NORA
The Model

Scores That Are
Earned,
Not Assigned

Most risk tools ask practitioners to rate their own risk. NORA works differently — your asset owners answer plain-English questions about their actual systems, and NORA derives the score from what they know. The result is a defensible number with a paper trail, not a best guess.

NORA's Scoring Model

Risk=Likelihood×Impact×Exposure

Likelihood

Derived from questions about threat activity and whether known risks apply to your environment

Impact

Derived from questions about data sensitivity, user count, business criticality, and regulatory obligations

Exposure

Derived from questions about control confidence — whether anyone can confirm the controls are working

You don't rate your own risk.
Your asset owners answer questions. NORA produces the score.

Every number is traceable to specific asset owner responses. Every score can be explained to an auditor in plain English. No estimation required.

Dimension 01

Likelihood

How probable is it that a threat event will occur? NORA doesn't ask practitioners to assign a number. It asks the asset owner the questions that reveal the answer — and derives the score from their responses.

What NORA Asks

Has anyone at your company reported a security problem or unusual activity with this system in the past year?

Can people outside your company access this system from the internet?

Do you know whether other companies similar to yours have had security problems with this type of system?

Is this a system that holds information that would be valuable to someone trying to steal it?

LevelRatingDescriptionExample
1
RareHighly unlikely to occur. No known threat activity targeting this type of system and strong controls are confirmed in place.A zero-day exploit against an internally isolated system with no external connectivity or known threat interest.
2
UnlikelyCould occur under unusual circumstances. A threat exists but is not actively targeting organizations like yours.A phishing campaign targeting a niche industry where strong email filtering and user training are actively in place.
3
PossibleA reasonable chance of occurring. Known threats exist and some controls may have gaps or have not been recently validated.Credential stuffing against a web portal where password policies exist but multi-factor authentication is not enforced.
4
LikelyExpected to occur in the foreseeable future. Active threat actors are targeting similar organizations in your industry.Ransomware targeting mid-size organizations during a known active campaign wave with publicly available attack tooling.
5
Almost CertainWill occur imminently or may already be occurring. Exploits are publicly available and controls cannot contain the threat.An unpatched, publicly disclosed vulnerability with an active proof-of-concept and no compensating controls.
Dimension 02

Impact

What actually happens to your business if this risk materializes? Not a theoretical worst case — a realistic one grounded in your organization. NORA derives this from what the asset owner knows about their own system.

What NORA Asks

What kind of information does this system store or process — customer records, payment information, employee data, health information?

If this system was completely unavailable for a full business day, what would stop working?

How many people inside and outside your organization rely on this system to do their jobs?

If information from this system was exposed publicly, would your company be required to notify anyone — customers, regulators, or partners?

LevelRatingDescriptionExample
1
MinimalLittle to no business consequence. Operations continue normally, no reporting obligations triggered.A non-critical internal tool experiences brief downtime affecting one employee with no data exposure.
2
MinorLimited impact contained to a small area of the business. Recovery is straightforward and no regulatory notification required.A single department loses access to a collaboration tool for several hours with no sensitive data involved.
3
SignificantMeaningful business disruption affecting multiple teams. Leadership attention required and regulatory review may apply.A customer-facing portal goes offline during business hours, disrupting transactions and triggering incident response.
4
SevereSerious consequence to operations, customers, or reputation. Regulatory notification is likely and recovery requires significant resources.A breach of customer records triggers mandatory regulatory reporting and legal review.
5
CriticalCatastrophic and potentially irreversible impact. Regulatory penalties, litigation, and lasting reputational damage are expected.Ransomware encrypts core systems, halts all operations, exposes customer data, and triggers regulatory investigation.
Dimension 03

Exposure

The variable most risk tools ignore entirely. Not whether a vulnerability exists — but whether a threat is actually positioned to reach you. If the asset owner can't confirm a control is working, that uncertainty is the exposure.

What NORA Asks

Does your own IT team manage this system, or does a vendor or supplier handle it for you?

Do you know who currently has access to this system, and could you get that list today if you needed it?

