Risk Vector
A risk vector is a specific category or dimension of risk used to organize and measure how a company might be exposed to a particular type of problem, often within a security rating or scoring system. Rather than a single overall score, it represents one distinct area of observable activity or exposure, such as a particular kind of network behavior. Different vendors and platforms define their own sets of risk vectors, so the term does not carry a single standardized meaning across the industry.
In the context of security ratings and risk-scoring platforms, a risk vector is a discrete, named category against which observable activities, events, or incidents are compared to similar activities, events, or incidents to derive a risk signal or contribute to an aggregate score. In some platforms, individual risk vectors correspond to specific observed conditions, for example, a device on a company's network running a potentially unwanted program (PUP), which are then rolled up into a broader risk assessment. The term should not be conflated with 'attack vector' or 'threat vector,' which denote the method or combination of methods an adversary uses to breach or infiltrate a system or network; a risk vector is a measurement and categorization construct, not an intrusion pathway. Definitions and vector taxonomies are vendor-specific, so scope, granularity, and scoring methodology vary by platform and are not governed by a single recognized standard; a risk vector reflects only what the platform observes and models, and does not by itself capture financial, geopolitical, ESG, or other risk dimensions outside its defined scope.
Why it matters
Risk vectors are the building blocks of most security ratings and risk-scoring platforms, and understanding them is essential for interpreting the aggregate scores that increasingly influence third-party onboarding, monitoring, and tiering decisions. When a vendor's overall rating changes, that movement is typically driven by activity within one or more underlying risk vectors. Without visibility into which vectors are contributing to a score, a risk analyst may misread the signal, escalating on a low-severity issue in one category or overlooking a meaningful shift in another. Treating the composite number as self-explanatory, rather than examining its component vectors, is a common source of misinterpretation.
Who it's relevant to
Inside Risk Vector
Common questions
Answers to the questions practitioners most commonly ask about Risk Vector.
