Risk Matrix Calculator

Score risks by likelihood and impact using NIST SP 800-30, ISO 31000 or a 3x3 matrix. Get a heat map, risk level and treatment recommendations. Free tool.

Advertisement

Risk Matrix Calculator for NIST, ISO 31000 and 3×3 Scoring

This risk matrix calculator scores risks by likelihood and impact, places them on a colour-coded heat map, and returns treatment recommendations with indicative cost ranges and timelines. It supports three frameworks — NIST SP 800-30, ISO 31000:2018, and a simplified 3×3 matrix — and each carries its own level definitions, financial and downtime bands, and risk-level thresholds. Assessed risks can be added to a register you build up across a session.

It is aimed at risk managers, IT and security leads, auditors, and consultants running a workshop who need something quicker than a full quantitative model but more disciplined than a whiteboard. A built-in library of common technology risk scenarios — ransomware, DDoS, insider exfiltration, misconfigured cloud storage, backup failure, and others — provides starting likelihood and impact ratings you can adjust.

The Scoring Method

The arithmetic is deliberately simple, which is the point of a qualitative matrix:

Risk score = likelihood level × impact level

Both are ordinal levels — 1 to 5 on the NIST and ISO matrices, 1 to 3 on the simple matrix — so scores run 1 to 25 or 1 to 9. The score is then mapped to a named risk level using framework-specific thresholds.

NIST SP 800-30 (5×5): 1–4 Very Low, 5–8 Low, 9–12 Moderate, 13–19 High, 20–25 Very High.

ISO 31000:2018 (5×5): 1–5 Low, 6–12 Medium, 13–16 High, 17–25 Extreme.

Simple (3×3): 1–3 Low, 4–6 Medium, 7–9 High.

The two 5×5 frameworks differ in more than labels. ISO’s bands are broader in the middle and its top band starts at 17, so a score of 17 or 18 is Extreme under ISO but only High under NIST. Choose the framework your organisation has already adopted rather than the one that produces the answer you want, and record which one you used — a score without its framework is meaningless.

What the levels actually mean

Each framework anchors its levels to concrete ranges, which is what stops a matrix becoming pure opinion. Under NIST, likelihood runs from Very Low (under 1% annual probability) to Very High (over 80%). Impact runs from Very Low (under $10K, under an hour of downtime) through Moderate ($100K to $1M, 8 to 24 hours) to Very High (over $10M, more than seven days). ISO uses the same financial and downtime bands with its own descriptive labels — Rare through Almost Certain for likelihood, Insignificant through Catastrophic for consequence.

A worked example

Assess “ransomware attack on critical systems” under NIST SP 800-30. You judge likelihood as Moderate (level 3, reasonably expected, 10–50% annual probability) and impact as High (level 4, $1M to $10M, one to seven days of downtime).

  • Risk score = 3 × 4 = 12 out of 25.
  • Under NIST thresholds, 12 falls in the 9–12 band: Moderate risk.
  • Under ISO 31000, the same score of 12 sits at the top of the 6–12 band: Medium — the same treatment tier under a different name.

Now raise impact to Very High (level 5): the score becomes 15, which is High under NIST and High under ISO. One step on a five-point impact scale moved the risk two treatment tiers under NIST. That sensitivity is exactly why impact ratings deserve to be argued about in the room, with the financial bands visible.

The limitation worth knowing

Multiplying ordinal levels is not real arithmetic. A likelihood of 5 with impact of 1 scores the same 5 as likelihood 1 with impact 5 — a certain trivial nuisance and a once-in-a-lifetime catastrophe rank identically. They are not remotely the same management problem: one is absorbed as an operating cost, the other is what insurance and continuity planning exist for. Matrix scores also cannot be summed, averaged, or compared against a budget. Use the matrix to triage and communicate, and when a risk reaches the top of the register, re-express it in dollars with the quantitative risk analysis tool, where annualised loss expectancy can be compared directly against control costs.

