Score risks by likelihood and impact using NIST SP 800-30, ISO 31000 or a 3x3 matrix. Get a heat map, risk level and treatment recommendations. Free tool.
This risk matrix calculator scores risks by likelihood and impact, places them on a colour-coded heat map, and returns treatment recommendations with indicative cost ranges and timelines. It supports three frameworks — NIST SP 800-30, ISO 31000:2018, and a simplified 3×3 matrix — and each carries its own level definitions, financial and downtime bands, and risk-level thresholds. Assessed risks can be added to a register you build up across a session.
It is aimed at risk managers, IT and security leads, auditors, and consultants running a workshop who need something quicker than a full quantitative model but more disciplined than a whiteboard. A built-in library of common technology risk scenarios — ransomware, DDoS, insider exfiltration, misconfigured cloud storage, backup failure, and others — provides starting likelihood and impact ratings you can adjust.
The arithmetic is deliberately simple, which is the point of a qualitative matrix:
Risk score = likelihood level × impact level
Both are ordinal levels — 1 to 5 on the NIST and ISO matrices, 1 to 3 on the simple matrix — so scores run 1 to 25 or 1 to 9. The score is then mapped to a named risk level using framework-specific thresholds.
NIST SP 800-30 (5×5): 1–4 Very Low, 5–8 Low, 9–12 Moderate, 13–19 High, 20–25 Very High.
ISO 31000:2018 (5×5): 1–5 Low, 6–12 Medium, 13–16 High, 17–25 Extreme.
Simple (3×3): 1–3 Low, 4–6 Medium, 7–9 High.
The two 5×5 frameworks differ in more than labels. ISO’s bands are broader in the middle and its top band starts at 17, so a score of 17 or 18 is Extreme under ISO but only High under NIST. Choose the framework your organisation has already adopted rather than the one that produces the answer you want, and record which one you used — a score without its framework is meaningless.
Each framework anchors its levels to concrete ranges, which is what stops a matrix becoming pure opinion. Under NIST, likelihood runs from Very Low (under 1% annual probability) to Very High (over 80%). Impact runs from Very Low (under $10K, under an hour of downtime) through Moderate ($100K to $1M, 8 to 24 hours) to Very High (over $10M, more than seven days). ISO uses the same financial and downtime bands with its own descriptive labels — Rare through Almost Certain for likelihood, Insignificant through Catastrophic for consequence.
Assess “ransomware attack on critical systems” under NIST SP 800-30. You judge likelihood as Moderate (level 3, reasonably expected, 10–50% annual probability) and impact as High (level 4, $1M to $10M, one to seven days of downtime).
Now raise impact to Very High (level 5): the score becomes 15, which is High under NIST and High under ISO. One step on a five-point impact scale moved the risk two treatment tiers under NIST. That sensitivity is exactly why impact ratings deserve to be argued about in the room, with the financial bands visible.
Multiplying ordinal levels is not real arithmetic. A likelihood of 5 with impact of 1 scores the same 5 as likelihood 1 with impact 5 — a certain trivial nuisance and a once-in-a-lifetime catastrophe rank identically. They are not remotely the same management problem: one is absorbed as an operating cost, the other is what insurance and continuity planning exist for. Matrix scores also cannot be summed, averaged, or compared against a budget. Use the matrix to triage and communicate, and when a risk reaches the top of the register, re-express it in dollars with the quantitative risk analysis tool, where annualised loss expectancy can be compared directly against control costs.
The four standard responses are mitigate, transfer, accept, and avoid. The tool selects a primary strategy from the risk level and lists specific actions, an expected residual risk, an indicative cost range, and a timeline. High and Very High risks get mitigation with a transfer option alongside, on the reasoning that cyber insurance moves financial impact but not operational impact — you still suffer the outage, you are merely reimbursed for part of it. Moderate risks are offered mitigation or formal acceptance, and formal acceptance means documented sign-off with a review schedule, not silence.
For context on where these risks actually sit, Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of breaches and in 88% of small and medium business breaches, third-party involvement doubling to 30%, and vulnerability exploitation behind 20% of breaches. IBM’s Cost of a Data Breach Report 2026 put the global average breach cost at $4.99M and the US average at $11.5M. Those figures are useful when arguing about which impact band a data breach scenario belongs in.
