A mobile operator's risk matrix rates seventy percent of modeled threats amber — what do you change?
answer
- ask what decision it is meant to drive
- look at the distribution, not one rating
- the middle is the safe answer for a rater
- bands should split the population you have
- a forced ranked list beats a recoloured grid
basics
~20 sA matrix that rates most threats alike has stopped discriminating, so it cannot sequence work. Diagnose why first — vague bands, raters avoiding the extremes, or a colour region drawn across too many cells — then re-cut the bands against the real portfolio.
solid answer
~50 sStart by asking what decision the matrix is meant to drive; if nothing gets sequenced, the instrument has failed regardless of how carefully each rating was made. Then diagnose the clustering rather than recolouring it away. Three causes dominate: unanchored bands, where the middle is the safe answer for any rater; genuine sameness, where an availability-focused portfolio really is full of comparable threats and the bands are cut too coarsely to separate them; and colouring, where amber has simply been painted over most of the grid. The fixes differ. Re-anchor and re-cut the bands so they split the actual population you have, not an abstract universal scale. Declare tiebreak criteria in advance for ordering within a band — cost to fix, blast radius, whether exploitation would be visible. And be willing to conclude that a grid is the wrong instrument here and produce a forced ranked list instead.
go deeper
Know that a risk matrix exists to help sequence work, and that a map where nearly everything is one colour has not done its job. Noticing and raising that is enough at this level.
Explain the mechanics of clustering: how vague bands push raters to the middle, how band boundaries cut on absolutes force everything into the centre rows, and how the colour regions are a separate decision from the bands.
Show you can diagnose before acting — separate rater behaviour from genuine portfolio sameness — and then re-cut bands, fix a compressed top band, and define tiebreak criteria that survive people arguing for their own findings.
Own the instrument itself. Be ready to argue that a grid is wrong for this portfolio and replace it with a forced ranked list, and to defend that against the pull of a familiar heat map that rolls up neatly for reporting.
## Read the distribution, not the ratings Any individual rating on a heat map can be defensible while the map as a whole is useless. The matrix exists to answer one question — what do we work on first — and a picture in which seventy percent of modelled threats share one colour answers it with a shrug. The first move is therefore not to adjust a rating but to state the decision the artefact is supposed to drive, and to say plainly that it currently does not. ## Diagnose before adjusting Four causes produce a clumped map, and they need different responses. **Central tendency.** When bands are defined by adjectives, the middle is the least criticisable choice. A rater who picks Moderate on both axes is never obviously wrong. This is a property of the raters and the wording, not of the system, and no amount of recolouring touches it. **Genuine sameness.** For a mobile-network operator, a large share of modelled threats really do fall in the same neighbourhood: various ways of degrading availability for a lot of subscribers, none catastrophic on its own, none negligible. The portfolio is truly bunched, and the bands are cut at the wrong places to separate it. **Bands cut on absolutes.** Corporate scales are often written so that the top bands describe outcomes this particular product cannot produce and the bottom bands describe outcomes nobody bothers modelling. Everything real lands in the middle two rows by construction. **Colouring.** The severity regions painted over the grid are a separate decision from the bands themselves, and drawing amber across a dozen cells guarantees a dominant colour whatever the underlying ratings say. ## What actually restores discrimination - **Re-cut the bands against the portfolio you have.** A scale should split the population you rate. If your threats cluster between two boundaries, the useful move is to place boundaries *inside* that cluster — subdivide the region where your decisions actually live — rather than to keep a scale calibrated for harms your service cannot cause. - **Fix the extremes too.** The mirror failure is range compression: a 5x5 whose top impact band covers both a delayed service and a loss of life. Two outcomes demanding entirely different responses share one cell, and the grid can never tell them apart. Split the band, or lift safety-of-life out of the grid as a separate gate rather than as a matrix row. - **Declare a tiebreak in advance.** Within a band, order by criteria agreed before the ratings exist: cost and structural quality of the fix, blast radius, whether exploitation would be detectable, whether one fix closes several modelled threats at once. Declaring them in advance is what stops the tiebreak becoming advocacy. - **Cap the population if you must.** Some teams impose a discipline that no more than a fixed number of threats may hold the top two colours at once; adding one forces demoting another. Crude, and it does force the conversation the matrix was avoiding. ## Know when the grid is the wrong instrument A matrix converts judgment into a shared picture. When the population is genuinely homogeneous, that picture carries almost no information, and the honest answer may be to abandon the grid for this portfolio. A **forced ranked list** — comparing threats pairwise until you have a total order, then drawing the line where capacity runs out — produces a decision the heat map could not, and it makes the tradeoffs explicit rather than hiding them behind a colour. The cost is that a ranked list does not aggregate or communicate upward as neatly, which is precisely why matrices persist. ## The traps to avoid Recolouring until the picture looks balanced is the most common wrong answer: it changes the presentation and none of the underlying judgments, and it teaches everyone that the colours are negotiable. Adding bands — moving to 7x7 — is the second: more cells on unanchored axes give false precision and more argument. Insisting that every amber item must be fixed is the third; it reads as rigour and is really a refusal to prioritise, which is the same failure the clumped map already represents. ## What an interviewer is listening for This question separates people who maintain a process from people who own a decision. The strong answer treats the clustering as evidence about the instrument, distinguishes causes that live in the raters from causes that live in the system, proposes a fix targeted at the diagnosed cause, and is willing to say that the artefact should change or be dropped. The weak answer adjusts colours until the heat map looks like the ones in the slide deck.
- A rail operator's 5x5 has a top impact band covering both a delayed service and a fatality. What is wrong?That is range compression: one band spans outcomes that demand completely different responses, so the matrix can never distinguish them and the more severe one is effectively invisible. Either split the band so safety-of-life sits alone at the top, or take safety-of-life out of the grid entirely and treat it as a separate gate. A scale whose extreme band swallows your worst case has stopped measuring exactly where it matters most.
- Isn't the fix simply a finer grid, say 7x7?No. Resolution is not the constraint — definition is. Adding cells to axes whose bands are still described by adjectives gives raters more places to disagree and presents the result as extra precision. If the bands are anchored and the population still clusters, the useful move is to move the boundaries into the cluster, not to add more of them everywhere.
- How do you order work within a single colour once you accept some clustering is real?With tiebreak criteria declared before the ratings exist. Useful ones are the cost and structural quality of the fix, blast radius if the threat is realised, whether exploitation would be visible to you, and whether one change closes several modelled threats at once. Declaring them up front is the point: chosen afterwards, they become the vocabulary whoever wants their item first reaches for.
An exam on which almost everyone scores between 60 and 70 has not measured the class. The problem is the paper's spread of difficulty, not the students' marks.
saying these in an interview costs you the question
- Recolours the grid until the picture looks balanced
- Adds more bands and calls the result more precise
- Accepts the clustering without checking rater behaviour
- Insists every amber item must be fixed
- Keeps a matrix that has never changed a plan