Skip to main content
Category: Risk Management

Likelihood Determination

Also known as: Likelihood Assessment, Risk Likelihood
Simply put

Likelihood determination is the step in risk assessment where you estimate how probable it is that a security threat will actually take advantage of a weakness and cause harm to an asset. It helps decision-makers focus attention on the risks most likely to occur rather than treating every possible problem as equally urgent. This estimate is often subjective and is typically paired with an assessment of potential impact to prioritize risks.

Formal definition

Likelihood determination is the process within risk assessment of estimating the probability that a given threat source is capable of exploiting a given vulnerability to produce an adverse impact on an asset. It is frequently expressed as a weighted factor derived from subjective analysis rather than precise statistical probability, and may account for factors such as the presence or absence of security controls, threat capability, and vulnerability exposure. Likelihood is generally combined with impact within a risk matrix to produce an overall risk rating that supports prioritization by risk managers and decision-makers. In practice, the rigor and accuracy of a likelihood determination depend on available threat and vulnerability data, the assessment methodology used, and the maturity of the organization; a virtual CISO typically advises on and helps structure this process, while accountability for accepting or treating the resulting risks remains with the client organization.

Why it matters

Likelihood determination is what keeps a risk assessment from collapsing into an unmanageable list of every conceivable thing that could go wrong. Without estimating how probable a given threat is to exploit a given vulnerability, organizations tend to treat all risks as equally urgent, which dilutes attention and spending. By pairing likelihood with an assessment of potential impact, decision-makers and risk managers can focus resources on the risks most likely to materialize and cause harm, rather than chasing low-probability scenarios at the expense of pressing ones.

The determination directly shapes downstream decisions about whether to accept, mitigate, transfer, or avoid a risk. When likelihood is systematically underestimated, real exposures may be deprioritized and left untreated; when it is overestimated, organizations may over-invest in controls that do not meaningfully reduce risk. Because likelihood is often a subjective, weighted factor rather than a precise statistical probability, the quality of the underlying analysis has an outsized effect on the credibility of the entire risk rating that results.

It is important to recognize the limits of this exercise. Likelihood estimates depend on the available threat and vulnerability data, the methodology applied, and the maturity of the organization performing the assessment. A virtual CISO can advise on and help structure how likelihood is determined, but accountability for accepting or treating the resulting risks remains with the client organization and its officers. Treating a likelihood rating as an objective certainty rather than an informed judgment is a common mistake that experienced practitioners work to correct.

Who it's relevant to

Risk Managers and Decision-Makers
Those responsible for prioritizing and treating risk rely on likelihood determination to decide where limited attention and resources should go. The likelihood factor, combined with impact in a risk matrix, drives the overall risk rating they use to compare and rank exposures.
Virtual and Fractional CISOs
A vCISO or fractional CISO typically advises on and helps structure the likelihood determination process, recommending methodology and helping interpret threat and vulnerability data. They direct and guide the assessment, but accountability for accepting or treating the resulting risks remains with the client organization.
Security and Governance Teams
Practitioners performing risk assessments apply likelihood analysis when evaluating how factors such as missing security controls, threat capability, and vulnerability exposure affect the probability of an adverse event. The rigor of their work depends on available data, the chosen methodology, and organizational maturity.
Organizational Officers and Leadership
Leaders who ultimately accept residual risk depend on credible likelihood estimates to make informed governance and business decisions. They should understand that these estimates are informed judgments, often subjective, rather than guaranteed predictions of what will occur.

Inside Likelihood Determination

Threat Event Frequency
An estimate of how often a given threat source is expected to attempt to exploit a vulnerability within a defined period. In many risk assessment methods this is a core input to likelihood, though the precision of the estimate typically varies by the quality of available data.
Vulnerability and Exploitability
Consideration of whether an exploitable weakness exists and how readily a threat source could act on it. Likelihood generally increases where vulnerabilities are present, unmitigated, and accessible, and decreases where controls reduce exposure.
Existing Controls and Mitigations
The set of preventive, detective, and corrective measures already in place. Likelihood determination often adjusts a baseline estimate downward to reflect controls, but this depends on controls being implemented and operating as intended rather than merely documented.
Qualitative or Quantitative Rating
The output expression of likelihood, which may be a categorical scale (for example, low, moderate, high) or a probabilistic or numeric estimate. The approach may vary by provider, framework, and the maturity of the organization's data.
Assumptions and Data Sources
The documented basis for the estimate, including threat intelligence, historical incident data, expert judgment, and stated assumptions. Recording these is important because likelihood estimates are often judgment-based and should be transparent and revisitable.
Contextual and Environmental Factors
Organization-specific conditions such as industry exposure, asset attractiveness, and operating environment that can raise or lower likelihood. These factors typically require stakeholder input and access to accurate organizational information.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood Determination.