Likelihood level multiplied by impact level. On a 5×5 matrix that yields 1 to 25; on 3×3 it yields 1 to 9. The score is then mapped to a named level by framework-specific thresholds.
Whichever your organisation has adopted. NIST SP 800-30 is the common choice for security programmes and US federal alignment. ISO 31000:2018 suits enterprise-wide risk management. The 3×3 matrix is for small organisations and rapid triage where a five-point scale would imply false precision.
Because their band thresholds differ. ISO’s top tier starts at 17 and NIST’s at 20, so scores in the high teens are rated more severely under ISO. Always record which framework produced a score.
No. They are ordinal products, not measurements. Averaging two risks scored 4 and 16 to claim an average risk of 10 is meaningless. Report the distribution, not a mean.
Every cell of the likelihood-by-impact grid, coloured by the framework’s risk bands, with your assessed risks plotted on it. Clustering in one quadrant is usually more informative than any individual score.
The risk remaining after treatment. Each recommendation states an expected residual level, and you should reassess and re-score once controls are actually in place rather than assuming the predicted residual was achieved.
They are indicative planning bands tied to risk level, not quotes. Use them to set expectations before procurement, and price specific controls properly — a scoped engagement can be estimated with the pentest scoping calculator.
The register is held in your browser for the session. Nothing is uploaded, and nothing is stored on our servers.
A risk matrix (also called a risk heat map) is a visual tool that plots risks on a grid based on their likelihood of occurrence and potential impact. By categorizing risks into cells ranging from low (green) to critical (red), a risk matrix enables rapid prioritization of security risks, business risks, and project risks.
Risk matrices are the most widely used risk assessment tool in cybersecurity, project management, and enterprise risk management. They appear in virtually every compliance framework — ISO 27005, NIST SP 800-30, COBIT, and COSO ERM all recommend risk matrix approaches for risk evaluation and communication.
A typical 5x5 risk matrix maps likelihood (vertical axis) against impact (horizontal axis):
| Likelihood / Impact | Negligible | Minor | Moderate | Major | Catastrophic |
|---|---|---|---|---|---|
| Almost Certain | Medium | High | Critical | Critical | Critical |
| Likely | Low | Medium | High | Critical | Critical |
| Possible | Low | Medium | Medium | High | Critical |
| Unlikely | Low | Low | Medium | Medium | High |
| Rare | Low | Low | Low | Medium | Medium |
| Level | Financial | Operational | Reputational | Regulatory |
|---|---|---|---|---|
| Negligible | <$10K | No disruption | No attention | No violation |
| Minor | $10K-$100K | Minor disruption | Local attention | Warning |
| Moderate | $100K-$1M | Significant disruption | Industry attention | Fine |
| Major | $1M-$10M | Major disruption | National attention | Major penalty |
| Catastrophic | >$10M | Business-threatening | Global attention | License revocation |
A risk matrix is a visual tool that helps organizations assess and prioritize risks by plotting likelihood against impact on a grid. Each cell represents a risk level (Low, Medium, High, Critical) based on the combination of how likely a risk is to occur and how severe its consequences would be. This tool supports multiple industry-standard frameworks including NIST.
The choice of framework depends on your industry and requirements. NIST is widely used in government and cybersecurity contexts. ISO 27005 is popular for information security management. Choose a framework that aligns with your compliance requirements and organizational risk management practices.
Likelihood should be assessed based on historical data, threat intelligence, and expert judgment about how often the risk event might occur. Impact considers the potential consequences including financial loss, operational disruption, reputational damage, and regulatory penalties. Be consistent in your criteria across all risk assessments.
Yes, the tool includes a Risk Register feature that stores your assessments in your browser local storage. You can add completed assessments to the register, review historical assessments, and export your entire risk register to CSV format for reporting and documentation purposes.
The scenario library contains common risk scenarios across different categories such as cybersecurity threats, operational risks, compliance risks, and natural disasters. Each scenario includes typical likelihood and impact ratings as a starting point. You can select a scenario and adjust the ratings based on your specific context.
After calculating a risk score, the tool provides actionable recommendations based on the risk level. Critical and high risks typically require immediate action and mitigation strategies. Medium risks should be monitored and addressed within a defined timeframe. Low risks may be accepted or addressed as resources allow.