Every number is traceable to specific asset owner responses. Every score can be explained to an auditor in plain English. No estimation required.
How probable is it that a threat event will occur? NORA doesn't ask practitioners to assign a number. It asks the asset owner the questions that reveal the answer — and derives the score from their responses.
What NORA Asks
Has anyone at your company reported a security problem or unusual activity with this system in the past year?
Can people outside your company access this system from the internet?
Do you know whether other companies similar to yours have had security problems with this type of system?
Is this a system that holds information that would be valuable to someone trying to steal it?
What actually happens to your business if this risk materializes? Not a theoretical worst case — a realistic one grounded in your organization. NORA derives this from what the asset owner knows about their own system.
What NORA Asks
What kind of information does this system store or process — customer records, payment information, employee data, health information?
If this system was completely unavailable for a full business day, what would stop working?
How many people inside and outside your organization rely on this system to do their jobs?
If information from this system was exposed publicly, would your company be required to notify anyone — customers, regulators, or partners?
The variable most risk tools ignore entirely. Not whether a vulnerability exists — but whether a threat is actually positioned to reach you. If the asset owner can't confirm a control is working, that uncertainty is the exposure.
What NORA Asks
Does your own IT team manage this system, or does a vendor or supplier handle it for you?
Do you know who currently has access to this system, and could you get that list today if you needed it?
Has anyone reviewed the security setup of this system in the last year, and do you know what they found?
If you needed to find out whether this system was properly secured right now, who would you ask?
Why Exposure changes everything: A system with strong Likelihood and Impact scores but confirmed, tested controls can have a dramatically lower composite score than one with assumed controls. NORA explicitly captures the difference between "we have a control" and "we can confirm the control is working." That gap is where real risk hides.
Composite scores from 1–125 map to five severity levels, each with a recommended response.
A risk score is only as good as the evidence behind it. NORA builds that evidence automatically — through the guided assessment process itself.
Each dimension score is derived from specific asset owner responses, not practitioner judgment. When an auditor asks why a score is High, there is a precise answer: the owner stated X and Y, which maps to these criteria.
When an asset owner says 'I think the controls are in place' or 'IT handles that,' NORA flags the uncertainty explicitly as an Exposure signal. Gaps in knowledge become part of the risk record — not blank fields that get skipped.
NORA translates the asset owner's responses into an audit-ready narrative automatically. The language is appropriate for framework submissions — no practitioner translation required.
A system handling sensitive customer data used by 500 employees scores differently than an internal tool used by two people — even if the controls are identical. Context is built into the methodology.