skip to content

How do you set a modeled threat's impact rating without inflating every finding to critical?

level: seniorimportance: should knowfreq 56%

answer

  1. Worst credible, not worst conceivable
  2. Assume success; likelihood holds the odds
  3. Stop at what the attacker position reaches
  4. Downstream attacks are separate rows
  5. Business harm needs its owner in the room

basics

~20 s

Rate the worst credible loss this one threat delivers, not the worst story you can tell. Name what is reached, cap it at what the attacker's position gives them, then translate that into business and regulatory harm.

solid answer

~50 s

I rate impact assuming the threat succeeds — likelihood already carries the probability — and then bound it by what the attacker's position actually reaches. Take an SMS appointment-reminder gateway for a veterinary chain where message identifiers are sequential: an anonymous caller can walk the range and read every reminder. The reachable set is not one record, it is every owner name, phone number, pet and appointment time across every clinic on the platform. Technically that is a confidentiality loss with no integrity or availability effect and no credentials exposed. In business terms it is a privacy breach affecting every client of every customer clinic, reputational damage with the clinics that resell the service, and likely notification duties. What I do not do is chain it onward into a hypothetical fraud campaign; that is a separate threat with its own likelihood.

go deeper

for a junior

Be ready to say impact is what is lost if the attack works, rated as though it does work, and that how hard the attack is belongs to likelihood instead. Name the asset, not just a severity word.

for a middle

An interviewer expects you to bound impact by what the attacker's position reaches: which asset, which dimension, how many records or tenants, and whether the loss can be undone. Show that read-only exposure has no integrity or availability dimension.

for a senior

Demonstrate the discipline that stops inflation: refuse to chain speculative follow-on attacks into one rating, insist on the business and regulatory translation from the person who owns it, and state explicitly what the threat does not affect.

for a principal

Own the calibration problem. Define what each impact band means in terms of named assets and outcomes so ratings survive a change of rater, and defend why a model where everything is critical is worse than no ratings at all.

## Worst credible, not worst conceivable Every impact discussion drifts upward, because you can always append "and then the attacker could...". Left unchecked, every threat in the model reaches critical, the ratings stop distinguishing anything, and the fix order silently reverts to whoever argues hardest. The discipline that stops the drift is to rate the **worst credible** loss — the worst outcome that follows from this threat, from this attacker position, with no further assumptions — rather than the worst outcome you can construct with enough narrative. ## Assume success; likelihood carries the probability Impact is conditional. Rate it as if the attack happened, every time. "But they would need to be on the internal network" is a true and important statement that belongs entirely on the likelihood axis; repeating it as a reason to lower impact double-counts the difficulty and hides how bad the failure would be. Keeping the axes clean is what makes the shape of a risk visible later — you need to be able to see "unlikely but ruinous" as a distinct thing from "likely and annoying". ## Bound it by what the attacker position reaches Ask what set of data or functions this threat exposes, and stop at the edge of that set. - **Which asset**: personal data, money, availability of a function, credentials, source-code or model IP, the truth of the audit record. - **Which dimension**: is it disclosure, corruption, destruction, denial, or loss of traceability? A read-only enumeration flaw has no integrity or availability dimension at all, and saying so is part of the rating. - **How much**: one record, one tenant, or the whole platform. With sequential identifiers the honest answer is the whole reachable range, not the single record in the report — assuming the attacker stops at one is the mirror-image error to catastrophising. - **How reversible**: money can sometimes be recovered, a service can be restarted, disclosure cannot be undone. Irreversibility legitimately pushes a rating up. ## Translate to business and regulatory harm — with the owner of that harm A technical statement like "confidentiality loss" does not decide anything. Someone has to say what it costs: contractual exposure with the clinics reselling the service, reputational damage in a market that runs on trust, the operational cost of notifying affected people, and whatever duties attach to personal data in the jurisdictions involved. That translation is not an engineer's call to make alone. In the veterinary reminder case, the fields look harmless — a name, a phone number, a pet and a time — but personal-data harm is not measured by field count. The volume, the direct identifiability and the linkage matter: an appointment time is a statement about when someone is out of the house, and the whole set is a ready-made list for targeted social engineering. ## Where to stop the chain The hard boundary is downstream consequences. "The phone numbers enable a phishing campaign, the campaign harvests banking credentials, therefore this is critical" folds three threats into one rating. Each of those steps has its own likelihood and its own controls, and each deserves its own row in the model if it matters. Rating one threat with the accumulated consequences of a chain both overstates it and makes it impossible to see which fix actually helps. ## Controls: usually likelihood, sometimes impact A control that makes an attack harder to reach moves likelihood. A control that limits what a successful attack gets moves impact — per-tenant partitioning so one caller cannot walk across clinics, short-lived unguessable identifiers so the reachable window is minutes rather than the whole history, or a value cap on a transaction. Being able to say which of the two a proposed mitigation buys you is a large part of what an interviewer is listening for, because it determines whether the fix changes the rating at all. ## Say the rating with its reasoning attached "High impact: confidentiality loss of directly identifying personal data for every client of every clinic on the platform, unrecoverable once disclosed, with notification and contractual exposure; no integrity, availability or credential impact." That sentence names the asset, the dimension, the volume, the reversibility, the business harm, and — just as usefully — what is *not* affected. A rating without those clauses is a number someone else has to take on faith, and it is the first thing challenged when the fix competes for a sprint.

  • The team says a leak of names and phone numbers is low impact because no passwords are involved. How do you push back?
    Privacy harm is not measured by field count. These records directly identify a person, cover every client of every clinic on the platform, and the appointment time is itself sensitive because it says when someone is away from home. The set is an ideal targeting list, the disclosure cannot be reversed, and notification duties attach to personal data regardless of whether a credential was involved. Absence of passwords bounds the credential dimension; it does not bound the privacy one.
  • Should an existing control lower the impact rating?
    Only if it limits what a successful attack obtains. Most controls make the attack harder to reach, which is a likelihood reduction, and moving them onto the impact axis double-counts them. Controls that genuinely lower impact cap the blast radius: per-tenant partitioning so one caller cannot cross clinics, short-lived unguessable identifiers that shrink the reachable window, or a value ceiling on a transaction. Being able to name which axis a mitigation moves is what makes the rating defensible.
  • How do you keep impact ratings comparable across threats rated by different people?
    Rate against named assets rather than adjectives. Agree in advance what a loss of the customer record set, of a day of a revenue-earning function, or of the audit trail is worth, so a rater is choosing between concrete described outcomes instead of inventing a severity word. Then require every rating to state the asset, the dimension and the volume reached. Ratings you can read back and challenge stay comparable; bare severity labels never do.

Rate the fire that this fault plausibly starts in this building — not the fire that spreads through the whole street once you have added enough what-ifs.

saying these in an interview costs you the question

  • Lowers impact because the attack is hard to reach
  • Chains hypothetical follow-on attacks until everything is critical
  • Calls personal-data exposure trivial because no passwords leaked
  • Assumes the attacker stops at the one record in the report
  • Lets the implementing engineer decide the business harm alone
  • Gives a severity word with no asset or volume attached

context