Threat Likelihood
Threat likelihood is an estimate of how probable it is that a given threat will exploit a weakness and cause harm to an organization. It is one of the main factors, alongside impact, that decision-makers and risk managers use to judge how serious a risk is. Because it usually relies on some degree of judgment, it is often expressed as a rating or weighted factor rather than an exact number.
Threat likelihood is a weighted factor, frequently based on subjective analysis, representing the probability that a given threat source is capable of exploiting a given vulnerability, or set of vulnerabilities, to affect an asset. In many methodologies it is estimated over a defined period (for example, the probability of exploitation within a calendar year) and considers attributes of the threat agent such as skill level and opportunity, as illustrated in the OWASP Risk Rating Methodology. Likelihood is typically combined with impact, and in some models with control maturity, to derive an overall risk rating; a virtual CISO may guide how likelihood is scored and applied within a risk assessment process, but the determination itself often varies by methodology, available data, and organizational context.
Why it matters
Threat likelihood is one of the two central inputs, alongside impact, that shape how an organization prioritizes its limited security resources. Without a reasoned estimate of how probable it is that a given threat will exploit a weakness, decision-makers and risk managers have no consistent basis for deciding which risks demand immediate investment and which can be accepted, monitored, or deferred. Because likelihood is frequently based on subjective analysis rather than precise measurement, the quality of these judgments directly affects whether an organization is spending on the risks that matter most or chasing lower-probability concerns while leaving more probable exposures unaddressed.
The estimate also carries governance and communication weight. When likelihood is expressed as a rating or weighted factor rather than an exact number, it must still be defensible to executives, boards, auditors, and other stakeholders who rely on it to understand the organization's risk posture. Methodologies such as the OWASP Risk Rating Methodology encourage estimating the likelihood of a successful attack by considering attributes of the threat agent, such as skill level and opportunity, while approaches like Mozilla's likelihood indicators frame it as the probability of exploitation within a calendar year. Making the reasoning explicit helps avoid the common trap of treating a subjective judgment as if it were an objective fact.
A virtual CISO is often engaged to guide how likelihood is scored and applied within a risk assessment process, bringing structure and consistency to what can otherwise be an ad hoc exercise. It is important to be clear about the boundary of that role: a vCISO advises on and directs the methodology, but the underlying determination varies by methodology, available data, and organizational context, and accountability for the resulting risk decisions generally remains with the client organization and its officers rather than transferring to the advisor.
Who it's relevant to
Inside Threat Likelihood
Common questions
Answers to the questions practitioners most commonly ask about Threat Likelihood.