Skip to content

Risk scenarios

A risk scenario describes one way things could go wrong: a threat realised against particular assets, with a probability, an impact and a decision about what to do. Scenarios belong to a risk assessment, but the Risk scenarios page gathers them all into a single register so you can see the whole exposure across studies at once.

Risk → Risk scenarios in the sidebar. Scenarios can also be created and edited from inside their parent risk assessment.

Scoring a scenario twice is the whole point. Each stage has its own Probability and Impact; CyberGuard looks the pair up in the assessment’s risk matrix and fills in the Level for you on save.

StageQuestion it answersWhat counts
InherentHow bad would this be with no controls at all?Nothing — the natural level of the risk
CurrentHow bad is it today?The Existing controls already in place
ResidualHow bad will it be once the plan is done?Existing plus the Extra controls you intend to add

The inherent stage is shown when the inherent_risk feature flag is on. Current and residual are always present, and the gap between them is the value your action plan claims to deliver — which is why a residual level higher than the current level, or lowered with no extra control to justify it, is flagged as an inconsistency.

  • Threats — the catalogue entries the scenario realises.
  • Assets — what is impacted.
  • Vulnerabilities — the weaknesses it exploits.
  • Existing controls and Extra controls — two distinct applied-control lists; this split is what separates the current picture from the target one.
  • Incidents — occasions where this scenario actually materialised.
  • Exceptions — approved deviations bearing on the scenario.
  • Antecedent scenarios — scenarios that must happen first, for chained risks.

Supporting fields round out the judgement: a Risk origin, Qualifications (the nature of the harm — confidentiality, availability, and so on), an Owner, a Justification for the scoring, and a Strength of knowledge rating that records how well-founded the estimate is. A scenario derived from an EBIOS RM operational scenario keeps a link back to it.

Reference IDs are generated as R.01, R.02 and so on within an assessment unless you set your own.

The Treatment decision records what you chose to do:

TreatmentMeaning
OpenNot yet decided
MitigateReduce it with controls
AcceptLive with it, as recorded in a risk acceptance
AvoidStop doing the thing that creates it
TransferShift it — typically to an insurer or a supplier
CancelledNo longer applicable

Validating a risk acceptance sets its scenarios to Accept automatically, and revoking that acceptance returns them to Open.

The register supports search and filters by risk assessment, domain, treatment, current and residual level. Use it for the questions that cut across studies — every unmitigated high risk, every scenario touching a given asset, everything still Open.