This risk matrix template contains the five building blocks of a defensible risk assessment in an ISMS as tables you can rebuild in Excel; this page offers no file download. The building blocks are a likelihood scale with a time reference, an impact scale in euros, a 5x5 matrix with risk levels assigned to each cell, acceptance thresholds with decision authority, and the link to a risk register. A worked example and a checklist before approval complete the template.
Key takeaways
- Every likelihood level needs a time reference, in this template for example “below 5% per year” for level 1.
- You must adapt the euro thresholds of the impact scale to your organization's revenue, earnings or liquidity.
- The 5x5 matrix has 25 cells; derive the risk level in Excel with an INDEX lookup instead of multiplying levels.
- BSI Standard 200-3 recommends no more than five categories per dimension.
- ISO/IEC 27001 clause 6.1.2 requires defined risk acceptance criteria; step 4 of the template documents them.
The template is written for information security officers, risk managers and executives who are setting up a first methodology or want to make an existing traffic-light matrix more defensible. What a risk matrix is and where it reaches its limits is covered in the glossary entry on the risk matrix; how the matrix fits into identification, analysis and evaluation is covered in the entry on risk analysis. Which other techniques come into question alongside the matrix is compared in the guide to risk analysis methods.
Step 1: how do you define the likelihood scale?
Every level needs a time reference, otherwise “rare” means something different in every department. The template shows frequency and annual likelihood side by side, so both ways of thinking lead to the same level.
| Level | Label | Frequency | Likelihood per year |
|---|---|---|---|
| 1 | very rare | less than once every 20 years | below 5% |
| 2 | rare | roughly every 5 to 20 years | 5% to below 20% |
| 3 | possible | roughly every 2 to 5 years | 20% to below 50% |
| 4 | likely | roughly every 1 to 2 years | 50% to below 80% |
| 5 | very likely | once a year or more often | 80% or more |
Step 2: define the impact scale in euros and other dimensions
The euro thresholds are the part of the template you must adapt. BSI Standard 200-3 notes that organizations typically anchor these thresholds in their financial figures, for example a percentage of revenue or the question of whether the organization would remain solvent after the event. The amounts below assume a company with 40 million euros in annual revenue; they are chosen freely and serve purely as illustration.
| Level | Label | Financial (example) | Legal and compliance | Operations | Reputation |
|---|---|---|---|---|---|
| 1 | negligible | below 20,000 euros | no breach | disruption under one hour | not noticeable |
| 2 | limited | 20,000 to below 100,000 euros | minor breach, no reporting duty | outage up to one working day | isolated customer complaints |
| 3 | significant | 100,000 to below 500,000 euros | reportable incident | outage of several days | regional press coverage |
| 4 | severe | 500,000 to below 2 million euros | regulatory proceedings, fine possible | critical processes down for over a week | national press coverage, customer loss |
| 5 | critical | 2 million euros or more | prohibition, personal liability of management | business continuity at stake | lasting loss of trust |
Several impact dimensions: the highest level counts
The rule for multiple dimensions: the highest applicable level counts. An event with little financial damage but a reportable personal data breach is rated level 3, not level 1.
Step 3: how do you assign the cells of the 5x5 matrix?
The cell assignment is a statement about your risk appetite. This template weights impact more heavily than likelihood; change the cells if your executive management weighs things differently.
| Impact / likelihood | 1 very rare | 2 rare | 3 possible | 4 likely | 5 very likely |
|---|---|---|---|---|---|
| 5 critical | medium | high | high | very high | very high |
| 4 severe | medium | medium | high | high | very high |
| 3 significant | low | medium | medium | high | high |
| 2 limited | low | low | medium | medium | high |
| 1 negligible | low | low | low | low | medium |
How do you build the matrix in Excel?
