Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogContact
EN · FR
Test access Book a demo
BUSINESS IMPACT

Before you score the risk, score the asset

Sit through any risk workshop and you will hear the same argument: is the impact a 3 or a 4? The debate feels like risk analysis. It is not. It is an unresolved question about the asset, being settled from memory, in the middle of a meeting, by whoever argues best.

SYNAPSE CONSULTING  ·  5 MIN READ

Where impact scores actually come from

A 5×5 matrix looks rigorous. Likelihood on one axis, impact on the other, colours in between. But the impact axis has a hidden dependency: you cannot say what a compromise costs unless you know what the asset is worth. When that value has never been established, every impact score is an improvisation, and the same risk lands on a 2 or a 4 depending on who is in the room.

The instrument that settles the question is the business impact assessment. Classify the asset once, with named levels everyone has agreed on, and the impact discussion changes nature: the score is read from the classification instead of being argued from intuition. In a risk programme, the BIA is not an annex. It is the input that makes every other score mean something.

The triad, plus the letter auditors care about

Convention classifies assets on three dimensions: confidentiality, integrity and availability. The triad is useful, but it is a convention, not a law of nature, and it has a blind spot that regulated organisations feel every year: it says nothing about whether you can prove who did what.

That is why SynapseRM classifies on four letters, C·I·A·T, where T stands for traceability: the level of logging and attribution the asset requires. The levels run from “no requirement to log who performed an action” to “full detail, author, precise action, data affected, date and time, sufficient for forensic or regulatory review”. In an era where NIS2 and DORA are built on evidence rather than assertion, the ability to reconstruct actions on an asset is a dimension of its criticality, not a technical afterthought.

Levels mean nothing until you define them

The second failure of most classification schemes is the naked scale. Asking an asset owner to rate confidentiality “from 1 to 4” produces numbers, not information: one owner's 3 is another owner's 2, and the aggregate is noise with decimals.

The fix is to give every level a definition in business language, written once by the organisation, applied identically to every asset. Not “confidentiality: 2” but “Internal: intended for use within the organisation; disclosure would cause limited inconvenience but no significant harm”. Not “availability: 3” but “the service must be restored within a few hours; prolonged downtime disrupts critical operations”. Availability levels expressed as tolerable downtime are particularly effective, because the asset owner is answering a question they actually know: how long can the business live without this?

The BIA form in SynapseRM: four dimensions with qualitative level definitions written in business language, a GDPR flag and a computed criticality
The BIA in SynapseRM: each level of C·I·A·T carries the organisation's own definition, so two assessors reading the same asset reach the same number.

With defined levels, classification stops being a matter of taste. Two assessors reading the same definitions about the same asset land on the same line, and an auditor reading the register three years later understands exactly what a “High” meant on the day it was assigned.

Three ways classification fails

Programmes that do run a BIA still lose value in three familiar ways:

What the frameworks expect

None of this is optional refinement. DORA Article 8 requires financial entities to identify, classify and adequately document their ICT supported functions and the information and ICT assets behind them, and to map the ones considered critical, including links and interdependencies. ISO 27001:2022 carries the same expectation in Annex A: an inventory of information and associated assets (control 5.9) and a classification of information according to the organisation's needs (control 5.12), while ISO 27005 places asset valuation at the start of the risk assessment it describes. NIS2, finally, asks for policies on risk analysis (Article 21(2)(a)); an analysis whose impact scores rest on classified assets is precisely what makes such a policy defensible in front of a supervisor.

How SynapseRM does it

The BIA module in SynapseRM applies everything above. An asset carries an identifier, an owner, a department and optional links to related assets. Each of the four dimensions is set by choosing a level whose full definition is on screen, in your organisation's own wording, since scales and definitions are configurable. A flag records whether the asset holds personal data, so the GDPR dimension of a later incident is a lookup rather than a scramble. The overall criticality is computed and displayed on the spot.

The saved assets view in SynapseRM: C, I, A and T scores per asset with an overall criticality badge, owner, department and last update
The asset register that results: C·I·A·T per asset, an overall criticality badge, and a visible last-updated date for every line.

Because the platform runs on one data model, the classification does not retire into a file. The criticality sits on the same record that assessments, risks and exceptions reference, so when an analyst scores the impact of a finding on the finance ERP, the asset's level is in front of them, not in a spreadsheet from another year. The workshop argument about “3 or 4” ends the honest way: it was settled before the meeting started.

NEXT STEP
Bring us one real project

In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.

Book a demo Request test access

Related reading: The risk register: the document every framework assumes you have · Twelve modules, one data model: why integration beats tooling

Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Privacy & cookies
Brussels, Belgium