Business Profile & Industry Threat Library
The Proprietary methodology starts with governance and context: know your organization before you assess. Set your industry and size to get relevant threat suggestions with starting AROs, then add them to the risk register and refine each one.
24 sectors from the Allianz Risk Barometer 2025.
Used for the peer benchmark list.
Location drives natural-hazard AROs — tune suggested values per site.
Your profile and register autosave to this browser (localStorage). Use Save JSON in the header for a portable backup you can re-import on any machine.
Top Risks for Your Industry
Source: Allianz Risk Barometer 2025 (3,778 respondents, 106 countries). Percentages = share of respondents in this sector selecting the risk.
Peer Benchmark by Company Size
Top 10 risks reported by companies of your size band — useful when your sector isn't listed or as a cross-check.
Threat Catalog — Browse by Category
Threat taxonomy from the RMLE-2000 "Threat AROs by Location" workbook. Each threat carries a suggested starting ARO — the course method is to refine these using your own incident history, statistics, and location data (e.g., a hurricane ARO in Miami is very different from Denver). Click a threat to add it to the register.
ARO Conversion Scale Reference (frequency → ARO value)
Risk Appetite, Tolerance Levels & Rating Definitions
Per Proprietary Methodology Lesson 1, senior leadership sets risk tolerance before the risk assessment is conducted, and reviews it periodically — particularly after a change in management. Tolerance levels set here directly drive the register: impact-type weights adjust risk scores, and threat-type tolerances flag risks that exceed what leadership will accept.
The total amount of risk the organization is prepared to accept, tolerate, or be exposed to at any point in time (BCI/DRJ). Typical drivers: fear of lawsuits, cost of controls, compliance requirements, internal politics, reputation.
Risk Tolerance by Threat Type
How much risk will leadership live with, per threat category? Low tolerance = least willing to accept — register risks in that category are flagged when their risk band exceeds the tolerance level. Defaults follow the RMLE-2000 Risk Tolerance Matrix sample.
Risk Tolerance by Impact Type — Scoring Weights
Tolerance converts to a numeric weight multiplied against each risk's impact rating: Low = 1.00, Medium = 0.75, High = 0.50, Critical = 0.25. The less tolerance you have for an impact type, the more weight it carries in prioritization. Weighted score = I × T × V × weight.
Qualitative Rating Definitions (Critical / High / Medium / Low)
Methodology: "Establish definitions for the qualitative ratings of Critical, High, Medium, and Low for Impact, Threat, and Vulnerability" during governance, before assessing. Pre-filled with the RMLE-2000 course definitions — edit to fit your organization (e.g., adjust the dollar bands to your scale). These are your documented, defendable rating criteria.
RASCI — Who Is Accountable & Responsible
Key governance activities and their owners (from the RMLE-2000 RASCI Matrix pattern: executives own policy, tolerance, and risk decisions; the CRO and Risk Committee run the process; analysts do the analysis). Exactly one Accountable per activity. Edit the roles to match your organization.
| Governance Activity | Accountable (owns outcome) | Responsible (does the work) |
|---|
Guided Risk & Vulnerability Assessment Walkthrough
Answer step-by-step questions to automatically compute metrics across risk assessment, financial ALE, and legal justification frameworks.
Step 1: Identify the Asset & Financial Scope
Specify what critical business asset or operation is being evaluated for potential disruption.
e.g., Corporate Headquarters, Customer Billing Database, Logistics Fleet.
Categorization based on operational resilience standards.
Enter directly, or build it from the Proprietary monetary-impact components below.
Asset Value Worksheet (Proprietary ALE Step 1 — six monetary impact components)
Worksheet total: $0 — typing in any component writes the sum into Total Asset Value above.
Step 2: Evaluate Consequence & Loss Severity (Impact - I)
If an undesirable event occurs, how severe is the operational, human, or financial damage?
What kind of loss dominates this scenario? Leadership's tolerance for this impact type (set in ) weights the risk score:
Step 3: Identify Threat Scenario & Annual Frequency
Describe the hazard or adversary and estimate how often this threat is expected to materialize.
Populated from your industry's top risks and the Threat catalog. Set your industry in the tab. For a rigorous T score (Intent + Capability + Location × EF × ARO), use the .
e.g., Flood, Power Grid Outage, Cyber Intrusion, Supply Chain Failure.
Expected incidents per year (e.g., 0.5 = once every 2 years; 2.0 = twice a year).
The result is compared against leadership's tolerance for this threat category (set in Governance) to flag risks exceeding tolerance.
Step 4: Evaluate Vulnerability & Existing Safeguards
Analyze system weaknesses and existing controls to establish the Vulnerability score ($V$).
% of total asset value destroyed if threat materializes with current controls.
Step 5: Proposed Safeguard & Multi-Framework Synthesis
Specify new mitigation controls to generate the comprehensive risk report across all frameworks.
Primary Cloud Data Platform
Executive Decision & Recommendation:
Loading recommendation...