Lay out the matrix with rows running from impact 5 (top) to 1 (bottom) and columns from likelihood 1 to 5, for example in the range B2:F6. With the likelihood level in column G and the impact level in column H, =INDEX($B$2:$F$6,6-H2,G2) returns the risk level as a lookup. To derive a level from a percentage, use =MATCH(E2,$K$2:$K$6,1) with the lower bounds 0, 5%, 20%, 50% and 80% in K2:K6. Avoid the obvious formula of likelihood times impact on level numbers: it produces scores from 1 to 25 whose intervals mean nothing, and it hides the weighting that the cell assignment makes visible.
Step 4: who may accept which risk level?
A matrix without a rule for action produces a list, not a decision. The review intervals in this table are suggestions, not normative requirements.
| Risk level | Meaning | Treatment | Who may accept | Review |
|---|---|---|---|---|
| low | Existing controls protect adequately | no additional control needed | risk owner | annually |
| medium | Controls may not be sufficient | assess treatment and decide with a rationale | head of department with a rationale | every six months |
| high | Protection is not adequate | treatment plan with a deadline is mandatory | executive management, time-limited | quarterly |
| very high | Protection is not adequate, acceptance is the exception | immediate measures, escalation to executive management | executive management, in writing and time-limited | monthly until reduced |
Link to ISO/IEC 27001 and BSI Standard 200-3
The meanings of the levels follow the risk categories of BSI Standard 200-3. ISO/IEC 27001 clause 6.1.2 requires defined risk acceptance criteria; this table is one way to document them.
Step 5: connect the matrix to the risk register
The matrix assesses, the register records the results. Each row of the register is one risk with asset, scenario, likelihood, impact, the risk level from this matrix, expected loss, treatment, risk owner and review date. The full 17 columns with dropdown lists and formulas are in the risk register template; it takes its scales and matrix from this template so that both speak the same language.
Worked example: ransomware on the ERP system
The figures in this example are chosen freely and serve purely as illustration. They use the scales from steps 1 and 2.
| State | Likelihood per year | Impact per event | Cell (L / I) | Risk level | Expected loss per year |
|---|---|---|---|---|---|
| Inherent, no controls | 30% (level 3) | 1,200,000 euros (level 4) | 3 / 4 | high | 360,000 euros |
| Current, with offline backups and endpoint protection | 15% (level 2) | 600,000 euros (level 4) | 2 / 4 | medium | 90,000 euros |
| Residual, after segmentation and a tested recovery | 8% (level 2) | 250,000 euros (level 3) | 2 / 3 | medium | 20,000 euros |
What the ransomware example shows
The example shows the strength and the limit of the matrix at once. Between current and residual risk the level stays at medium, yet the expected loss falls from 90,000 to 20,000 euros. If the planned controls cost 30,000 euros a year, they are set against an expected reduction of 70,000 euros. The matrix cannot make that trade-off; it needs the amount, as the article A heat map cannot answer a budget question argues. Under step 4, accepting the residual risk sits with the head of department, with a rationale and a review in six months.
What should you check before approving the risk matrix?
Before executive management approves the matrix, all eight points on this checklist should be met:
- Every likelihood level has a time reference.
- The euro thresholds are derived from revenue, earnings or liquidity and confirmed by executive management.
- Non-financial dimensions are defined, and the highest applicable level counts.
- The cell assignment is justified and approved.
- Every risk level has a treatment rule, an acceptance authority and a review interval.
- Two departments have rated the same test risks independently and reached the same result.
- The register keeps inherent, current and residual risk apart.
- Every assumption behind an estimate is recorded in one sentence.
From template to living assessment: Rizzqo
A spreadsheet template works as long as the register is small and one person maintains it. It gets harder once assets change, controls are completed and several departments assess at the same time. In Rizzqo, the building blocks of this template are configuration: scale bands translate percentages and euros into your levels, the risk level is a lookup in a configurable matrix, and the expected loss is computed from likelihood and impact. Each risk assessment is linked to the affected assets from the inventory and keeps inherent, current and residual risk apart. Controls are tracked as tasks with a planned reduction in likelihood or impact: while planned, the reduction is reserved; once completed, it lowers the current risk, and tasks sync with Jira in both directions. The euro bands and the cell assignment are a decision for your executive management.