The first stage of risk analysis and management is to identify potential threats to an asset or service, estimate the probability that the threat might materialise,
assess how vulnerable the asset or service is to these threats and to assess the impact should the threat materialise. For example, as identified above, flood is one example of a threat that might be relevant to an asset such as a data centre. We would determine the probability that the centre might be flooded, assess the vulnerability of the data centre to flooding and the impact on the organisation if it did flood. Putting all these together would give us a measure of risk.