Risk Assessment

The process of analyzing identified risks to estimate their likelihood and potential impact.

Key Points

  • Performed after risk identification to analyze probability and impact.
  • Includes qualitative methods (scoring, ranking) and quantitative methods (numerical analysis, simulations).
  • Results guide prioritization, response planning, and contingency reserves.
  • Uses inputs like risk statements and historical data; outputs include risk ratings and updates to the risk register.

Example

After listing risks on a software project, the team estimates the chance and impact of a critical vendor delay (40% probability, high schedule impact). They rank it as a top risk and plan mitigation steps such as securing a backup supplier.

PMP Example Question

After identifying risks, a project manager leads a session to estimate each risk's probability and potential effect to prioritize the list. What process is being performed?

  1. Risk identification
  2. Risk assessment
  3. Risk response planning
  4. Risk audit

Correct Answer: B — evaluating and estimating identified risks

Explanation: Risk assessment analyzes known risks to estimate probability and impact for prioritization. Identification creates the list, response planning selects actions, and audits review effectiveness.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Become an AI-First Agile Leader!

HK School of Management empowers you to master AI as your most powerful co-pilot—without the complexity. Transform your agile leadership with practical, prompt-based workflows and proven strategies designed for real-world scrum challenges. For the price of lunch, you get the tools to automate mundane tasks, refine backlogs with precision, and drive unprecedented efficiency in your team. Backed by our 30-day money-back guarantee—zero risk, real impact.

Learn More