skip to content

How do you anchor risk-matrix impact bands so two raters land on the same cell?

level: seniorimportance: should knowfreq 46%

answer

  1. the adjectives are doing no work
  2. define it before the argument starts
  3. observable outcomes in product nouns
  4. shared skeleton, product-specific anchors
  5. double-rate old threats and compare cells

basics

~20 s

Replace adjective labels like Major with concrete, observable outcomes in the product's own vocabulary — for a photo-sharing service, Impact 4 means any cross-account read of another user's private media. Write the anchors before the rating argument, then calibrate them on past threats.

solid answer

~50 s

An unanchored band is just a synonym: "Impact 4 = Major" tells a rater nothing, so the cell they pick reflects their temperament rather than the threat. An anchor names an outcome you could observe and check — for a photo-sharing service, `Impact 4 = an authenticated stranger reads another account's private media; Impact 5 = the same at bulk scale, or with no account required`. Good anchors are observable, written in the product's own nouns, bounded so they say what falls *outside* the band, and agreed before anyone has a finding to defend. Then calibrate: have two people independently rate eight or ten already-settled threats and compare cell by cell. The band whose wording split them is the one to rewrite. Where one corporate scale spans very different products, keep a shared band skeleton and let each product write its own anchor table under it.

go deeper

for a junior

Know that a matrix band needs a written definition and that adjectives like Major are not one. Be ready to point at a band and ask what concrete outcome it means for this specific product.

for a middle

Explain how an anchor is built: an observable outcome, in the product's vocabulary, bounded against the neighbouring bands, and written before any live rating. Be able to turn a vague band into an anchored one on the spot.

for a senior

Show you have run this. Talk about calibrating anchors by double-rating settled threats, diagnosing which band's wording caused a split, and holding the line when the owner of a finding argues their rating up or down.

for a principal

Own the two-layer scale across a portfolio: what the organisation fixes centrally versus what each product defines locally, and how you keep ratings comparable across teams without making the scale useless for any of them.

## The problem anchors solve A risk matrix is only worth drawing if two competent people, handed the same threat, put it in the same cell. Without that, the grid is a device for laundering opinion into a colour. The usual reason they land differently is that the bands are defined by adjectives — Negligible, Minor, Moderate, Major, Catastrophic — which are synonyms for the rank position rather than definitions of it. Asked what separates Moderate from Major, an unanchored team argues about vocabulary. ## What an anchor is An anchor is a **concrete, checkable outcome** attached to a band. Compare: - Unanchored: `Impact 4 = Major business impact.` - Anchored, for a photo-sharing service: `Impact 4 = any cross-account read of another user's private media by an authenticated stranger, one account at a time. Impact 5 = the same read at bulk scale, or achievable with no account at all.` Four properties make an anchor work: - **Observable.** After an incident you could say plainly whether the described thing happened. - **In the product's own nouns.** "Private media", "another account", "bulk" beat "confidentiality breach". - **Bounded.** It says what falls outside as well as inside, so the neighbouring bands do not overlap. The step from 4 to 5 above is scale and required access, stated explicitly. - **Written first.** Anchors agreed before there is a finding to defend are wildly cheaper than anchors negotiated while someone's release date depends on the answer. The likelihood axis needs the same treatment: bands anchored on the preconditions an attacker must satisfy rather than on words like "Possible". Keep the two axes' anchors independent — an anchor that smuggles impact into the likelihood definition makes the cell double-count. ## One scale, very different products The hard case is a corporate 5x5 shared by, say, an identity platform team and a marketing microsite team. Under the shared grid, "Medium" comes to mean opposite things: a defaced microsite page in one review, something close to cross-tenant token issuance in the other. Two responses fail. Letting each team invent its own scale destroys any comparison across the portfolio. Forcing one literal anchor list on both makes it meaningless for at least one of them. The working answer is a **two-layer scale**: the organisation fixes the band count and the *business* meaning of each band (roughly what class of harm, disruption or regulatory exposure a band represents), and each product writes its own anchor table mapping its concrete outcomes onto those bands. The identity team's Impact 5 and the microsite team's Impact 5 then describe different technical events but comparable business consequences, which is exactly what a shared scale is for. ## Calibration: how you find out whether it worked Anchors are a hypothesis until tested. Take eight to ten threats already settled and uncontroversial. Two raters score them independently, without conferring. Then compare cell by cell and look at *where* they diverged, not just how often. A split on one particular band boundary is a wording defect in that band; a scattered split suggests the axis itself is not anchored at all. Rewrite, re-test, and keep the settled cases as a precedent table — over time the accumulated worked examples do more for repeatability than the prose definitions do. ## The failure modes anchors actually fix - **Central tendency.** With vague bands, the middle is the safe choice for a rater who does not want to be wrong, and ratings pile up in the centre. - **Advocacy drift.** The person who found the issue rates it higher; the person who must fix it rates it lower. An anchor moves the argument from "how bad is it" to "did this outcome occur", which is answerable. - **Drift over time.** Last year's Major quietly becomes this year's Moderate as the team's tolerance shifts. Written anchors and precedent make the drift visible and deliberate. ## What anchoring does not fix Anchoring makes bands repeatable; it does not make the scale a measurement. The bands remain ordinal, so you still cannot multiply or average them. It also cannot supply judgment about harm nobody has yet experienced — for a novel threat class the anchors are an argument-starter, not an oracle. And an anchored, repeatable, beautifully documented rating that never changes what the team builds next is still theatre. Repeatability is a precondition for the matrix being useful, not proof that it is.

  • Does moving from a 3x3 to a 5x5 grid improve repeatability?
    Not on its own. More cells without anchors give raters more places to disagree and dress the result up as extra precision. Anchor the bands first; only then ask whether your decisions actually need five levels of impact. Many teams find three well-anchored bands separate work better than five vague ones, and the extra resolution is worth adding only when a real decision hinges on it.
  • How do you keep 'Medium' meaningful across an identity platform and a marketing microsite sharing one corporate scale?
    Split the scale into two layers. The organisation owns the band count and the business meaning of each band — the class of harm, disruption or regulatory exposure it represents. Each product owns an anchor table mapping its own concrete outcomes onto those bands. The two teams then describe different technical events at Impact 4 while making comparable business claims, which is the only way a shared scale stays comparable.
  • How do you prove your anchors are working?
    Measure it. Have two people independently rate a sample of already-settled threats and compare the exact cells, not just the final colour. Look at where the divergence clusters: a repeated split at one boundary is a wording defect in that band, while scattered disagreement means the axis is not really anchored. Rewrite, re-test, and keep the settled cases as precedent for future raters.

A wine label that says 'good' helps nobody agree. One that says 'grapes from this valley, this year, aged three years' lets two people check the same facts and reach the same verdict.

saying these in an interview costs you the question

  • Treats Major, Moderate and Minor as definitions
  • Writes the anchors after the disagreement, to win it
  • Adopts a generic corporate scale unchanged for every product
  • Assumes more bands means more accurate ratings
  • Never checks whether two raters actually agree

context