
THREAT‑WATCH
Glossary
Risk Assessment
The structured process of identifying, analyzing, and prioritizing security risks based on likelihood and potential impact.
A risk assessment inventories assets, identifies threats and vulnerabilities affecting them, and estimates the likelihood and business impact of each risk materializing, producing a prioritized list that guides where security investment goes. NIS2, ISO 27001, and GDPR all require some form of ongoing risk assessment, not a one-time exercise, since the threat landscape and business environment both change.