Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

OWASP Risk Rating Calculator

Likelihood × impact, the OWASP way — with a vector you can share and paste back.

Security No upload Works offline Free, no sign-up

Risk rating

Overall risk severity Not rated yet Rate the factors below: the result updates as you go.
Likelihood
—
Technical impact
—
Business impact
—
Work the severity out from

The methodology uses business impact when you know the business; with only one impact group rated, that one is used.

Overall risk severity: impact (rows) against likelihood (columns)
Likelihood LOWLikelihood MEDIUMLikelihood HIGH
Impact HIGH Medium High Critical
Impact MEDIUM Low Medium High
Impact LOW Note Low Medium

All sixteen scores in one line. Paste a vector or a share link here and press Load to rate the same risk again.

Threat agent factors

Who would attack? Rate the worst-case group of threat agents.

How technically skilled is this group of threat agents?
How motivated is this group of threat agents to find and exploit this vulnerability?
What resources and opportunities are required for this group of threat agents to find and exploit this vulnerability?
How large is this group of threat agents?
Vulnerability factors

How easily that group finds and exploits this weakness, and whether anyone would notice.

How easy is it for this group of threat agents to discover this vulnerability?
How easy is it for this group of threat agents to actually exploit this vulnerability?
How well known is this vulnerability to this group of threat agents?
How likely is an exploit to be detected?
Technical impact factors

What a successful attack does to the data and the service.

How much data could be disclosed and how sensitive is it?
How much data could be corrupted and how damaged is it?
How much service could be lost and how vital is it?
Are the threat agents’ actions traceable to an individual?
Business impact factors

What it costs the business. Leave these unrated if you do not know the business: the technical impact is used.

How much financial damage will result from an exploit?
Would an exploit result in reputation damage that would harm the business?
How much exposure does non-compliance introduce?
How much personally identifiable information could be disclosed?

Next steps

About the OWASP Risk Rating Calculator

The OWASP Risk Rating Methodology estimates how serious a security risk is for the business, using the standard model risk = likelihood × impact. You rate sixteen factors from 0 to 9 — who the attackers are, how easy the weakness is to find and exploit, what an attack would do to the data and the service, and what it would cost the business — and the calculator works out the likelihood and impact levels and the overall severity from the methodology’s matrix.

Every factor shows the methodology’s own options and scores, so a rating can be defended in a review. The vector records all sixteen scores in one line, such as (SL:5/M:2/O:7/S:1/ED:3/EE:6/A:9/ID:2/LC:9/LI:7/LAV:5/LAC:8/FD:1/RD:2/NC:1/PV:5), which you can paste into a ticket or a report and paste back here later. Nothing you enter leaves your browser.

How to use it

  1. Pick the worst-case threat agent in mind (an anonymous Internet user, an insider, a partner) and rate the four threat agent factors for that group.
  2. Rate the four vulnerability factors: how easy it is to discover and to exploit, how well known it is, and whether an attack would be detected.
  3. Rate the technical impact (confidentiality, integrity, availability, accountability) and, if you know the business well enough, the business impact (financial, reputation, non-compliance, privacy).
  4. Read the likelihood, the impact and the overall severity. With both impact groups rated, choose which one decides the severity — the methodology prefers business impact when good business information exists.
  5. Copy the vector or a share link to keep the rating with the finding, or paste a vector into the box to load a rating someone else made.

Examples

The methodology’s own worked example
Input
(SL:5/M:2/O:7/S:1/ED:3/EE:6/A:9/ID:2/LC:9/LI:7/LAV:5/LAC:8/FD:1/RD:2/NC:1/PV:5)
Result
Likelihood 4.375 (MEDIUM), technical impact 7.25 (HIGH), business impact 2.25 (LOW): severity Low on business impact, High on technical impact alone.

This is why the business context matters: the same technical weakness is a different risk for a different business.

