Likelihood × impact — the risk language boards already understand
Walk into a risk committee with "we have 847 Highs" and watch the room glaze. Walk in with likelihood and impact — the same axes they use for everything from supply chain to credit — and the conversation starts.
Cyber is not a special snowflake risk domain. It only sounds like one when we brief it in scanner dialect.
The frame (without the formula dump)
Likelihood — how plausible is it that an attacker uses this path against us, given what's exposed and what we've verified?
Impact — if they succeed, how bad is it for the business (data, operations, trust, regulatory blast radius)?
Combine those and you get a ranked sense of breach risk — not a trivia contest about which CVE number is larger.
You do not need to project a research paper on the wall. You need the committee to feel: we're sorting by how we'd actually get hurt, not by how loud the vulnerability database was this week.
Why this beats "count the Criticals"
Critical counts answer "how busy is the vuln program?" Likelihood × impact answers "where is our breach risk concentrated?"
Those are related. They are not the same. A low-likelihood Critical on a sealed-off system can wait behind a higher-likelihood path with moderate labels and a ugly business consequence. Boards get that instantly — if you say it in their language.
What to put on one slide
Keep the math in the product; keep the story human:
- Current breach-risk level (the BreachRisk Score / trend — a measurement, not a guarantee)
- Top few paths — each in one line: what it is, why likelihood is real, what impact means in business terms
- Movement — what dropped since last period because likelihood or impact actually changed (fixed, mitigated, no longer exposed)
- Ask — decision, budget, or risk acceptance — one sentence
If a finding can't survive that template, it probably shouldn't open the meeting.
Guardrails so you don't overclaim
- Likelihood is informed by verification and exposure — not vibes and headlines.
- Impact is business language your execs recognize — not only CVSS "Confidentiality High."
- The score is an estimate / measurement of breach risk. Say that once. Don't let anyone hear "warranty."
The point
Security teams live in findings. Boards live in risk tradeoffs. Likelihood × impact is the bridge — and it's the same bridge every other risk function already uses.
Use it, and cyber stops sounding like a foreign language. It starts sounding like something the committee can govern.