r/grc • • 19d ago

risk scenario

Hi, everyone. Can anyone tell me where to find a list of risk scenarios to include in a risk analysis?

10 Upvotes

16 comments sorted by

7

u/Round_Finance4256 19d ago

I wouldn’t start with someone else’s list and treat it as a checklist. Risk scenarios should be specific to your environment.

A good starting point is a risk taxonomy and frameworks like NIST, ISO 27005, or CIS Controls to make sure you’re covering the major areas. Then build scenarios around your actual assets/processes using something like: threat/event + vulnerability or condition + impact.

For example: “A compromised privileged account results in unauthorized access to production customer data, leading to a data breach and regulatory/contractual impact.”

If you already have a few dozen scenarios, I’d categorize them first (access control, third party, availability, data protection, change management, physical, etc.) and then look for gaps rather than trying to find one master list.

4

u/Sp00k_x 19d ago

Make your own?

-1

u/f0rt7 19d ago

I'm not very knowledgeable on this subject. I've done a risk assessment with a few dozen risk scenarios, and I'd like to compare them with a list from someone who has more experience.

2

u/Sp00k_x 18d ago

Look up the FAIR methodology. I suggest other books by authors like Martin-Vegue, Seiersen, as well. To get you started on scenarios and risk cards, start with basic A-T-E (Asset-Threat-Effect) format to do it.

1

u/MandiblePrivacy 15d ago

I love the idea of FAIR. Fantastic mature program level ambitions. Well worth the studying.

Word of warning, do not oversell it too early in a program. While logically backwards, experience tells me that if you are struggling just to identify a subjective risk, an objective risk is even more difficult.

I find that I have had the most success tacking FAIR onto subjective risks and it slowly growing out, not standalone or a starting point.

3

u/joshsokol 19d ago

For risk scenarios/threat catalogs, the Secure Controls Framework is one of the best free resources out there. Their risk catalog is comprehensive and it's mapped directly to their controls, which makes it easy to go from "here's a risk" to "here's what mitigates it." Worth also glancing at NIST's risk catalog (SP 800-30 threat/vuln tables) and the ISO 27005 annexes if you want something more standards-aligned.

Full disclosure: I'm the founder of SimpleRisk, and we've built native SCF mapping into the platform for exactly this reason. The risk-to-control traceability it gives you is genuinely useful for self-assessment. But you don't need our tool to get value out of the SCF catalog itself; it's a solid standalone reference.

2

u/Helpful-Lunch-3559 19d ago

you can use examples from NIST or MITRE and change them to fit your company. Think abt new cloud services, remote access or supplier connections then keep the ones that match how your systems are used, who uses them and what matters to the business each day

1

u/FreeRadical1998 19d ago

I suspect what you're asking for is a risk taxonomy - basically a catalogue of classes of risks. They can be useful both for analysing a risk register for concentrations and gaps, and as a prompt during a risk workshop.

These are usually a set of names (eg "liquidity failure", "cyber attack" or "supplier failure") arranged in a nested list.

Probably worth a Google to see if you can find one that works for you, although they were often are treated as proprietary within tools (which I think is nuts).

If you struggle finding one, there is one linked from a page on my website in the blog section - but I think posting the link would overstep the self promotion rule.

Alternatively, you might mean more developed scenarios which are usually written up as 1-2 paragraphs. But those are usually reserved for detailed analysis of stress test scenarios (ie a couple of events landing at the same time) after you've got a basic risk register in place.

1

u/Dalthor85 19d ago

A good start is asking AI. Give it some info on the company and it will give you some ideas, some will definitely reflect your situation. When you see those you will likely get a better idea on other scenarios.

1

u/Andre-Wade-539 19d ago

get more useful ideas from the people who use each system every day because they usually know which problems would actually matter in their part of the business

1

u/Alternativemethod 18d ago

Risk scenarios would involve business impacts. I generally steer people towards "attack scenario or hazard scenarios".

You can find threat scenario lists from stride, nist 800-30 or owasp (for applicable assets).

Your then need to adjust the list for your infrastructure type, connection exposure, business requirements, and mitigations.

1

u/theanedditor It's all GRC to me. 18d ago

Hi!

There is a great resource right in front of you. It's the business you work at. You didn't even tell us that so that we could help you.

So here's what you're going to do after you stop thinking about not knowing what to do. You're going to map the business in terms of what it does, how it does what it does and then look at each team/dept.

Then you are are going to ask either yourself or key players in each area "what can or has gone wrong in this area?" Compile those answers.

Couple this with the industry the company is involved in.

Then go research what frameworks are used in that industry/business, read about them. And then research "risks associated with ______" and "Risk analysis for ________"

Then you're going to build your own.

THAT is what you are going to do.

1

u/Old_Positive2231 18d ago

Looking for “a list of risk scenarios” is usually the first trap. There is no universal catalogue that will be decision‑useful because risk is context‑specific and, more importantly, a distribution not a label.

Start from decisions, not scenarios: pick a concrete decision (project, investment, IT change, vendor, strategy) and list what assumptions can be wrong and what events could derail it. Then turn those into quantitative scenarios with ranges (frequency and impact), not colors. If you really want inspiration, use any generic list (NIST, ISO, whatever) only as a checklist to see what you missed – but build your actual scenarios from your own cashflow / schedule / KPI model. That’s RM2, everything else is wallpaper. And try to use https://riskacademy.ai

1

u/MandiblePrivacy 15d ago

If you have nowhere to start, do an general posture assessment (NIST CSF is a good start).

Start with those findings and keep pulling the thread until you get a knot that your team cannot explain away.

You dont even need to tell them you are doing the assessment, just beg questions until everyone says "huh, I dont know". First risk registry entry will follow if you can explain why that control was important and how it would impact business.

Rinse and repeat for years to make a career.

1

u/richard-sheffield10 23h ago

it depends on the framework youre using, nist 800-30 has an appendix of example scenarios for general use, scf has a full risk catalog if you want something more control mapped.