Risk scoring methodologies and custom risk scales
Choose how Strike Graph combines likelihood and impact into a risk score, and tailor the ratings, ranges, and colors to your organization
Written By Micah
Every risk in Strike Graph is scored on two inputs: Likelihood and Impact. Your scoring methodology decides which ratings are available for those inputs and how they combine into a single combined score. Setting it once for your workspace keeps every risk in your register directly comparable.
Where to find the risk scoring methodology setting
Go to Settings, open the Workspace Settings tab, and find the Risk Scoring Methodology card. This setting applies to your entire workspace, so it is available to users with Manager permissions.
The three risk scoring methodologies
Strike Graph offers three methodologies. Each one uses the same two inputs and produces a combined score, but they differ in how many ratings they offer and how the combined score is calculated.
Advanced — 5-point NIST matrix is the default for new workspaces. It gives you enough granularity to distinguish between risks without asking assessors to split hairs, and it follows a rubric auditors recognize.
Basic — 3-point suits organizations early in a compliance program, where a shorter scale keeps the first risk assessment moving.
Custom — likelihood × impact is for organizations that need the risk scale to match a methodology they have already documented. It is the only methodology that lets you rename ratings, redefine score ranges, and set your own colors.
Changing your risk scoring methodology
Select a new methodology from the Risk Scoring Methodology dropdown and confirm the change. Two things happen when you do:
Every existing risk is re-scored under the new methodology. Some risks will land in a different range than they do now.
Any rating with no equivalent on the new scale becomes unscored, and those risks need to be scored again.
The second point matters most when you move from a 5-point methodology to Basic — 3-point. Basic has no Very Low or Very High rating, so any risk currently rated Very Low or Very High on either axis becomes unscored.
Changing your scoring methodology cannot be undone. If your risk register is already populated, plan the change with your team before you make it.
Customizing your risk scale under Custom scoring
When your methodology is set to Custom — likelihood × impact, a scale editor appears directly beneath the dropdown. The editor has two sections.
Input Labels
This section controls the wording your team sees when scoring a risk. Each of the five ratings has a Likelihood name and an Impact name, and you can set them independently. If your risk management policy describes likelihood as "Rare" through "Almost Certain" and impact as "Negligible" through "Catastrophic", you can enter that wording here and your assessors will see it in the scoring dropdowns.
Each name is limited to 50 characters.
Combined Score Ranges
Custom scoring multiplies the two ratings, so a risk's combined score falls somewhere between 1 and 25. This section defines the five ranges that span that scale and how each one is presented:
Range boundaries: Drag the handles on the slider to set where one range ends and the next begins. The ranges always stay contiguous and always cover 1 through 25, so it is not possible to leave a gap or create an overlap.
Color: Click the color chip to pick the color used for that range's score badge throughout the platform.
Name: The wording shown on score badges, in the risk register, and in filters. Limited to 50 characters.
Description: Optional context explaining what the range means for your organization.
The default ranges are Very Low (1-4), Low (5-8), Moderate (9-12), High (13-19), and Very High (20-25).
Click Save Settings to apply your changes. Your risks are re-sorted into the ranges you defined, and the new names and colors appear everywhere risk scores are displayed, including your audit exports.
Resetting the risk scale to defaults
Click Reset to defaults to return every rating name, range name, color, and score range to its original value. Risks whose combined score falls into a different range afterward are re-sorted into it. Resetting cannot be undone.
Availability
Basic and Advanced scoring are available in every Strike Graph workspace. Custom scoring is enabled per organization. If you do not see the Custom — likelihood × impact option and you would like to use it, reach out to your Customer Success Manager or contact support through the in-app messenger.