Risk scenarios
A risk scenario describes one way things could go wrong: a threat realised against particular assets, with a probability, an impact and a decision about what to do. Scenarios belong to a risk assessment, but the Risk scenarios page gathers them all into a single register so you can see the whole exposure across studies at once.
Where to find it
Section titled “Where to find it”Risk → Risk scenarios in the sidebar. Scenarios can also be created and edited from inside their parent risk assessment.
Key concepts
Section titled “Key concepts”Current versus residual
Section titled “Current versus residual”Scoring a scenario twice is the whole point. Each stage has its own Probability and Impact; CyberGuard looks the pair up in the assessment’s risk matrix and fills in the Level for you on save.
| Stage | Question it answers | What counts |
|---|---|---|
| Inherent | How bad would this be with no controls at all? | Nothing — the natural level of the risk |
| Current | How bad is it today? | The Existing controls already in place |
| Residual | How bad will it be once the plan is done? | Existing plus the Extra controls you intend to add |
The inherent stage is shown when the inherent_risk feature flag is on. Current and residual are always present, and the gap between them is the value your action plan claims to deliver — which is why a residual level higher than the current level, or lowered with no extra control to justify it, is flagged as an inconsistency.
What a scenario links to
Section titled “What a scenario links to”- Threats — the catalogue entries the scenario realises.
- Assets — what is impacted.
- Vulnerabilities — the weaknesses it exploits.
- Existing controls and Extra controls — two distinct applied-control lists; this split is what separates the current picture from the target one.
- Incidents — occasions where this scenario actually materialised.
- Exceptions — approved deviations bearing on the scenario.
- Antecedent scenarios — scenarios that must happen first, for chained risks.
Supporting fields round out the judgement: a Risk origin, Qualifications (the nature of the harm — confidentiality, availability, and so on), an Owner, a Justification for the scoring, and a Strength of knowledge rating that records how well-founded the estimate is. A scenario derived from an EBIOS RM operational scenario keeps a link back to it.
Reference IDs are generated as R.01, R.02 and so on within an assessment unless you set your own.
Treatment
Section titled “Treatment”The Treatment decision records what you chose to do:
| Treatment | Meaning |
|---|---|
| Open | Not yet decided |
| Mitigate | Reduce it with controls |
| Accept | Live with it, as recorded in a risk acceptance |
| Avoid | Stop doing the thing that creates it |
| Transfer | Shift it — typically to an insurer or a supplier |
| Cancelled | No longer applicable |
Validating a risk acceptance sets its scenarios to Accept automatically, and revoking that acceptance returns them to Open.
Working with scenarios
Section titled “Working with scenarios”The register supports search and filters by risk assessment, domain, treatment, current and residual level. Use it for the questions that cut across studies — every unmitigated high risk, every scenario touching a given asset, everything still Open.
Related
Section titled “Related”- Risk assessments — the study a scenario belongs to.
- Threats and Assets — what a scenario points at.
- Applied controls — the existing and extra controls behind the two scores.
- Vulnerabilities — technical weaknesses feeding a scenario.
