RUEN
Home/Materials/Risk matrix
Risk management

Risk matrix: how to build one in an hour (an SMB example)

A risk matrix is the simplest tool to rank risks by importance and decide what to tackle first. We show how to build one in an hour using an SMB example.

Updated: June 28, 2026 · Author: Evgeny Telenkov · ≈ 6 min read

What a risk matrix is

A risk matrix is a table where each risk is rated on two scales: probability (how likely the event is) and impact (how painful it is if it happens). Their product gives the priority: red zone — act now, yellow — keep under control, green — accept.

How to build one in an hour

  1. List 10–15 risks (cyberattack, IT outage, supplier loss, key person loss, etc.).
  2. Rate probability on a 1–3 scale (low/medium/high).
  3. Rate impact on a 1–3 scale (low/medium/high).
  4. Multiply — get a priority from 1 to 9.
  5. Start with risks scoring 6–9: they need mitigation measures and plans.
RiskProbabilityImpactPriority
Cyberattack / ransomware339 (red)
Loss of a key supplier236 (red)
Equipment failure224 (yellow)

What to do with the result

For the red zone — reduce probability (protective measures) and prepare plans for if it materialises (BCP). The matrix is the entry point to risk management; for processes, criticality is calculated more deeply via the BIA.

FAQ

Which scale to choose — 3 or 5 points?

For small and mid-sized business a 1–3 scale for probability and impact is enough. A 5-point scale is needed when finer prioritisation of many risks is required.

How is a risk matrix different from a BIA?

The matrix prioritises risks by probability and impact. The BIA assesses the consequences of downtime of specific processes and sets recovery times. They are used together.

From the risk register to management decisions

Check whether your risks reach the people who decide. The dashboard shows the state on one screen, the turnkey engagement makes it work.

Evgeny Telenkov
Evgeny Telenkov
Director, business continuity practice · PhD in Economics · Academic Director & Chief Examiner
Risk Manager of the Year in Russia 2020 (RusRisk). Built business continuity from scratch at Nornickel, more than 20 plans; led risk functions at Beeline, Rosneft and EY. Chief risk officer of a 20 billion dollar petrochemical megaproject. Deputy chair of Rosstandart technical committee 010 "Risk management", co-author of six national standards. Author of the ERGP and SAFE programmes.