Create your own
Lesson illustration

Assessing Non-Monetary Loss Severity by Asset Value

Good to see you again. In the previous lesson, you traced how a technical incident can create operational, financial, reputational, and intellectual-property consequences. This lesson narrows the focus: how serious is a loss when it is not immediately expressed in money?

This is an important distinction-level skill. A deleted file, leaked design, unavailable booking system, or altered medical record may not have a price label attached, but each can be extremely valuable because of the role it plays. By the end of this lesson, you should be able to judge an asset’s value, explain the consequence if it is compromised, and give a supported low, medium, or high impact rating without relying only on monetary loss.


Impact is about harm; risk also includes likelihood

First, keep two connected ideas separate:

  • Impact (or severity of loss) asks: If this asset is compromised, how harmful would the outcome be?
  • Likelihood asks: How likely is that compromise to happen?
  • Risk combines the two: a very harmful event that is likely to occur is a higher priority than the same event if it is remote.

This lesson is mainly about judging impact. Do not make the common exam mistake of calling something “high risk” just because its impact is high. A high-value asset may create a high-impact loss, but the overall risk rating still depends on likelihood and vulnerabilities.

A three-by-three risk matrix: severity of impact increases from minimal to serious harm vertically, while likelihood increases from remote to more likely than not horizontally. It shows that impact and likelihood must both be considered when calculating overall risk.

For example:

  • A school’s emergency-contact database may have a high impact if deleted, because safeguarding information could be unavailable.
  • If it is securely backed up, strongly access-controlled, and difficult to reach from the internet, the likelihood of permanent loss might be lower.
  • The loss is still serious; the overall risk may be reduced by the controls.

A clear answer therefore follows this order:

Only after that, if required, add likelihood to decide the risk priority.


Assets have value because they support objectives

An asset is not just a laptop, server, or piece of software. It is anything an organisation needs in order to operate, meet its duties, serve people, or maintain its position.

Assets can include:

  • information: customer records, employee files, research, designs, source code;
  • systems and services: email, booking systems, payment systems, production control;
  • physical equipment: devices, network hardware, specialist machinery;
  • processes: payroll, order fulfilment, patient care, teaching and assessment;
  • intangible assets: reputation, brand, customer trust, and competitive advantage;
  • people and their ability to carry out essential work.

This wider definition matters. If an attacker steals a company’s unreleased product design, the file itself is not valuable because it occupies storage space. It is valuable because it contains work that gives the company an advantage over competitors.

A basic risk assessment and management method

Read the National Cyber Security Centre’s practical explanation of identifying assets and assessing their impact. It gives a useful model of an asset register and shows why the same cyber incident can have different severity for different organisations.

In Step 3 – Understand your assets and assess impact, read from the explanation of assets and impact ratings. Focus on the point that assets can be equipment, systems, services, information, or processes, and that a High rating needs a stated meaning. Then study Table 1: Example asset register immediately below. Compare the entries for intellectual property, corporate IT, HR information, operational technology, and online sales. In particular, read the IP example, then identify what makes the HR and production-system examples High impact even before calculating likelihood.

The NCSC examples make an essential point: a rating is not a label chosen by instinct. It is a judgement supported by consequences.


How to judge a non-monetary loss

When money has not yet been lost—or cannot sensibly be calculated—judge the asset by asking what the organisation would lose the ability to do, prove, protect, or recover.

1. Does it support a core function?

A core function is something the organisation must do to achieve its main purpose.

For example:

AssetOrganisationWhy its loss may be serious
Patient recordsGP surgeryStaff may be unable to safely identify patients, treatments, allergies, or prescriptions.
Stock and dispatch systemOnline retailerOrders cannot be picked, packed, or accurately delivered.
Production-control systemManufacturerMachinery may be unable to produce goods correctly or safely.
Assessment recordsCollegeGrades, progress, and evidence may be unavailable or incorrect.

If losing the asset stops a core function, the impact is usually high. This remains true even before someone calculates lost revenue.

A small office printer is also an asset, but its failure can normally be worked around by using another device or sending work electronically. It is more likely to be low impact. The difference is not whether both assets are “technology”; it is whether the organisation can still achieve its objectives.

2. Does the asset involve people’s safety, rights, or privacy?

Some data is valuable because losing confidentiality, integrity, or availability could harm people rather than merely inconvenience the organisation.

Consider a care provider’s records containing medication, allergies, and emergency contacts:

  • Confidentiality loss: unauthorised people see sensitive personal information.
  • Integrity loss: medication details are changed incorrectly.
  • Availability loss: staff cannot access records when care is needed.

