Lesson 3 of 4 · 9 min
Assets, threats, and choosing controls in proportion
A small, repeatable risk analysis: what you have, what could go wrong, how likely and how bad, and which controls actually match that.
Security effort is finite: time, money, and how much friction you and your colleagues will tolerate before giving up on a safeguard. NIST Special Publication 800-30, the US government’s risk assessment guide, exists to make that effort land where it matters. It defines risk assessment as “the process of identifying, estimating, and prioritizing risks”, and its core idea scales down easily: a two-person NGO can walk through the same four questions a large agency does, just faster and with less paperwork.
The four terms that make risk assessment work
| Term | NIST definition (paraphrased) | A concrete example |
|---|---|---|
| Asset | Something you value and would suffer from losing | A source’s identity; a client’s case file; a donor list; the org’s email account |
| Threat | Any event with the potential to cause harm through unauthorised access, disclosure, or disruption | A phishing message; a lost laptop; a subpoena; a former employee with old credentials |
| Vulnerability | A weakness that a threat could exploit or trigger | No screen lock; one shared password; unpatched software; a public donor spreadsheet link |
| Likelihood and impact | How probable the threat is, and how bad it would be if it happened | A phishing attempt: likely, moderate impact. A subpoena for the same inbox: less likely, severe impact |
A worked example: the donor list
Take a small NGO’s donor spreadsheet, kept in a shared cloud folder. The asset is the donors’ names, emails and gift amounts. A plausible threat is a phishing email to whoever has edit access, aiming to steal their login. The vulnerability is that the folder link only needs a password, not a second factor, and that password is reused elsewhere. Likelihood is meaningful (phishing is common, per the previous lesson), and impact is real but not catastrophic: embarrassment, possibly some donor concern, not physical danger. That combination points to proportionate controls: multi-factor authentication on the account, a unique password, and limiting edit access to people who actually need it — not, for example, taking the list offline entirely or buying enterprise security software the organisation cannot maintain.
A worked example: the source’s identity
Now take a journalist’s knowledge of a confidential source inside a government agency. The asset is the source’s identity. The threat is a state actor with legal power to demand records, and enough motivation to actually use it (recall the adversary model from the first lesson: this actor has real resources and low risk aversion). The vulnerability might be that the reporter’s phone carrier logs who called whom, or that notes exist in an ordinary, unencrypted notes app. Likelihood may be lower than the phishing case, but impact is severe — the source could lose their job, freedom, or safety. That combination justifies controls disproportionate to the donor-list example: separate devices for sensitive reporting, communication over Signal rather than plain calls or texts, and, per the next lesson, treating this as a case for expert help rather than self-taught defences.
Matching effort to risk, not to fear
NIST 800-30 frames this as evaluating risk “with respect to technology, processes, individuals, [and] the enterprise” and choosing a response: accept a small risk, reduce it with a control, or in rare cases transfer or avoid it entirely (for example, by simply not keeping a piece of information at all). The discipline is resisting two opposite mistakes: treating every risk as catastrophic, which burns out people and budgets on controls nobody keeps up, and treating every risk as acceptable, which leaves the one real threat unaddressed. A five-minute version of this analysis, written down and revisited when circumstances change, beats an unwritten sense that “we should probably be more careful”.
A short checklist to reuse
- List the two or three things you would least want exposed, lost, or destroyed.
- For each, name the realistic adversary from the first lesson — not the scariest one you can imagine.
- Name one concrete weakness that adversary could actually use.
- Rate likelihood and impact honestly, then pick a control sized to that rating.
- Write the decision down; revisit it if your work, your data, or the adversary changes.
Key takeaways
- Risk assessment identifies assets, threats and vulnerabilities, then estimates likelihood and impact before choosing a response.
- NIST SP 800-30 defines risk assessment as identifying, estimating and prioritising risk, not eliminating it.
- The same asset can require very different controls depending on the realistic adversary and the impact of failure.
- Controls should be proportionate: too little leaves real risk unaddressed; too much burns out people and budgets.
- A short, written risk analysis beats an unwritten sense of “we should be careful”, and should be revisited when things change.
Check yourself
1. In risk analysis terms, what is a “vulnerability”?
- The person or group that wants to cause harm
- A weakness that a threat could exploit or trigger — Right.
- The value of what you are protecting
- A tool used to defend a system
NIST defines a vulnerability as a weakness in a system, procedure, or implementation that a threat source could exploit.
2. Why might the journalist’s source-identity risk justify stronger controls than the NGO’s donor-list risk, even if the donor-list threat is more likely?
- Likelihood is the only factor that matters
- Impact matters too, and losing a source can mean severe, irreversible harm — Right.
- Journalists always face more threats than NGOs
- Donor lists are never worth protecting
Risk combines likelihood and impact. A less likely but far more severe outcome can justify stronger controls than a more likely but milder one.
3. What does NIST SP 800-30 recommend doing with an identified risk?
- Always eliminate it completely, regardless of cost
- Ignore risks below a fixed threshold
- Choose a proportionate response: accept, reduce, transfer, or avoid it — Right.
- Buy the most expensive available security product
Risk management involves weighing options and selecting a response sized to the risk, not applying one fixed reaction to every case.
Do it with FireAI
Put this lesson into practice on your own Mac.
- Pick the right security mode for where you are, and use the kill switch — Match FireAI’s strictness to where you are, and know where the emergency stop is.
- Turn on threat lists, and investigate a flagged connection — Go from a red flag to a real answer in one page, without leaving FireAI.
- Investigate a connection — Decide with the facts in front of you, not a vague warning.
Sources
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
- NIST Computer Security Resource Center Glossary: risk assessment
- NIST Computer Security Resource Center Glossary: threat
- NIST Computer Security Resource Center Glossary: vulnerability
Put it into practice on your Mac
Try every feature free for 17 days, no card needed.