Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Likelihood Of Breach Model
Governance, Ownership & Risk

Likelihood Of Breach Model

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Governance, Ownership & Risk

A likelihood of breach model is a prioritisation method that estimates which security issues are most likely to lead to compromise. It combines telemetry, observed exposures, and contextual risk signals to rank findings by practical threat potential. The goal is to direct remediation effort toward the vulnerabilities that matter most.

What a likelihood of breach model measures

A likelihood of breach model is not just a severity score with different wording. It estimates which weaknesses are most likely to become real compromise paths, using evidence such as exposure, exploitability, attack signal, and surrounding context to rank what deserves attention first.

That makes the model useful when teams need to separate noisy vulnerability backlogs from issues that are actually plausible entry points. It is a prioritisation method, so its value depends on the quality of the signals it ingests and whether those signals reflect real attack conditions rather than theoretical risk alone.

What inputs make the model useful

The strongest models combine telemetry from assets, detections, threat intelligence, exposure data, and contextual findings about how a system is deployed. A finding on an internet-facing service with weak authentication or known exploitation patterns should generally rank higher than the same finding in a tightly isolated environment.

This is where the model differs from simple severity scoring. Severity tells you how bad a flaw can be in the abstract; likelihood of breach asks how likely it is to be used in practice, given observed behaviour and the current environment.

How practitioners should interpret the ranking

A likelihood of breach ranking is a decision aid, not a statement of certainty. It should be read as a relative ordering of remediation priorities, especially when security teams need to choose between hundreds or thousands of findings.

The model is most reliable when it is transparent about what drives the score. If the logic is opaque, teams can over-trust the output or underweight important issues that are rare but catastrophic. FIRST EPSS is a useful reference point for understanding probability-based prioritisation, even when a local model uses different signals.

Where it fits in security operations

Likelihood of breach models sit in the middle of vulnerability management, exposure management, and threat-informed remediation. They help defenders move from “what exists” to “what matters now,” which is especially important when limited engineering capacity forces trade-offs.

Used well, the model supports faster decisions on patching, compensating controls, segmentation, and monitoring. Used poorly, it can hide systemic weaknesses if the organisation treats the ranking as a substitute for governance, asset ownership, or basic hygiene.

Risk and Threat Considerations

Likelihood-of-breach prioritisation can fail when the underlying signals are stale, incomplete, or biased toward easily observed issues. That creates a false sense of confidence, especially if low-scoring findings are still reachable by an attacker or if the model underestimates chained exploitation across multiple weak points.

Failure mechanism: The model misranks exposure when telemetry, exploit data, or asset context do not reflect how an attacker would actually move from reconnaissance to compromise.

Impact: Teams may spend remediation effort on low-value issues while leaving highly reachable weaknesses unaddressed, increasing breach probability despite a healthy-looking backlog.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.RA-01 — Risk IdentificationLikelihood models directly support identifying likely breach paths and prioritising risk.
ID.RA-05 — Threats, Vulnerabilities, Likelihoods, and Impacts Are Used to Understand RiskThe term explicitly combines vulnerability, exposure, and likelihood for risk prioritisation.
Recommendation — Use ID.RA-01 to rank findings by breach likelihood and exposure evidence. Apply ID.RA-05 to combine threat, exposure, and impact signals in remediation ranking.
NIST SP 800-53 Rev 5RA-3 — Risk AssessmentThe model is a risk-assessment method for comparing real compromise potential.
RA-5 — Vulnerability Monitoring and ScanningPrioritisation depends on current vulnerability and exposure telemetry.
Recommendation — Use RA-3 to assess exploitability and likelihood before prioritising remediation. Use RA-5 to feed current exposure and scan data into prioritisation.
CIS Controls v8CIS-7 — Continuous Vulnerability ManagementLikelihood of breach models are commonly used to rank remediation within vuln management.
Recommendation — Use CIS-7 to focus remediation on the vulnerabilities most likely to be exploited.
MITRE ATT&CKT1190 — Exploit Public-Facing ApplicationPublic exposure is a key input to breach-likelihood assessment for real attack paths.
Recommendation — Map externally exposed findings to T1190 and prioritise those most reachable by attackers.

Practitioner Guidance

What to watch for: Treat the model as a prioritisation layer that must be checked against asset criticality, exploitability, and real exposure. If a high-value system is ranked low, investigate the data inputs rather than assuming the score is correct.

Practitioner takeaway: The best likelihood models improve judgement, but they do not replace it. They work when they are tied to current evidence and reviewed alongside the organisation’s actual attack surface.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org