The integrity loss may be especially severe because staff could make unsafe decisions using inaccurate information. Even where no physical harm occurs, the organisation may fail in its professional, legal, or safeguarding duties.

A distinction-level response should name the specific consequence rather than write only “it breaks GDPR” or “there could be legal trouble.” For example:

If attackers alter allergy information, care staff may rely on incorrect records. This could create a safeguarding risk and make the service unsafe. The loss of integrity is therefore high impact because the asset directly supports safe care, not merely administration.

3. Is the information difficult—or impossible—to recreate?

Recovery matters. Some assets can be restored quickly from backups; others cannot.

Asset lossCan it be restored?Why this affects severity
A standard software installationUsually yesIt can normally be reinstalled from a trusted source.
A backed-up spreadsheetOften yesA recent backup may reduce downtime and data loss.
Original research resultsNot fullyRepeating experiments may take months or may be impossible.
A leaked trade secretNoA backup restores the owner’s copy, but cannot make the attacker forget or delete it.
Public trust after a breachNot quicklyTrust may take sustained good practice and clear communication to rebuild.

This gives you a valuable sentence pattern:

The impact is high because the asset cannot simply be restored from backup. Although the organisation may recover its own copy, the confidentiality loss is permanent if the information has been copied or published.

That is particularly useful for intellectual property, private personal data, passwords, authentication keys, and strategic plans.

4. Would compromise damage trust, reputation, or relationships?

Reputation and brand are intangible assets: you cannot touch them, but they have real organisational value.

A loss can be severe when it causes:

  • customers to doubt whether their data is safe;
  • staff to feel their information has been mishandled;
  • suppliers to stop sharing sensitive details;
  • partner organisations to doubt reliability;
  • regulators or the public to question the organisation’s competence;
  • people to switch to alternatives.

However, be precise. A minor internal incident that is detected and fixed quickly may have little reputational effect. A public breach involving sensitive data, poor communication, or repeated failures has a much stronger case for high impact.

Compare these two situations:

  • A staff member accidentally sends an internal meeting agenda to the wrong colleague. The impact may be low if the information is not sensitive and is deleted quickly.
  • A retailer exposes thousands of customers’ payment details and initially denies the breach. The impact may be high because customers, payment providers, and the public may lose trust.

The key variable is not simply “data was leaked.” It is the value, sensitivity, scale, and likely use of that data, alongside the organisation’s relationship with affected people.


Define what low, medium, and high mean

Labels are only useful when they have agreed meanings. Calling an asset “high value” without explaining why is too vague for distinction-level work.

A workable BTEC-style scale is below. An actual organisation could use different definitions, but you must apply one scale consistently.

Impact ratingMeaning of the non-monetary lossTypical indicators
LowInconvenience or limited disruption; normal work can continue or quickly use an alternative.Few people affected; data is non-sensitive; asset is easily replaced; no lasting trust or service effect.
MediumNoticeable disruption or harm that needs management but does not stop the organisation’s main purpose.A department is delayed; recovery takes time; some confidential data is involved; contractual or reputational effects are possible.
HighSerious or prolonged inability to meet core objectives, protect people, meet obligations, or preserve competitive advantage.Essential service stops; sensitive data is exposed or altered; safety may be affected; irreplaceable IP is lost; major trust damage is plausible.

Notice that high impact does not mean “expensive.” It means the outcome seriously affects what the organisation exists to do and what it is responsible for.

The NCSC cautions that terms such as high, medium, and low can mean different things to different people. For that reason, a good risk register includes both a label and a brief narrative explaining it.

Component driven risk management methods

Read the NCSC’s explanation of how risk assessment starts with assets and leads to impact ratings. This supports stronger exam judgement because it includes intangible assets, such as reputation and brand, rather than treating assets as hardware only.

In Scope and assets, read the discussion of components and assets. Note the final point that reputation and brand can be valuable assets. Next, in Elements of risk, read the explanation of impact. Focus on how a loss of confidentiality, integrity, or availability can lead to wider outcomes such as delays, safety concerns, and reputational harm. Finally, in Prioritising your risks, read the warning about qualitative labels. Use this to remember that “High” must be justified with scenario-specific evidence.


A method for making a supported judgement

Use this six-step process in a scenario. It is short enough to use under exam conditions.

Step 1: Identify the precise asset

Avoid broad wording such as “the computer system” if the scenario gives more detail.