Does a virtual CISO calculate likelihood using precise statistical probabilities?
Not usually. Likelihood determination in most vCISO-led risk assessments is a structured, qualitative judgment rather than a precise statistical calculation. It typically draws on threat intelligence, historical patterns, control maturity, and expert reasoning to place a scenario into ordinal bands such as low, moderate, or high. Some organizations layer semi-quantitative or fully quantitative methods on top, but these depend on data availability and organizational maturity, and they are often not feasible in earlier-stage programs. A virtual CISO advises on and directs this process, but the resulting ratings remain estimates informed by judgment, not guarantees of future events.
If a virtual CISO rates a threat's likelihood as low, does that mean the organization is protected against it?
No. A low likelihood rating reflects a considered estimate that an event is less probable given current conditions; it does not prevent the event or transfer accountability for the outcome. Likelihood is only one input into a broader risk picture that also weighs potential impact. A low-likelihood, high-impact scenario may still warrant significant attention. A virtual CISO advises and directs prioritization, but accountability for accepting, mitigating, or transferring the associated risk typically remains with the client organization and its officers unless a contract specifies otherwise.
What inputs does a virtual CISO typically use to determine likelihood?
In many engagements a virtual CISO considers threat sources and their capability or motivation, known vulnerabilities and exposure, the presence and maturity of existing controls, and relevant historical or industry incident patterns. Frameworks such as NIST CSF or the risk methodology in NIST guidance may inform the structure of this analysis. The quality of the determination depends heavily on client cooperation and access to accurate information about systems, data, and controls, which is why availability of internal context materially affects the outcome.
How does a virtual CISO handle likelihood determination when historical data is limited?
When quantitative data is sparse, which is common, a virtual CISO often relies on qualitative or semi-quantitative approaches, using defined ordinal scales and documented rationale to keep judgments consistent and defensible. They may reference threat intelligence and comparable industry patterns as proxies. It is generally good practice to document assumptions explicitly so that ratings can be revisited as more data becomes available. The value of this approach may vary by provider and depends on organizational maturity and stakeholder input.
Is likelihood determination something a virtual CISO does hands-on within security tools?
Typically no. Likelihood determination is a governance and risk-management activity, not an operational one. A virtual CISO provides the strategy, methodology, and executive-level guidance to structure and interpret these ratings, but hands-on activities such as configuring scanning tools, running SOC monitoring, or extracting telemetry are generally out of scope unless explicitly contracted. The vCISO may direct how such operational data feeds into the likelihood analysis while relying on internal teams or other providers to produce it.
How often should likelihood determinations be revisited in a vCISO engagement?
Likelihood ratings are point-in-time estimates that can shift as threats, controls, and business conditions change, so they are often revisited on a defined cadence and after material events such as significant infrastructure changes or new threat developments. The appropriate frequency varies by organization and is usually agreed within the engagement scope. Because the vCISO relationship is typically part-time and may be shared across clients, establishing a clear reassessment schedule and stakeholder access up front helps ensure determinations stay current.

Common misconceptions

Likelihood determination produces a precise, objective probability of a breach.
In many engagements likelihood is an estimate based on judgment, assumptions, and often incomplete data. It is typically expressed as a qualified rating or range, and it does not guarantee or predict that a specific event will or will not occur.
A virtual CISO who documents likelihood ratings becomes accountable for the security decisions and outcomes that follow.
A vCISO generally advises on and helps produce likelihood assessments, but legal and organizational accountability for accepting, mitigating, or transferring the associated risk usually remains with the client organization and its officers unless a contract specifies otherwise.
A high likelihood rating means an incident is imminent and a low rating means the organization is safe.
Likelihood reflects relative estimated frequency or probability under stated assumptions, not certainty. Low-likelihood risks can still occur, and ratings should be periodically revisited as threats, vulnerabilities, and controls change.

Best practices

Document the assumptions, data sources, and methodology behind each likelihood estimate so the rating is transparent and can be reviewed or challenged later.
Use qualified language and consistent scales, and state whether the approach is qualitative or quantitative rather than implying a precise probability the underlying data cannot support.
Base likelihood adjustments on controls that are verified as implemented and operating, not on controls that are only planned or documented.
Engage relevant stakeholders to gather accurate contextual and environmental information, recognizing that estimate quality depends on client cooperation and access.
Clarify in the engagement scope that the vCISO advises on likelihood determination while accountability for resulting risk decisions typically stays with the client organization.
Revisit likelihood estimates on a defined cadence or when threats, vulnerabilities, or controls materially change, since a point-in-time rating can quickly become outdated.