Has anyone reviewed the security setup of this system in the last year, and do you know what they found?

If you needed to find out whether this system was properly secured right now, who would you ask?

Why Exposure changes everything: A system with strong Likelihood and Impact scores but confirmed, tested controls can have a dramatically lower composite score than one with assumed controls. NORA explicitly captures the difference between "we have a control" and "we can confirm the control is working." That gap is where real risk hides.

LevelRatingDescriptionExample
1
ProtectedControls are confirmed, tested, and actively working. You can state with certainty this system is defended.An internally hosted system with documented, tested controls and recent audit validation. No public-facing surface.
2
VerifiedControls exist and have been reviewed but not fully tested end-to-end. Confidence is high but complete certainty cannot be claimed.A cloud system with documented controls and logging enabled, though the last formal validation was over six months ago.
3
UncertainControls may be in place but cannot be confirmed. Someone would need to verify before confidence can be established.A SaaS platform where security settings are assumed to follow vendor defaults but no internal review has been conducted.
4
ExposedControls are known to be insufficient, untested, or partially missing. Meaningful attack surface with limited defensive confidence.A web application with known configuration gaps, no recent penetration test, and external accessibility not formally assessed.
5
UnguardedControls cannot be confirmed or are known to be absent. No one can confirm this system is defended.A legacy system still in use with no assigned owner, no recent security review, and no monitoring in place.

How Scores Translate to Risk Levels

Composite scores from 1–125 map to five severity levels, each with a recommended response.

Risk LevelScore RangeWhat It MeansRecommended Response
Monitor
1–14Low probability, low consequence, or strong confirmed controls. Acceptable residual risk.Routine monitoring and periodic review
Low
15–39Risk is real but manageable with standard controls and documentation.Document and track. Standard control review cycle.
Medium
40–77Meaningful risk requiring a mitigation plan and owner accountability.Mitigation planning within 90 days. Enhanced monitoring.
High
78–99Serious risk requiring prompt action and executive awareness.Immediate mitigation required. Escalate to leadership.
Critical
100–125Urgent risk demanding the organization's highest priority response.Urgent action. Board-level awareness. Immediate remediation.
Why It Holds Up

Why NORA Scores Are Defensible

A risk score is only as good as the evidence behind it. NORA builds that evidence automatically — through the guided assessment process itself.

Every Score Has a Source

Each dimension score is derived from specific asset owner responses, not practitioner judgment. When an auditor asks why a score is High, there is a precise answer: the owner stated X and Y, which maps to these criteria.

Uncertainty Is Captured, Not Hidden

When an asset owner says 'I think the controls are in place' or 'IT handles that,' NORA flags the uncertainty explicitly as an Exposure signal. Gaps in knowledge become part of the risk record — not blank fields that get skipped.

Narratives Are Auto-Generated

NORA translates the asset owner's responses into an audit-ready narrative automatically. The language is appropriate for framework submissions — no practitioner translation required.

Scores Reflect Business Context

A system handling sensitive customer data used by 500 employees scores differently than an internal tool used by two people — even if the controls are identical. Context is built into the methodology.

Self-assigned score vs. NORA-derived score — the same system, rated two ways

Without NORA — Self-Assigned

  • ·Practitioner reviews the system and assigns L=3, I=4, E=2 based on their own judgment
  • ·No record of what informed the rating decision
  • ·If the assessor changes, the rating logic changes with them
  • ·Auditor asks 'why is this a Medium?' — answer is 'our security team evaluated it'

With NORA — Derived From Asset Owner Responses

  • ·Asset owner answers guided questions about their system in plain English
  • ·NORA derives L=3 from threat context, I=4 from data type and user count, E=2 from confirmed controls
  • ·Complete response history stored and traceable
  • ·Auditor asks 'why is this a Medium?' — answer is a specific, sourced narrative

See the Guided Assessment in Action

Watch how NORA turns plain-English asset owner responses into a scored, narrated, audit-ready risk assessment — without asking anyone to rate their own risk.