Risk management

Risk matrix: how to build one in an hour (an SMB example)

A risk matrix is the simplest tool to rank risks by importance and decide what to tackle first. We show how to build one in an hour using an SMB example.

Updated: June 28, 2026 · Author: Evgeny Telenkov · ≈ 6 min read
Risk matrix: how to build one in an hour (an SMB example)

What a risk matrix is

A risk matrix is a table where each risk is rated on two scales: probability (how likely the event is) and impact (how painful it is if it happens). Their product gives the priority: red zone — act now, yellow — keep under control, green — accept.

How to build one in an hour

  1. List 10–15 risks (cyberattack, IT outage, supplier loss, key person loss, etc.).
  2. Rate probability on a 1–3 scale (low/medium/high).
  3. Rate impact on a 1–3 scale (low/medium/high).
  4. Multiply — get a priority from 1 to 9.
  5. Start with risks scoring 6–9: they need mitigation measures and plans.
RiskProbabilityImpactPriority
Cyberattack / ransomware339 (red)
Loss of a key supplier236 (red)
Equipment failure224 (yellow)

What to do with the result

For the red zone — reduce probability (protective measures) and prepare plans for if it materialises (BCP). The matrix is the entry point to risk management; for processes, criticality is calculated more deeply via the BIA.

See how resilient your business really is

13 questions, 5 minutes, free — results on screen and by email.

FAQ

Which scale to choose — 3 or 5 points?

For small and mid-sized business a 1–3 scale for probability and impact is enough. A 5-point scale is needed when finer prioritisation of many risks is required.

How is a risk matrix different from a BIA?

The matrix prioritises risks by probability and impact. The BIA assesses the consequences of downtime of specific processes and sets recovery times. They are used together.

Evgeny Telenkov
Evgeny Telenkov
Chief Risk Officer · PhD in Economics · "Best Risk Manager of Russia 2020"
20 years in risk management. Led risk management at Beeline, Nornickel, Rosneft and EY. Built business continuity plans for Nornickel, Rostec, NSD and DIA. Trained 300+ risk and BCM specialists.
More about the approach and expert →