How to Use It

  1. Choose a framework. NIST SP 800-30 for US federal alignment and most security programmes, ISO 31000 for enterprise risk management, the 3×3 matrix for a fast small-organisation pass.
  2. Pick or write a scenario. The scenario library covers infrastructure, data, cloud, application, and human-factor risks with typical starting ratings.
  3. Rate likelihood. Use the stated probability ranges rather than instinct. “Reasonably expected” means 10–50% in a given year under NIST.
  4. Rate impact. Use the financial and downtime bands. If a risk is high-cost but short-duration, or vice versa, rate on whichever dimension your organisation is genuinely less able to absorb, and note why.
  5. Read the treatment recommendation. High and Very High risks return mitigation actions plus a transfer option; Moderate risks return mitigation or documented acceptance; low risks return acceptance with monitoring.
  6. Add to the register. Build the full register in one session and use the heat map to see clustering.

Treatment Strategies

The four standard responses are mitigate, transfer, accept, and avoid. The tool selects a primary strategy from the risk level and lists specific actions, an expected residual risk, an indicative cost range, and a timeline. High and Very High risks get mitigation with a transfer option alongside, on the reasoning that cyber insurance moves financial impact but not operational impact — you still suffer the outage, you are merely reimbursed for part of it. Moderate risks are offered mitigation or formal acceptance, and formal acceptance means documented sign-off with a review schedule, not silence.

For context on where these risks actually sit, Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of breaches and in 88% of small and medium business breaches, third-party involvement doubling to 30%, and vulnerability exploitation behind 20% of breaches. IBM’s Cost of a Data Breach Report 2026 put the global average breach cost at $4.99M and the US average at $11.5M. Those figures are useful when arguing about which impact band a data breach scenario belongs in.

Frequently Asked Questions

How is a risk score calculated?

Likelihood level multiplied by impact level. On a 5×5 matrix that yields 1 to 25; on 3×3 it yields 1 to 9. The score is then mapped to a named level by framework-specific thresholds.

Which framework should I use?

Whichever your organisation has adopted. NIST SP 800-30 is the common choice for security programmes and US federal alignment. ISO 31000:2018 suits enterprise-wide risk management. The 3×3 matrix is for small organisations and rapid triage where a five-point scale would imply false precision.

Why do NIST and ISO give different labels for the same score?

Because their band thresholds differ. ISO’s top tier starts at 17 and NIST’s at 20, so scores in the high teens are rated more severely under ISO. Always record which framework produced a score.

Can I average or add risk scores?

No. They are ordinal products, not measurements. Averaging two risks scored 4 and 16 to claim an average risk of 10 is meaningless. Report the distribution, not a mean.

What does the heat map show?

Every cell of the likelihood-by-impact grid, coloured by the framework’s risk bands, with your assessed risks plotted on it. Clustering in one quadrant is usually more informative than any individual score.

What is residual risk?

The risk remaining after treatment. Each recommendation states an expected residual level, and you should reassess and re-score once controls are actually in place rather than assuming the predicted residual was achieved.

Do the cost ranges reflect real quotes?

They are indicative planning bands tied to risk level, not quotes. Use them to set expectations before procurement, and price specific controls properly — a scoped engagement can be estimated with the pentest scoping calculator.

Is the register saved?

The register is held in your browser for the session. Nothing is uploaded, and nothing is stored on our servers.

What Is a Risk Matrix

A risk matrix (also called a risk heat map) is a visual tool that plots risks on a grid based on their likelihood of occurrence and potential impact. By categorizing risks into cells ranging from low (green) to critical (red), a risk matrix enables rapid prioritization of security risks, business risks, and project risks.

Risk matrices are the most widely used risk assessment tool in cybersecurity, project management, and enterprise risk management. They appear in virtually every compliance framework — ISO 27005, NIST SP 800-30, COBIT, and COSO ERM all recommend risk matrix approaches for risk evaluation and communication.

