Free Security Tool

OWASP Risk Calculator

Assess vulnerability risk using the official OWASP Risk Rating Methodology. Calculate likelihood, impact, and overall risk severity. No signup required.

How to use this calculator

  1. Select one option from each factor below, starting with Threat Agent and working down
  2. You don't need to fill every factor: partial results are available as you go
  3. Click Calculate Risk at the bottom to see your overall score
  4. The result combines Likelihood (who + how) with Impact (damage) into a single risk rating

Likelihood Factors

Threat Agent Factors

0/4
Skill Level
How technically skilled is this group of threat agents?
Motive
How motivated is this group of threat agents to find and exploit this vulnerability?
Opportunity
What resources and opportunities are required for this group to exploit this vulnerability?
Size
How large is this group of threat agents?

Vulnerability Factors

0/4
Ease of Discovery
How easy is it for this group to discover this vulnerability?
Ease of Exploit
How easy is it for this group to actually exploit this vulnerability?
Awareness
How well known is this vulnerability to this group of threat agents?
Intrusion Detection
How likely is an exploit to be detected?

Impact Factors

Technical Impact

0/4
Loss of Confidentiality
How much data could be disclosed and how sensitive is it?
Loss of Integrity
How much data could be corrupted and how damaged is it?
Loss of Availability
How much service could be lost and how vital is it?
Loss of Accountability
Are the threat agents' actions traceable to an individual?

Business Impact

0/4
Financial Damage
How much financial damage will result from an exploit?
Reputation Damage
Would an exploit result in reputation damage that would harm the business?
Non-Compliance
How much exposure does non-compliance introduce?
Privacy Violation
How much personally identifiable information could be disclosed?

Want to find real vulnerabilities?

Stop guessing risk scores. Find actual vulnerabilities in your infrastructure. CyberOrbit scans for OWASP Top 10 issues, CVEs, misconfigurations, and 20+ vulnerability classes across a full external pentest.

What is the OWASP Risk Rating Methodology?

The OWASP Risk Rating Methodology is a standardized framework for assessing the severity of security vulnerabilities. It evaluates risk based on two dimensions: Likelihood (how probable is an attack?) and Impact (how bad would it be?). Each dimension uses multiple sub-factors scored from 0-9 to produce an overall risk rating of LOW, MEDIUM, HIGH, or CRITICAL.

How Is Risk Calculated?

Likelihood Factors

  • Threat Agent: Skill, motive, opportunity, size
  • Vulnerability: Ease of discovery, ease of exploit, awareness, detection

Impact Factors

  • Technical: Confidentiality, integrity, availability, accountability
  • Business: Financial, reputation, compliance, privacy
Risk = (Likelihood + Impact) / 2
LOW
0 - 3
MEDIUM
3 - 6
HIGH
6 - 9
CRITICAL
9+

Frequently Asked Questions

What is the OWASP Risk Rating Methodology?

It's a standardized framework from OWASP for assessing vulnerability severity. It combines likelihood factors (threat agent capability, vulnerability ease of exploit) with impact factors (technical and business damage) to produce a risk score from 0-9.

How is this different from CVSS?

CVSS focuses on technical characteristics of a vulnerability. OWASP Risk Rating adds business context: financial damage, reputation impact, compliance risk, and privacy implications. This makes it better suited for prioritizing remediation based on business risk.

Do I need to fill in every factor?

No, you can get a partial risk calculation with any subset of factors. However, filling in all 16 factors gives the most accurate result. At minimum, select at least one factor from each of the four groups.

Is this tool free?

Yes, completely free with no signup required. For automated vulnerability discovery and risk assessment across your infrastructure, try a free CyberOrbit assessment.