# Risk analysis

**How do you carry out a risk analysis?**

A risk analysis answers three questions. What can happen, how likely is it, and what does it cost. From that follows where you invest first.

The starting point is a list of what you protect. Customer data, the accounts, production, being reachable by email. Without that list you assess into thin air, because you do not know what is at stake.

Then for each point you consider what can go wrong and what that would mean. An outage of the inventory system for three days can be put in figures. The loss of patient records or client files additionally touches your professional duties and your reputation.

The result is an order of work. A high risk that is cheap to remedy is tackled first. Record the analysis in writing. Under section 32 NISG 2026 the risk analysis is one of the requirements, and Article 32 GDPR likewise calls for measures appropriate to the risk.

## Related terms
- [Security objectives: confidentiality, integrity, availability](https://vetosec.at/en/it-security/schutzziele/)
- [IT asset inventory](https://vetosec.at/en/it-security/it-inventar/)
- [Gap analysis](https://vetosec.at/en/it-security/gap-analyse/)
- [NIS2](https://vetosec.at/en/it-security/nis2/)

## Source
https://vetosec.at/en/it-security/risikoanalyse/ (vetosec, grundlagen)
