Risk basics · 3 min read
Vulnerability vs Threat vs Risk
Three words people use interchangeably, and the clean distinction that makes you sound like a pro.
The definitions
- Vulnerability: a *weakness* that could be exploited (an unpatched server, a weak password policy, an untrained employee).
- Threat: *something that could exploit* a vulnerability to cause harm (a hacker, malware, a careless insider, a flood).
- Risk: the *combination of likelihood and impact*: how probable it is that a threat exploits a vulnerability, and how bad it would be if it did. Risk = likelihood × impact.
An example
A server is missing a critical patch (vulnerability). A known exploit and active attackers exist (threat). The server holds customer PII and faces the internet, so a breach is *likely* and the *impact* is severe: that's high risk. Take the same unpatched server with no network access and no sensitive data, and the *risk* drops sharply even though the vulnerability is identical.
Why it matters
You reduce risk by acting on the parts you control: patch the vulnerability, block the threat (firewalls, monitoring), or reduce the impact (encryption, backups, segmentation). Naming which lever a control pulls (and that risk is *likelihood × impact*, not just 'a bad thing') is exactly what interviewers and auditors listen for.