Total Identified Risks
0
Total Pre-Mitigation ALE
$0
Post-Mitigation ALE
$0
Net Annual Cost Benefit
$0
Interactive Risk Assessment Spreadsheet
| # | Asset Name & PIEFAO Category | Threat Scenario | Asset Value ($) | Exp % (EF) | Rate (ARO) | Pre ALE ($) | Impact (I) | Threat (T) | Vuln (V) | Risk Score | Risk Level | Control Cost ($) | Post ALE ($) | ROI % | Risk Owner | Treatment | Status | Next Review | Action |
|---|
Pre vs. Post Mitigation Annualized Loss Expectancy (ALE)
Risk Profile Distribution (R = I × T × V)
Treatment Decisions, Countermeasure Packages & Residual Risk
Proprietary treatment options: Accept the risk, Mitigate with countermeasures, Transfer it (insurance/contract), or Avoid the activity. Build countermeasure option packages, check the cost rule (control cost should not exceed the ALE), then re-rate the risk to confirm the residual sits within tolerance.
Countermeasure Library (RMLE-2000 Lesson 3)
Click a control to add it to the selected risk's plan. Layer controls across the 3 D's — Deter, Detect, Delay.
Cost heuristics: physical = high upfront + ongoing maintenance • procedural = low upfront + ongoing training • logical = varies with sophistication.
Countermeasure Plan for Selected Risk
Assign each control to option packages: P1 Maximum Protection (benchmark — best regardless of cost), P2 Recommended (balanced), P3 Least Expensive.
Option Package Comparison
Proprietary cost-benefit rule: the annual control cost should not exceed the risk's Pre-ALE. Adopt a package to write its total into the register row's Annual Control Cost.
Post-Treatment Residual Risk (Re-Scoring Loop)
Methodology: after selecting countermeasures, go back to your ratings and re-evaluate — controls principally reduce Vulnerability, and may also affect Threat and Impact. Re-rate below (use the Vulnerability Calculator definitions), then confirm the residual band sits within leadership tolerance.
DAR — Decision Analysis & Resolution Matrix
Structured, criteria-based selection between alternatives (e.g., competing controls, vendors, or option packages). Weights must sum to 100%; score each alternative 1–10 per criterion; highest weighted total wins. Document the justification for traceability.
Risk Assessment Report Generator
Builds the leadership report from your live register using the RMLE-2000 template: executive summary, risk profile, tolerance exceptions answering management's five questions, buy-down schedule, and control costs. Timeliness beats polish — generate and brief.
Program Maturity Scorecard — LAMRA
The Key Success Factors: Leadership, Awareness, Measures, Resources, Action. Ten checks per factor, each worth 10%. Lack of Leadership is the #1 reason programs fail; lack of Resources is #2 (and is itself "a form of risk tolerance that may result in negligence"); lack of timely Action is #3. Your lowest-scoring factor is where to invest first.
Note: the course also uses LAMRA for the risk management lifecycle — Look, Assess, Manage, Review, Apply.
Determination Guide: Impact, Threat & Vulnerability
Objective decision criteria, quantitative thresholds, and triage rules for risk rating.
1 Consequence & Loss Severity: Impact (I)
If an undesirable event carries any credible risk of fatality or permanent disability, it automatically elevates to Critical (71.0) regardless of financial loss.
Proprietary Methodology cost bands: loss > $1,000,000 = Critical (71.0). Loss $501k–$1M = High (25.0). Loss $251k–$500k = Medium (5.0). Loss < $250k = Low (2.0).
If disruption exceeds the Maximum Tolerable Period of Disruption (MTPD) causing cascading enterprise failure, rate as High or Critical.
