Score inherent risk before any control credit from threat, exposure and vulnerability against asset value, data sensitivity and regulatory reach.
Inherent risk deliberately ignores your controls: exposure is scored on where the asset sits, threat on who would want it, and vulnerability on how maintainable the technology is. The impact side leans hardest on data sensitivity because that is what drives both regulatory consequence and attacker motivation, and asset value enters as a band rather than a raw figure so a rounding error in the valuation cannot swing the score. You cannot demonstrate that a control is worth its cost without a credible before figure, and inherent risk is also what an auditor asks for when they want to know why a control exists at all. It is a management estimate, not a measured probability.
Inherent Risk
Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band.
Monetary inherent risk
SLE = asset value × expected loss share; inherent ALE = SLE × uncontrolled annual rate of occurrence.
Inherent risk = likelihood × impact, where likelihood = 0.40 × threat + 0.35 × exposure + 0.25 × vulnerability and impact = 0.40 × sensitivity + 0.25 × regulatory exposure + 0.35 × asset value band. Inherent risk deliberately ignores your controls: exposure is scored on where the asset sits, threat on who would want it, and vulnerability on how maintainable the technology is. The impact side leans hardest on data sensitivity because that is what drives both regulatory consequence and attacker motivation, and asset value enters as a band rather than a raw figure so a rounding error in the valuation cannot swing the score.
You cannot demonstrate that a control is worth its cost without a credible before figure, and inherent risk is also what an auditor asks for when they want to know why a control exists at all. It is a management estimate, not a measured probability.
This calculator takes 8 inputs: Threat actor capability and intent, Attack surface exposure, Prevalence of known weaknesses in this technology, Asset replacement and revenue value, Data sensitivity, Regulatory and contractual exposure, Expected loss as a share of asset value if realised, Annual rate of occurrence with no controls. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
It is a modelling convention: risk as it would be if the controls were removed. Some frameworks skip it and score current risk directly, which is defensible but makes it impossible to show what the control estate is buying you. Where inherent risk gets abused is when it is inflated to make a control programme look successful.
Because valuations are rough and a 5×5 matrix cannot carry that precision. Decade bands keep the score stable when someone revises the number from £900k to £1.1m, and the monetary ALE output is there for when you do want the currency figure.