Skip to main content
Category: Risk Management

Threat Likelihood

Also known as: Risk Likelihood, Likelihood Determination, Likelihood
Simply put

Threat likelihood is an estimate of how probable it is that a given threat will exploit a weakness and cause harm to an organization. It is one of the main factors, alongside impact, that decision-makers and risk managers use to judge how serious a risk is. Because it usually relies on some degree of judgment, it is often expressed as a rating or weighted factor rather than an exact number.

Formal definition

Threat likelihood is a weighted factor, frequently based on subjective analysis, representing the probability that a given threat source is capable of exploiting a given vulnerability, or set of vulnerabilities, to affect an asset. In many methodologies it is estimated over a defined period (for example, the probability of exploitation within a calendar year) and considers attributes of the threat agent such as skill level and opportunity, as illustrated in the OWASP Risk Rating Methodology. Likelihood is typically combined with impact, and in some models with control maturity, to derive an overall risk rating; a virtual CISO may guide how likelihood is scored and applied within a risk assessment process, but the determination itself often varies by methodology, available data, and organizational context.

Why it matters

Threat likelihood is one of the two central inputs, alongside impact, that shape how an organization prioritizes its limited security resources. Without a reasoned estimate of how probable it is that a given threat will exploit a weakness, decision-makers and risk managers have no consistent basis for deciding which risks demand immediate investment and which can be accepted, monitored, or deferred. Because likelihood is frequently based on subjective analysis rather than precise measurement, the quality of these judgments directly affects whether an organization is spending on the risks that matter most or chasing lower-probability concerns while leaving more probable exposures unaddressed.

The estimate also carries governance and communication weight. When likelihood is expressed as a rating or weighted factor rather than an exact number, it must still be defensible to executives, boards, auditors, and other stakeholders who rely on it to understand the organization's risk posture. Methodologies such as the OWASP Risk Rating Methodology encourage estimating the likelihood of a successful attack by considering attributes of the threat agent, such as skill level and opportunity, while approaches like Mozilla's likelihood indicators frame it as the probability of exploitation within a calendar year. Making the reasoning explicit helps avoid the common trap of treating a subjective judgment as if it were an objective fact.

A virtual CISO is often engaged to guide how likelihood is scored and applied within a risk assessment process, bringing structure and consistency to what can otherwise be an ad hoc exercise. It is important to be clear about the boundary of that role: a vCISO advises on and directs the methodology, but the underlying determination varies by methodology, available data, and organizational context, and accountability for the resulting risk decisions generally remains with the client organization and its officers rather than transferring to the advisor.

Who it's relevant to

Risk Managers and Security Leaders
Those responsible for assessing and prioritizing risk rely on threat likelihood, alongside impact, as a primary factor in judging how serious a given risk is. They need a defensible, consistent way to score likelihood so that resource allocation reflects the risks most probable to materialize rather than the most visible or technically interesting ones.
Virtual and Fractional CISOs
A vCISO or fractional CISO is often engaged to guide how likelihood is scored and applied within a risk assessment process, selecting a methodology and establishing consistent scoring criteria. Their role is advisory and directive rather than a transfer of accountability; the determination itself varies by methodology, available data, and organizational context, and final risk decisions remain with the client organization.
Executives and Boards
Senior decision-makers use likelihood ratings to understand the organization's risk posture and to approve or challenge how risks are being prioritized. Because likelihood is frequently a subjective, weighted factor rather than an exact number, executives benefit from understanding the reasoning and assumptions behind each rating so they can weigh it appropriately in governance decisions.
Auditors and Compliance Stakeholders
Parties reviewing a risk assessment need to see how likelihood was determined and applied, including the period over which it was estimated and the threat attributes considered. A transparent, repeatable approach to likelihood determination supports scrutiny of whether the organization's risk ratings are consistent and reasonable.

Inside Threat Likelihood

Threat source characterization
An assessment of who or what could initiate a threat, including the capability, intent, and opportunity of adversarial actors or the frequency of non-adversarial events such as system failures or human error.
Vulnerability consideration
An evaluation of the weaknesses a threat could exploit; likelihood often rises where exploitable vulnerabilities exist and falls where effective controls reduce exposure.
Control effectiveness
The degree to which existing preventive and detective controls reduce the probability that a threat event succeeds, which directly influences the likelihood rating.
Likelihood rating scale
The qualitative (for example, low, medium, high) or quantitative scale used to express probability; qualitative approaches are common in many engagements where precise data is unavailable.
Contribution to risk
Threat likelihood is one of two primary inputs to risk, combined with potential impact to produce a prioritized risk rating rather than serving as a standalone conclusion.

Common questions

Answers to the questions practitioners most commonly ask about Threat Likelihood.