Risk Matrix Structure

A typical 5x5 risk matrix maps likelihood (vertical axis) against impact (horizontal axis):

Likelihood / ImpactNegligibleMinorModerateMajorCatastrophic
Almost CertainMediumHighCriticalCriticalCritical
LikelyLowMediumHighCriticalCritical
PossibleLowMediumMediumHighCritical
UnlikelyLowLowMediumMediumHigh
RareLowLowLowMediumMedium

Impact Categories

LevelFinancialOperationalReputationalRegulatory
Negligible<$10KNo disruptionNo attentionNo violation
Minor$10K-$100KMinor disruptionLocal attentionWarning
Moderate$100K-$1MSignificant disruptionIndustry attentionFine
Major$1M-$10MMajor disruptionNational attentionMajor penalty
Catastrophic>$10MBusiness-threateningGlobal attentionLicense revocation

Common Use Cases

  • Security risk assessment: Evaluate and prioritize cybersecurity risks based on threat likelihood and potential business impact
  • Board risk reporting: Present risk posture to executives and boards using visual heat maps that communicate risk levels without technical detail
  • Project risk management: Identify and prioritize risks to project timelines, budgets, and deliverables
  • Compliance risk evaluation: Assess the likelihood and impact of compliance failures across regulatory frameworks
  • Vendor risk assessment: Categorize third-party risks based on the vendor's criticality and the sensitivity of data they access

Best Practices

  1. Define scales clearly — Ambiguous terms like "likely" mean different things to different people. Define each level with specific criteria: "Likely = expected to occur within the next 12 months based on historical data."
  2. Use consistent scales across the organization — Everyone should use the same likelihood and impact definitions. Inconsistent scales make risk comparison meaningless.
  3. Include multiple impact dimensions — A single "impact" score oversimplifies. Evaluate financial, operational, reputational, and regulatory impact separately, then use the highest rating.
  4. Review and update regularly — Risk ratings change as threats evolve, controls are implemented, and business context shifts. Review quarterly at minimum.
  5. Supplement with quantitative analysis — Risk matrices are excellent for communication and initial prioritization but are inherently subjective. For high-value decisions, supplement with quantitative risk analysis (ALE, Monte Carlo simulation).

Frequently Asked Questions

What is a risk matrix and how does it work?+

A risk matrix is a visual tool that helps organizations assess and prioritize risks by plotting likelihood against impact on a grid. Each cell represents a risk level (Low, Medium, High, Critical) based on the combination of how likely a risk is to occur and how severe its consequences would be. This tool supports multiple industry-standard frameworks including NIST.

Which risk assessment framework should I use?+

The choice of framework depends on your industry and requirements. NIST is widely used in government and cybersecurity contexts. ISO 27005 is popular for information security management. Choose a framework that aligns with your compliance requirements and organizational risk management practices.

How do I determine the likelihood and impact levels?+

Likelihood should be assessed based on historical data, threat intelligence, and expert judgment about how often the risk event might occur. Impact considers the potential consequences including financial loss, operational disruption, reputational damage, and regulatory penalties. Be consistent in your criteria across all risk assessments.

Can I save my risk assessments?+

Yes, the tool includes a Risk Register feature that stores your assessments in your browser local storage. You can add completed assessments to the register, review historical assessments, and export your entire risk register to CSV format for reporting and documentation purposes.

What are the pre-built risk scenarios in the library?+

The scenario library contains common risk scenarios across different categories such as cybersecurity threats, operational risks, compliance risks, and natural disasters. Each scenario includes typical likelihood and impact ratings as a starting point. You can select a scenario and adjust the ratings based on your specific context.

How do I interpret the recommendations provided?+

After calculating a risk score, the tool provides actionable recommendations based on the risk level. Critical and high risks typically require immediate action and mitigation strategies. Medium risks should be monitored and addressed within a defined timeframe. Low risks may be accepted or addressed as resources allow.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.