decisions through Acceptable Risk
Key Concepts
- Define Security Risk Assessment as evaluation of vulnerability, Likelihood, Impact, and Risk to support decision-making
- Apply the risk relationship by linking threat scenario, vulnerability, Likelihood, Impact, and Risk output
- Assess Likelihood using threat conditions and Prevention Vulnerability
- Assess Impact using personnel, operational exposure, and Mitigation Vulnerability
- Differentiate Prevention Measures (reduce likelihood) and Mitigation Measures (reduce impact)
- Conduct Prevention and Mitigation Vulnerability Assessments separately, without retrofitting results
- Apply validity checks to verify consistency, realism, and logical alignment across assessments
- Identify and control cognitive bias, overestimation, and unsupported assumptions in risk evaluation
- Identify and evaluate existing security measures and determine their effectiveness against defined scenarios
- Calculate and prioritize risks using structured Risk Matrix outputs and operational relevance
- Define Residual Risk based on implemented measures and realistic reduction assumptions
- Apply the Acceptable Risk Model to align Residual Risk with activity criticality
- Distinguish between Security responsibility (risk assessment) and Leadership responsibility (risk acceptance decisions)
- Support decision-making through structured, evidence-based, and traceable risk outputs
- Ensure all assessments follow the SMART chain from threat scenario to decision output
MODULE 1: VULNERABILITY ASSESSMENT (FOUNDATION)+
Purpose
Define exposure by identifying weaknesses in prevention and mitigation layers.
Learning Outcomes
identify existing prevention measures
identify existing mitigation measures
evaluate effectiveness of measures using scale
determine gaps in prevention (likelihood driver)
determine gaps in mitigation (impact driver)
justify ratings using evidence
Key Exercises
map current measures to threat scenario
identify prevention gaps using penetration logic
identify mitigation gaps using “what happens after event” logic
MODULE 2: PREVENTION VULNERABILITY (LIKELIHOOD DRIVER)+
Purpose
Determine ability to prevent threat realization.
Learning Outcomes
assess effectiveness of prevention measures
assign prevention vulnerability score
identify failure points in layered defence
verify alignment with threat scenario
justify rating using observed gaps
Key Exercises
simulate threat penetration through current system
identify weakest layer in defence
assign prevention vulnerability score with justification
MODULE 3: LIKELIHOOD DETERMINATION+
Purpose
Determine probability of event occurrence.
Learning Outcomes
combine threat assessment (Layer 2) with prevention vulnerability
determine likelihood rating
identify cases where low history ≠ low likelihood
detect bias and inflated assessments
justify likelihood using evidence and context
Key Exercises
calculate likelihood for multiple scenarios
compare likelihood across events
correct unrealistic likelihood ratings
MODULE 4: IMPACT COMPONENT ANALYSIS+
Purpose
Determine consequence of event if realized.
Learning Outcomes
assess effect on personnel
assess effect on operations/assets
evaluate intended effect of threat actor
differentiate operational vs reputational impact
justify ratings based on scenario
Key Exercises
assign personnel impact scores
assign operational impact scores
validate intended effect vs realistic outcome
MODULE 5: MITIGATION VULNERABILITY (IMPACT DRIVER)+
Purpose
Determine ability to reduce consequences after event.
Learning Outcomes
identify mitigation measures in place
evaluate effectiveness of response capability
assign mitigation vulnerability score
identify gaps in response, recovery, continuity
justify rating using evidence
Key Exercises
simulate post-event response
identify delays, failures, gaps
assign mitigation vulnerability score
MODULE 6: IMPACT DETERMINATION+
Purpose
Produce final impact rating.
Learning Outcomes
combine personnel impact, operational impact, mitigation vulnerability
calculate final impact rating
verify consistency across events
justify final impact output
Key Exercises
calculate impact for multiple scenarios
compare impact levels across events
correct inconsistencies
MODULE 7: RISK CALCULATION+
Purpose
Determine overall security risk.
Learning Outcomes
calculate risk
assign risk level
position risk within matrix
identify priority risks
justify risk level
Key Exercises
calculate risk scores
rank risks by severity
identify highest priority risk
MODULE 8: VALIDITY CHECK+
Purpose
Ensure analytical integrity.
Learning Outcomes
compare likelihood across events
compare impact across events
identify anomalies and inconsistencies
verify logical flow from threat → risk
correct flawed assessments
Key Exercises
run full validity check
identify inconsistent ratings
correct and justify adjustments
MODULE 9: RESIDUAL & PROJECTED RISK+
Purpose
Define risk after measures.
Learning Outcomes
differentiate current risk vs projected risk
determine residual risk after implemented measures
evaluate realism of projected reduction
prevent overestimation of measures
justify residual risk
Key Exercises
compare current vs projected risk
identify unrealistic reductions
define residual risk level
MODULE 10: RISK PRIORITIZATION & DECISION SUPPORT+
Purpose
Direct resource allocation based on risk.
Learning Outcomes
identify highest risk events
determine which risks require immediate action
evaluate operational impact of risk
justify prioritization
Key Exercises
rank risks by operational relevance
assign response priority
justify prioritization decisions
MODULE 11: ACCEPTABLE RISK MODEL+
Purpose
Support leadership in risk acceptance decisions.
Learning Outcomes
differentiate security role vs leadership role
define residual risk levels (Low → Very High → Unacceptable)
align risk with activity criticality
determine which activities can proceed
identify required approval level
justify acceptable risk recommendation
Key Exercises
match risk level to allowed activity
determine decision authority level
identify unacceptable conditions
MODULE 12: CRITICALITY & DECISION LOGIC+
Purpose
Enable decision-making based on operational importance.
Learning Outcomes
identify activity criticality level
verify that criticality is assigned by leadership
assess whether risk is justified by objective
determine ACAT strategy (Accept / Control / Avoid / Transfer)
justify operational decision
Key Exercises
assign criticality to activities
match risk vs criticality
define decision outcome
MODULE 13: FINAL OPERATIONAL SCENARIO+
Purpose
Validate full capability chain.
Scenario Conditions
incomplete data
conflicting assessments
time pressure
leadership decision requirement
Learning Outcomes
assess vulnerabilities
determine likelihood and impact
calculate risk
define residual risk
apply acceptable risk model
produce decision-ready output
Key Exercises
execute full risk assessment
produce decision brief
defend recommendation
Assessment Requirements
Prevention Vulnerability Assessment
Mitigation Vulnerability Assessment
Likelihood Calculation
Impact Calculation
Risk Matrix Output
Residual Risk Definition
Acceptable Risk Decision Support
Need help choosing the right training?
Tell us the role, capability, or operational requirement you need to address.
Apply for this course.
Submit your course selection and applicant details. Supporting documents are requested separately after review.
Need this capability across an organization or public-service unit?
We adapt course scope, scenarios, delivery, and assessment to your staff, mandate, and operating environment.