Is threat likelihood the same as the probability that my organization will be breached?
No. Threat likelihood estimates how probable it is that a particular threat event or threat source will act against a given asset, often expressed qualitatively or on a defined scale rather than as a precise statistical probability. It is one input into risk, not a standalone breach forecast. Whether a threat succeeds also depends on existing vulnerabilities, controls, and potential impact. Treating a likelihood rating as a prediction of certain breach or safety overstates what the estimate is designed to convey, and a virtual CISO typically frames it as a directional judgment used to prioritize, not a guarantee of outcomes.
Can a virtual CISO give us an exact, objective likelihood number for each threat?
Not usually. Threat likelihood assessments often rely on informed judgment, historical patterns, threat intelligence, and organizational context, so results can vary by provider, method, and available data. Assigning a specific percentage may imply a level of precision that the underlying evidence does not support. In many engagements a virtual CISO uses ordinal scales such as low, moderate, or high, with documented rationale, so ratings remain defensible and comparable rather than falsely exact. The value of the estimate depends heavily on the quality of inputs and stakeholder cooperation.
How does a virtual CISO typically go about estimating threat likelihood?
A virtual CISO generally starts by identifying relevant threat sources and events for the organization's assets, then considers factors such as threat actor capability and intent, historical incident frequency, exposure of the asset, and the strength of existing controls. These factors are mapped to a defined rating scale, often aligned with a framework such as NIST guidance, with the reasoning documented. Because a virtual CISO focuses on governance and strategy, they usually direct and structure this analysis rather than performing hands-on data collection tasks like log analysis, which may involve internal teams or contracted specialists.
How often should threat likelihood ratings be reviewed or updated?
Likelihood ratings can become stale as the threat environment, business operations, and control posture change, so many organizations revisit them on a periodic cadence and after significant events such as a major architecture change, a new regulatory obligation, or a relevant incident. A virtual CISO may recommend a review frequency appropriate to the organization's risk profile and maturity, but the specific cadence varies. Accountability for maintaining current risk information typically remains with the client organization, with the virtual CISO advising on process and triggers.
How does threat likelihood connect to compliance frameworks like ISO 27001 or NIST CSF?
Several frameworks expect organizations to assess the likelihood and impact of risks as part of a documented risk assessment process. For example, ISO 27001 calls for a defined risk assessment methodology, and NIST guidance describes likelihood as a component of risk determination. A virtual CISO can help structure likelihood assessments so they support readiness for these frameworks, but a documented likelihood rating on its own does not assert certification or guarantee a compliant outcome. Certification and formal compliance status depend on audits and organizational actions beyond the assessment itself.
What are the limitations we should keep in mind when using threat likelihood in decisions?
Threat likelihood estimates are only as reliable as the data, threat intelligence, and organizational context behind them, and they can carry inherent uncertainty and subjectivity. Their usefulness depends on consistent scales, access to stakeholders, and honest input about controls and exposure. A virtual CISO advises on how to interpret and prioritize using these estimates, but legal and organizational accountability for the resulting decisions generally remains with the client's officers. Likelihood should be combined with impact and considered alongside qualitative judgment rather than treated as a precise or final answer.

Common misconceptions

Threat likelihood is a precise, calculable probability figure.
In many engagements, likelihood is assessed qualitatively because reliable quantitative data is often unavailable. Ratings such as low, medium, or high represent informed judgments and may vary by provider and methodology rather than being exact statistical probabilities.
A high likelihood rating means a breach is inevitable, and engaging a virtual CISO to lower it guarantees prevention.
Likelihood expresses probability, not certainty, and a vCISO advises on reducing it but cannot guarantee outcomes such as breach prevention. Accountability for security decisions and their consequences generally remains with the client organization.
Assessing threat likelihood is a purely technical exercise handled by operational security tools.
Likelihood assessment is a governance and business risk activity that combines technical inputs with judgment about threat sources, business context, and control maturity. It should not be conflated with SOC monitoring or the work of a managed security service provider.

Best practices

Define the assessment scope, time horizon, and rating scale up front, and document the assumptions behind each likelihood rating so results are repeatable and defensible.
Base likelihood ratings on multiple inputs, including threat intelligence, historical incident data, industry context, and current control effectiveness, rather than a single data point.
Pair every likelihood rating with an impact estimate so that prioritization reflects overall risk rather than probability alone.
Reassess likelihood periodically and after significant changes to the threat landscape, business environment, or control posture, since ratings can become stale quickly.
Communicate likelihood to executives and boards in business risk terms, making clear that ratings are informed estimates and that accountability for acting on them rests with the organization.
Recognize that assessment quality depends on organizational maturity, stakeholder cooperation, and data access, and flag gaps in these areas as limitations on the reliability of the results.