OWASP Risk Rating Calculator
Likelihood × impact, the OWASP way — with a vector you can share and paste back.
Risk rating
- Likelihood
- —
- Technical impact
- —
- Business impact
- —
| Likelihood LOW | Likelihood MEDIUM | Likelihood HIGH | |
|---|---|---|---|
| Impact HIGH | Medium | High | Critical |
| Impact MEDIUM | Low | Medium | High |
| Impact LOW | Note | Low | Medium |
All sixteen scores in one line. Paste a vector or a share link here and press Load to rate the same risk again.
About the OWASP Risk Rating Calculator
The OWASP Risk Rating Methodology estimates how serious a security risk is for the business, using the standard model risk = likelihood × impact. You rate sixteen factors from 0 to 9 — who the attackers are, how easy the weakness is to find and exploit, what an attack would do to the data and the service, and what it would cost the business — and the calculator works out the likelihood and impact levels and the overall severity from the methodology’s matrix.
Every factor shows the methodology’s own options and scores, so a rating can be defended in a review. The vector records all sixteen scores in one line, such as (SL:5/M:2/O:7/S:1/ED:3/EE:6/A:9/ID:2/LC:9/LI:7/LAV:5/LAC:8/FD:1/RD:2/NC:1/PV:5), which you can paste into a ticket or a report and paste back here later. Nothing you enter leaves your browser.
How to use it
- Pick the worst-case threat agent in mind (an anonymous Internet user, an insider, a partner) and rate the four threat agent factors for that group.
- Rate the four vulnerability factors: how easy it is to discover and to exploit, how well known it is, and whether an attack would be detected.
- Rate the technical impact (confidentiality, integrity, availability, accountability) and, if you know the business well enough, the business impact (financial, reputation, non-compliance, privacy).
- Read the likelihood, the impact and the overall severity. With both impact groups rated, choose which one decides the severity — the methodology prefers business impact when good business information exists.
- Copy the vector or a share link to keep the rating with the finding, or paste a vector into the box to load a rating someone else made.
Examples
(SL:5/M:2/O:7/S:1/ED:3/EE:6/A:9/ID:2/LC:9/LI:7/LAV:5/LAC:8/FD:1/RD:2/NC:1/PV:5)
Likelihood 4.375 (MEDIUM), technical impact 7.25 (HIGH), business impact 2.25 (LOW): severity Low on business impact, High on technical impact alone.
This is why the business context matters: the same technical weakness is a different risk for a different business.
(SL:6/M:9/O:9/S:9/ED:7/EE:5/A:6/ID:8/LC:9/LI:7/LAV:5/LAC:9/FD:7/RD:9/NC:7/PV:9)
Likelihood 7.375 (HIGH), technical impact 7.5 (HIGH), business impact 8 (HIGH): severity Critical.
(SL:5/M:1/O:7/S:4/ED:7/EE:3/A:4/ID:3/LC:2/LI:1/LAV:1/LAC:1/FD:1/RD:1/NC:2/PV:3)
Likelihood 4.25 (MEDIUM), technical impact 1.25 (LOW), business impact 1.75 (LOW): severity Low.
Common uses
- Agreeing on the priority of pentest findings with a client, factor by factor.
- Rating threats found in a threat model so the riskiest are mitigated first.
- Writing a defensible risk score into a ticket, with the vector to reproduce it.
- Comparing the technical and the business view of the same weakness.
How the severity is worked out
- Likelihood is the average of the eight threat agent and vulnerability factors.
- Technical impact is the average of its four factors, and so is business impact.
- Each average becomes a level: 0 to under 3 is LOW, 3 to under 6 is MEDIUM, 6 to 9 is HIGH.
- The overall severity comes from the methodology’s matrix: a LOW likelihood gives Note, Low or Medium for LOW, MEDIUM or HIGH impact; a MEDIUM likelihood gives Low, Medium or High; a HIGH likelihood gives Medium, High or Critical.
The calculator waits until every factor of a group is rated before it scores that group, because an average of some factors would quietly change the result. The methodology also lets an organisation add factors, change options or weight them; this calculator uses the published factors and equal weights, so its numbers match other tools that follow the methodology.
Business impact or technical impact?
The methodology says to use business impact when you have good information about the business, because the business risk is what justifies spending money on a fix — and to fall back on technical impact when you do not. A tester outside the organisation often knows the technical impact but not the financial or regulatory consequences; the system owner can fill those in later. When both groups are rated, the calculator shows the severity for the impact you choose and, beside it, what the other one would give.
OWASP risk rating or CVSS?
They answer different questions. CVSS from FIRST scores the technical severity of a vulnerability in a fixed, published way — the same vulnerability gets the same base score anywhere, which is why vendors and the NVD publish it. The OWASP Risk Rating Methodology estimates the risk to one business: who would attack, how likely it is, and what it would cost that organisation. Many pentest reports give both: CVSS for the vulnerability and an OWASP rating for the client’s risk. The Threat Model Builder uses this same rating engine.
The vector format
The vector lists every rated factor as code:score in the methodology’s order — SL (skill level), M (motive), O (opportunity), S (size), ED (ease of discovery), EE (ease of exploit), A (awareness), ID (intrusion detection), LC, LI, LAV and LAC (loss of confidentiality, integrity, availability and accountability), FD (financial damage), RD (reputation damage), NC (non-compliance) and PV (privacy violation) — in brackets. It is the format of the open-source OWASP Risk Assessment Calculator, so ratings can be moved between the two. Factors you have not rated are left out of the vector.
Limitations
- The result is an estimate built from your judgements; different people can rate the same factor differently. Agree on the threat agent first.
- It uses the methodology’s published factors and equal weights. If your organisation customised the model, adjust the numbers to your own scale.
- It is not a substitute for CVSS where a standard technical score is required, such as vulnerability disclosure.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
What do the scores 0 to 9 mean?
Each factor has options with a score, from the methodology itself: for example skill level runs from no technical skills (1) to security penetration skills (9), and intrusion detection from active detection in the application (1) to not logged (9). Higher always means more likely or more damaging. You can also type any whole number from 0 to 9 when your case sits between two options.
Why is my severity “Note”?
Note is the matrix cell for LOW likelihood and LOW impact: the risk is worth recording, but it is not a priority. It is below Low.
Which threat agent should I rate?
The methodology says to use the worst case: of the groups that could attack, rate the one that gives the highest risk. If an anonymous Internet user and an employee could both exploit it, rate the one that is more likely or more capable.
Can I paste a vector from another calculator?
Yes, if it uses the same sixteen codes, with or without brackets and in any order. A share link with vector= in it works too. Codes it does not know, repeated codes and scores outside 0 to 9 are reported so you can fix them.
Is anything sent to a server?
No. The calculation runs in your browser. The share link carries the vector after a # sign, a part of the address that browsers do not send to the website.