Risk Assessment Panel

OWASP Risk Rating Methodology · All scores 0–9

🎭

Threat Agent Factors

Who is the attacker?
5
Some technical skills
4
Low or no reward
7
Some access required
2
Developers
🕳

Vulnerability Factors

How exploitable is the weakness?
3
Difficult to discover
5
Exploit is available
6
Obvious to defenders
1
Detected and responded
💻

Technical Impact

What is the damage to the system?
6
Extensive critical data disclosed
7
Extensive seriously corrupt data
5
Extensive secondary services interrupted
2
Fully traceable
💼

Business Impact

What is the real-world damage?
7
Significant effect on profit
5
Major accounts lost
2
Minor violation
3
One individual
📊 Risk Assessment Results
Threat Agent Avg
4.5
Agent Score
Vulnerability Avg
3.8
Vuln Score
Likelihood Score
4.1
(Agent + Vuln) / 2
Technical Impact
5.0
Tech Score
Business Impact
4.3
Biz Score
Impact Score
4.6
(Tech + Biz) / 2
MEDIUM

Moderate risk. This vulnerability should be planned for remediation in the next development cycle. Review with your security team and apply appropriate controls.

// Risk Matrix — Likelihood × Impact
LOW Impact MEDIUM Impact HIGH Impact
HIGH Likelihood MEDIUM HIGH CRITICAL
MED Likelihood LOW MEDIUM HIGH
LOW Likelihood NOTE LOW MEDIUM