Skip to content
← Threat modelling and risk for people at risk

Lesson 3 of 4 · 9 min

Assets, threats, and choosing controls in proportion

A small, repeatable risk analysis: what you have, what could go wrong, how likely and how bad, and which controls actually match that.

Security effort is finite: time, money, and how much friction you and your colleagues will tolerate before giving up on a safeguard. NIST Special Publication 800-30, the US government’s risk assessment guide, exists to make that effort land where it matters. It defines risk assessment as “the process of identifying, estimating, and prioritizing risks”, and its core idea scales down easily: a two-person NGO can walk through the same four questions a large agency does, just faster and with less paperwork.

The four terms that make risk assessment work

TermNIST definition (paraphrased)A concrete example
AssetSomething you value and would suffer from losingA source’s identity; a client’s case file; a donor list; the org’s email account
ThreatAny event with the potential to cause harm through unauthorised access, disclosure, or disruptionA phishing message; a lost laptop; a subpoena; a former employee with old credentials
VulnerabilityA weakness that a threat could exploit or triggerNo screen lock; one shared password; unpatched software; a public donor spreadsheet link
Likelihood and impactHow probable the threat is, and how bad it would be if it happenedA phishing attempt: likely, moderate impact. A subpoena for the same inbox: less likely, severe impact

A worked example: the donor list

Take a small NGO’s donor spreadsheet, kept in a shared cloud folder. The asset is the donors’ names, emails and gift amounts. A plausible threat is a phishing email to whoever has edit access, aiming to steal their login. The vulnerability is that the folder link only needs a password, not a second factor, and that password is reused elsewhere. Likelihood is meaningful (phishing is common, per the previous lesson), and impact is real but not catastrophic: embarrassment, possibly some donor concern, not physical danger. That combination points to proportionate controls: multi-factor authentication on the account, a unique password, and limiting edit access to people who actually need it — not, for example, taking the list offline entirely or buying enterprise security software the organisation cannot maintain.

A worked example: the source’s identity

Now take a journalist’s knowledge of a confidential source inside a government agency. The asset is the source’s identity. The threat is a state actor with legal power to demand records, and enough motivation to actually use it (recall the adversary model from the first lesson: this actor has real resources and low risk aversion). The vulnerability might be that the reporter’s phone carrier logs who called whom, or that notes exist in an ordinary, unencrypted notes app. Likelihood may be lower than the phishing case, but impact is severe — the source could lose their job, freedom, or safety. That combination justifies controls disproportionate to the donor-list example: separate devices for sensitive reporting, communication over Signal rather than plain calls or texts, and, per the next lesson, treating this as a case for expert help rather than self-taught defences.

Matching effort to risk, not to fear

NIST 800-30 frames this as evaluating risk “with respect to technology, processes, individuals, [and] the enterprise” and choosing a response: accept a small risk, reduce it with a control, or in rare cases transfer or avoid it entirely (for example, by simply not keeping a piece of information at all). The discipline is resisting two opposite mistakes: treating every risk as catastrophic, which burns out people and budgets on controls nobody keeps up, and treating every risk as acceptable, which leaves the one real threat unaddressed. A five-minute version of this analysis, written down and revisited when circumstances change, beats an unwritten sense that “we should probably be more careful”.

A short checklist to reuse

  • List the two or three things you would least want exposed, lost, or destroyed.
  • For each, name the realistic adversary from the first lesson — not the scariest one you can imagine.
  • Name one concrete weakness that adversary could actually use.
  • Rate likelihood and impact honestly, then pick a control sized to that rating.
  • Write the decision down; revisit it if your work, your data, or the adversary changes.

Key takeaways

  • Risk assessment identifies assets, threats and vulnerabilities, then estimates likelihood and impact before choosing a response.
  • NIST SP 800-30 defines risk assessment as identifying, estimating and prioritising risk, not eliminating it.
  • The same asset can require very different controls depending on the realistic adversary and the impact of failure.
  • Controls should be proportionate: too little leaves real risk unaddressed; too much burns out people and budgets.
  • A short, written risk analysis beats an unwritten sense of “we should be careful”, and should be revisited when things change.

Check yourself

  1. 1. In risk analysis terms, what is a “vulnerability”?

    • The person or group that wants to cause harm
    • A weakness that a threat could exploit or trigger — Right.
    • The value of what you are protecting
    • A tool used to defend a system

    NIST defines a vulnerability as a weakness in a system, procedure, or implementation that a threat source could exploit.

  2. 2. Why might the journalist’s source-identity risk justify stronger controls than the NGO’s donor-list risk, even if the donor-list threat is more likely?

    • Likelihood is the only factor that matters
    • Impact matters too, and losing a source can mean severe, irreversible harm — Right.
    • Journalists always face more threats than NGOs
    • Donor lists are never worth protecting

    Risk combines likelihood and impact. A less likely but far more severe outcome can justify stronger controls than a more likely but milder one.

  3. 3. What does NIST SP 800-30 recommend doing with an identified risk?

    • Always eliminate it completely, regardless of cost
    • Ignore risks below a fixed threshold
    • Choose a proportionate response: accept, reduce, transfer, or avoid it — Right.
    • Buy the most expensive available security product

    Risk management involves weighing options and selecting a response sized to the risk, not applying one fixed reaction to every case.

Do it with FireAI

Put this lesson into practice on your own Mac.

Sources

Put it into practice on your Mac

Try every feature free for 17 days, no card needed.

Download for Mac Docs