SQL injection on a public login page of a shop
Input
(SL:6/M:9/O:9/S:9/ED:7/EE:5/A:6/ID:8/LC:9/LI:7/LAV:5/LAC:9/FD:7/RD:9/NC:7/PV:9)
Result
Likelihood 7.375 (HIGH), technical impact 7.5 (HIGH), business impact 8 (HIGH): severity Critical.
Verbose error messages on an intranet tool
Input
(SL:5/M:1/O:7/S:4/ED:7/EE:3/A:4/ID:3/LC:2/LI:1/LAV:1/LAC:1/FD:1/RD:1/NC:2/PV:3)
Result
Likelihood 4.25 (MEDIUM), technical impact 1.25 (LOW), business impact 1.75 (LOW): severity Low.

Common uses

  • Agreeing on the priority of pentest findings with a client, factor by factor.
  • Rating threats found in a threat model so the riskiest are mitigated first.
  • Writing a defensible risk score into a ticket, with the vector to reproduce it.
  • Comparing the technical and the business view of the same weakness.

How the severity is worked out

  • Likelihood is the average of the eight threat agent and vulnerability factors.
  • Technical impact is the average of its four factors, and so is business impact.
  • Each average becomes a level: 0 to under 3 is LOW, 3 to under 6 is MEDIUM, 6 to 9 is HIGH.
  • The overall severity comes from the methodology’s matrix: a LOW likelihood gives Note, Low or Medium for LOW, MEDIUM or HIGH impact; a MEDIUM likelihood gives Low, Medium or High; a HIGH likelihood gives Medium, High or Critical.

The calculator waits until every factor of a group is rated before it scores that group, because an average of some factors would quietly change the result. The methodology also lets an organisation add factors, change options or weight them; this calculator uses the published factors and equal weights, so its numbers match other tools that follow the methodology.

Business impact or technical impact?

The methodology says to use business impact when you have good information about the business, because the business risk is what justifies spending money on a fix — and to fall back on technical impact when you do not. A tester outside the organisation often knows the technical impact but not the financial or regulatory consequences; the system owner can fill those in later. When both groups are rated, the calculator shows the severity for the impact you choose and, beside it, what the other one would give.

OWASP risk rating or CVSS?

They answer different questions. CVSS from FIRST scores the technical severity of a vulnerability in a fixed, published way — the same vulnerability gets the same base score anywhere, which is why vendors and the NVD publish it. The OWASP Risk Rating Methodology estimates the risk to one business: who would attack, how likely it is, and what it would cost that organisation. Many pentest reports give both: CVSS for the vulnerability and an OWASP rating for the client’s risk. The Threat Model Builder uses this same rating engine.

The vector format

The vector lists every rated factor as code:score in the methodology’s order — SL (skill level), M (motive), O (opportunity), S (size), ED (ease of discovery), EE (ease of exploit), A (awareness), ID (intrusion detection), LC, LI, LAV and LAC (loss of confidentiality, integrity, availability and accountability), FD (financial damage), RD (reputation damage), NC (non-compliance) and PV (privacy violation) — in brackets. It is the format of the open-source OWASP Risk Assessment Calculator, so ratings can be moved between the two. Factors you have not rated are left out of the vector.

Limitations

  • The result is an estimate built from your judgements; different people can rate the same factor differently. Agree on the threat agent first.
  • It uses the methodology’s published factors and equal weights. If your organisation customised the model, adjust the numbers to your own scale.
  • It is not a substitute for CVSS where a standard technical score is required, such as vulnerability disclosure.

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

What do the scores 0 to 9 mean?

Each factor has options with a score, from the methodology itself: for example skill level runs from no technical skills (1) to security penetration skills (9), and intrusion detection from active detection in the application (1) to not logged (9). Higher always means more likely or more damaging. You can also type any whole number from 0 to 9 when your case sits between two options.

Why is my severity “Note”?

Note is the matrix cell for LOW likelihood and LOW impact: the risk is worth recording, but it is not a priority. It is below Low.

Which threat agent should I rate?

The methodology says to use the worst case: of the groups that could attack, rate the one that gives the highest risk. If an anonymous Internet user and an employee could both exploit it, rate the one that is more likely or more capable.

Can I paste a vector from another calculator?

Yes, if it uses the same sixteen codes, with or without brackets and in any order. A share link with vector= in it works too. Codes it does not know, repeated codes and scores outside 0 to 9 are reported so you can fix them.

Is anything sent to a server?

No. The calculation runs in your browser. The share link carries the vector after a # sign, a part of the address that browsers do not send to the website.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.