| Band | Midpoint | Financial Loss | Human & Operational Criteria | Business Continuity Criteria |
|---|---|---|---|---|
| Low (1-3) | 2.0 | < $250,000 | Little or no impact on human life or business operations. | Absorbed within routine RTO limits. |
| Medium (4-13) | 5.0 | $251k - $500k | Loss of sensitive data or costly equipment; significant inconveniences. | Essential function disruptions recovered within RTOs. |
| High (14-49) | 25.0 | $501k - $1M | Reputation/morale damage, bad publicity, lawsuits. | Essential function disruption exceeds RTOs. |
| Critical (50-100) | 71.0 | > $1,000,000 (> 60%) | Fatalities / loss of life, permanent shutdown, collapse. | Complete failure of primary mission functions. |
2 Threat Likelihood & Frequency (T)
| Band | Midpoint | Annual Rate (ARO) | Adversarial Threat Indicator | Natural / Hazard Indicator |
|---|---|---|---|---|
| Low (0.01-0.24) | 0.12 | < 0.10 (< 1 in 10 yrs) | No known adversary has intent or capability. | No historical precedence in geographic region. |
| Medium (0.25-0.49) | 0.37 | 0.10 - 0.50 (1 in 2 to 10 yrs) | Capability exists, but asset is a secondary target. | Occurs rarely in region (10-yr storm event). |
| High (0.50-0.74) | 0.62 | 0.50 - 1.00 (1 in 1 to 2 yrs) | Active intent and verified capability; peers targeted. | Frequent seasonal occurrence (annual severe weather). |
| Critical (0.75-1.00) | 0.87 | > 1.00 (Multiple/yr) | Definite threat; active targeting confirmed by intel. | Continuous exposure (active flood zone, daily probes). |
3 Vulnerability Exposure Rubric (V)
| Band | Midpoint | Countermeasure State | Vulnerability Description |
|---|---|---|---|
| Low (0.01-0.24) | 0.12 | > 80% Effective (Defense-in-Depth) | Multi-layered redundant controls active; bypass virtually impossible. |
| Medium (0.25-0.49) | 0.37 | 50% - 80% Effective (Primary Controls) | Good primary safeguards, but at least 1 secondary gap exists. |
| High (0.50-0.74) | 0.62 | 20% - 50% Effective (Partial Safeguards) | Controls incomplete; multiple gaps allow standard threat entry. |
| Critical (0.75-1.00) | 0.87 | < 20% Effective (No Safeguards) | No active controls; system completely exposed to trivial attack. |
Analytical Risk Formula Calculator
Formula: Risk Score = Impact × Threat × Vulnerability
Represents consequence/loss amount across PIEFAO assets (People, Info, Equipment, Facilities, Ops, Other).
Likelihood that an adversary or natural hazard will initiate an undesirable event.
Degree of susceptibility or ease with which controls can be bypassed.
Scale Guidance:
- Low: 1.00 to 3.00
- Medium: 4.00 to 13.00
- High: 14.00 to 49.00
- Critical: 50.00 to 100.00
Financial Risk & Annualized Loss Expectancy (ALE) Calculator
Quantitative Financial Loss Formulas: SLE = AV × EF and ALE = SLE × ARO
1 Baseline Risk Inputs (Pre-Control)
Replacement, business value, or recovery cost of asset.
% of asset lost during event.
Estimated occurrences per year.
2 Countermeasure & ROI Analysis (Post-Control)
Total annual cost of implementing and maintaining safeguard.
Threat Calculator
RMLE-2000 Threat Calculator workbook: T = (Intent + Capability + Location) × Exposure Factor × ARO, capped at 0.99.
Threat Context & Intelligence (documented — does not enter the math)
Scored Factors
Vulnerability Calculator
RMLE-2000 Vulnerability Calculator workbook: V = CM Effectiveness + Internal Weaknesses + Asset Attractiveness. Note: "Unknown" answers are penalized almost as heavily as "Yes" — uncertainty itself is treated as vulnerability.
1 Countermeasure (CM) Effectiveness Review
Rate the six control families protecting this asset. Stronger defenses carry lower correlation factors (Tested Defense in Depth = 0.0083 ... Poor Security = 0.0550; N/A = 0). Subtotal max 0.33.
2 Internal & Administrative Weaknesses
Yes = 0.055 • Unknown = 0.02285 • No = 0. Answer honestly — an "Unknown" costs nearly half a "Yes".
3 Asset Attractiveness
How appealing and reachable is this asset from the threat's perspective? Subtotal max 0.33.
Post-countermeasure loop (Proprietary): after adding controls, re-rate Section 1, apply the new lower V, and compare the new risk score.
Cost of Prevention (COP) Legal / Economic Framework
Formula: C = P × M (Hand Rule for Safeguard Justification)
Annual probability of disaster occurring (0.00 to 1.00).
Total direct financial damage if disaster happens.
Cost to implement and maintain preventive controls.
Evaluation & Legal Justification
If prevention cost (C) is less than expected loss (P × M), failing to implement the control is economically inefficient and legally vulnerable.
Standard Rating Scales & Risk Matrix
Qualitative-to-Quantitative conversion midpoints and boundaries.
Impact (I) & Risk Score Scales
| Rating Band | Score Range | Scale Midpoint | Action Guideline |
|---|---|---|---|
| Low | 1 – 3 | 2.0 | Acceptable / Monitor |
| Medium | 4 – 13 | 5.0 | Planned Mitigation |
| High | 14 – 49 | 25.0 | Priority Action |
| Critical | 50 – 100 | 71.0 | Immediate Escalation |
Threat (T) & Vulnerability (V) Probability Scales
| Rating Band | Decimal Range | Scale Midpoint |
|---|---|---|
| Low | 0.01 – 0.24 | 0.12 |
| Medium | 0.25 – 0.49 | 0.37 |
| High | 0.50 – 0.74 | 0.62 |
| Critical | 0.75 – 1.00 | 0.87 |
Impact vs Likelihood (T × V) Risk Matrix
Medium
Medium
High
Critical
Low
Medium
Medium
High
Low
Low
Medium
Medium
Low
Low
Low
Low