Understanding the risks an organization faces is key in defining appropriate security measures to implement. Risks are defined by the likelihood of an event occurring and the severity of an event’s impact on business operations. Organizations should perform risk assessments at least annually to identify threats and rank them based on criticality.