The numbers that represent risk in enterprise governance programs — scores, ratings, heat map positions, quantified exposure values — are models of risk built on assumptions, proxies, and simplified criteria. Models are wrong in specific, structured ways. Understanding how your risk numbers are wrong is more valuable than assuming they are right.
The Assumption Architecture of Risk Numbers
Every risk score is built on a set of assumptions. The assumptions determine what the score can detect and what it will systematically miss. In most enterprise risk programs, those assumptions are implicit — embedded in the scoring methodology without being stated, making them invisible to the people who rely on the scores.
The most consequential implicit assumption in most risk scoring models is that the criteria in the scoring methodology capture the dimensions of risk that matter most in the current environment. This assumption was evaluated when the methodology was designed. It was not necessarily re-evaluated when the environment changed, when the threat landscape shifted, or when the organization adopted new technologies that introduced risk categories the methodology was not designed to assess. The methodology runs. The scores are produced. The assumption that the scores reflect the current risk environment is rarely examined.
Five Ways the Numbers Are Wrong
They Measure Likelihood Without Evidence
Risk likelihood in most scoring models is assessed through expert judgment calibrated to ordinal scales: low, medium, high, very high. The calibration of those scales to actual event probabilities is rarely documented, and the expert judgment that drives the assessments is rarely tested for accuracy against historical outcomes. Organizations that have been running risk programs for ten years rarely know whether their likelihood assessments from ten years ago predicted actual events with any accuracy. The feedback loop that would make likelihood assessment better over time has not been built.
They Measure Impact on the Wrong Dimension
Impact in most risk scoring models is measured against business operations: revenue impact, operational disruption, regulatory exposure. These are legitimate impact dimensions. They are not the only impact dimensions, and they are not always the most material ones. Reputational impact from a privacy breach may exceed the direct financial impact by an order of magnitude and may persist for years after the direct impact has been recovered. Strategic impact from a supply chain compromise may alter competitive position in ways that financial modeling does not capture. Most risk scores do not include these dimensions because they are harder to quantify.
Impact dimensions that are excluded from the scoring model because they are hard to quantify are not lower impact. They are unscored impact that is occurring in the space the model does not cover.
They Aggregate in Ways That Lose Information
Risk registers aggregate individual risk assessments into portfolio views: the top ten risks, the heat map, the aggregate risk position. Aggregation produces summary information at the cost of detail. A portfolio view that shows a stable risk position may contain individual risks that have moved significantly while others moved in the opposite direction, producing a stable aggregate from unstable components. The aggregate is accurate. It does not tell the story the governance program needs to tell.
They Are Static in Dynamic Environments
Risk positions change continuously. New vulnerabilities are discovered. Threat actors change tactics. Vendors introduce new risk through changes in their own environments. Business decisions create new risk exposures. Risk scores that are updated quarterly capture the position at four points per year and interpolate the rest. In environments where the risk position changes significantly between quarterly updates, the scores are describing a risk landscape that no longer exists.
They Are Influenced by the People Who Provide Inputs
Self-reported risk assessments reflect the risk tolerance and organizational interests of the people who report them. Business units that are assessed on operational performance have incentives to report risks as lower than security teams assess them. IT teams that are measured on system availability have incentives to understate the risk of systems they are responsible for. The risk scores produced by self-reported inputs are influenced by those incentives in ways that produce systematic biases rather than random errors.
What to Do With Numbers That Are Wrong
The answer is not to stop measuring risk. Imperfect measurement is better than no measurement, and structured risk quantification — even when imperfect — enables prioritization, communication, and accountability that qualitative risk assessment does not. The answer is to be explicit about the ways the measurements are wrong and to build governance practices that account for those limitations.
Documenting the assumptions behind the scoring methodology, and reviewing those assumptions periodically against the current environment, makes the model's limitations visible rather than implicit. Adding independent validation — red team assessments, external audits, threat intelligence inputs — creates checkpoints that identify where the model's outputs have diverged from observable reality. Presenting risk scores to leadership with explicit confidence intervals and limitation statements rather than as precise measurements creates informed consumers of the data rather than overconfident ones.
The risk governance program that knows its numbers are wrong in specific ways and accounts for those ways is more robust than the program that assumes its numbers are right. The former is building on accurate self-knowledge. The latter is building on a foundation that the first significant incident will undermine.
Use the numbers. Know what they cannot tell you. Govern accordingly.
The risk program that knows how its measurements are wrong is more trustworthy than the one that doesn't. Build the self-knowledge into the governance design.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
