Likelihood Determination
Likelihood determination is the step in risk assessment where you estimate how probable it is that a security threat will actually take advantage of a weakness and cause harm to an asset. It helps decision-makers focus attention on the risks most likely to occur rather than treating every possible problem as equally urgent. This estimate is often subjective and is typically paired with an assessment of potential impact to prioritize risks.
Likelihood determination is the process within risk assessment of estimating the probability that a given threat source is capable of exploiting a given vulnerability to produce an adverse impact on an asset. It is frequently expressed as a weighted factor derived from subjective analysis rather than precise statistical probability, and may account for factors such as the presence or absence of security controls, threat capability, and vulnerability exposure. Likelihood is generally combined with impact within a risk matrix to produce an overall risk rating that supports prioritization by risk managers and decision-makers. In practice, the rigor and accuracy of a likelihood determination depend on available threat and vulnerability data, the assessment methodology used, and the maturity of the organization; a virtual CISO typically advises on and helps structure this process, while accountability for accepting or treating the resulting risks remains with the client organization.
Why it matters
Likelihood determination is what keeps a risk assessment from collapsing into an unmanageable list of every conceivable thing that could go wrong. Without estimating how probable a given threat is to exploit a given vulnerability, organizations tend to treat all risks as equally urgent, which dilutes attention and spending. By pairing likelihood with an assessment of potential impact, decision-makers and risk managers can focus resources on the risks most likely to materialize and cause harm, rather than chasing low-probability scenarios at the expense of pressing ones.
The determination directly shapes downstream decisions about whether to accept, mitigate, transfer, or avoid a risk. When likelihood is systematically underestimated, real exposures may be deprioritized and left untreated; when it is overestimated, organizations may over-invest in controls that do not meaningfully reduce risk. Because likelihood is often a subjective, weighted factor rather than a precise statistical probability, the quality of the underlying analysis has an outsized effect on the credibility of the entire risk rating that results.
It is important to recognize the limits of this exercise. Likelihood estimates depend on the available threat and vulnerability data, the methodology applied, and the maturity of the organization performing the assessment. A virtual CISO can advise on and help structure how likelihood is determined, but accountability for accepting or treating the resulting risks remains with the client organization and its officers. Treating a likelihood rating as an objective certainty rather than an informed judgment is a common mistake that experienced practitioners work to correct.
Who it's relevant to
Inside Likelihood Determination
Common questions
Answers to the questions practitioners most commonly ask about Likelihood Determination.