Better examples:

  • the customer-payment database;
  • the production-control system;
  • the HR records containing addresses and sickness information;
  • the unreleased prototype designs;
  • the school’s attendance and safeguarding records.

Step 2: Identify the type of compromise

Use the CIA triad you met in the previous lesson:

  • Confidentiality: read, copied, or disclosed;
  • Integrity: changed, corrupted, or made unreliable;
  • Availability: deleted, encrypted, inaccessible, or unusable.

The same asset can have a different severity depending on what happened. A public website being temporarily unavailable is not the same as its content being altered to publish false emergency advice.

Step 3: Link the compromise to real consequences

Ask:

  • What work cannot be done?
  • Who is affected?
  • Could decisions become inaccurate or unsafe?
  • Could the organisation fail to meet a legal, contractual, or professional duty?
  • Is the data sensitive, unique, or commercially valuable?
  • Can the asset be recovered, recreated, or replaced?
  • Would the loss become public or undermine trust?

Step 4: Consider the time scale

A high-quality judgement often separates immediate from long-term harm:

  • Immediate: staff cannot work, a service is unavailable, work is delayed.
  • Long-term: trust declines, research is copied, confidential data remains exposed, a competitive advantage is lost.

Step 5: Assign a rating using your defined scale

Do not hedge without reaching a conclusion. Write:

I would rate the impact as high because...

rather than:

It could be medium or high.

You can still state a condition when the scenario leaves uncertainty:

I would rate the impact as high if the records are the only current copy; with tested, recent backups, the availability impact may reduce to medium, although the confidentiality impact would remain high if data had been copied.

Step 6: Keep impact separate from likelihood

Finish the impact judgement first. Then, if the question is about risk priority, discuss probability and existing controls.


Worked scenario: no money is stolen

A college discovers that an attacker has accessed a shared drive used by the safeguarding team. The drive contains student welfare notes, emergency contacts, reports of concerns, and details of support plans. The attacker copied the files but did not delete or alter them. The college has a backup, so staff can continue accessing the drive.

A weak response would be:

This is serious because the attacker accessed files and the college could get fined.

That does not explain the asset value or recognise that availability is not the main issue.

A stronger analysis works through the method:

  1. Asset: safeguarding records and emergency-contact information.
  2. Compromise: confidentiality—an attacker copied the files.
  3. Value: the data is sensitive and supports safeguarding responsibilities and safe support for students.
  4. Non-monetary consequences: students and families may lose trust; disclosure could cause distress or put vulnerable students at greater risk; the college may fail to meet its duty to protect personal information.
  5. Recoverability: backups do not resolve the confidentiality loss because copied data cannot be taken back.
  6. Rating: high impact.

A distinction-level paragraph could be:

The safeguarding drive should be rated as a high-value information asset because it contains sensitive welfare information and emergency contacts needed to support students safely. The main impact is a loss of confidentiality, as the attacker copied rather than deleted the records. Although backups allow staff to keep using the system, they do not reverse disclosure of sensitive information. The incident could damage the trust of students and parents and may create safeguarding concerns if the information is misused. Therefore, the impact is high even though there is no evidence of direct financial theft or service downtime.

Why this earns stronger marks:

  • It identifies the type of loss accurately.
  • It uses evidence from the scenario.
  • It does not wrongly claim that a backup fixes every problem.
  • It makes a clear, justified rating.
  • It recognises a valuable non-monetary loss: privacy, trust, and safeguarding.

Comparing two assets fairly

It can be difficult when more than one loss seems serious. Compare assets by their connection to objectives, people, and recoverability—not by which sounds more dramatic.

Scenario comparison

A local manufacturer experiences two incidents:

  1. A staff laptop containing generic training materials is stolen.
  2. A server containing the only copy of a confidential prototype design is accessed and copied by a competitor.
QuestionStolen training-material laptopCopied prototype design
Does it support a core function?Limited; materials can probably be obtained elsewhere.Yes; the design supports product development and future competitiveness.
Is the information sensitive or unique?Usually low sensitivity if no personal data is stored.Highly confidential and unique.
Can it be replaced or restored?Usually yes, from standard copies or cloud storage.The company can restore its copy, but cannot undo copying by the competitor.
Could trust or reputation be affected?Limited, unless personal data is present.Potentially significant if the theft becomes known or shows weak protection of innovation.
Likely impact judgementLow or medium, depending on encryption and contents.High.

A high impact rating for the prototype design is justified even if the laptop costs more to replace. The physical device has a clear price; the stolen idea may have much greater strategic value.


Using the risk matrix correctly

Once you have rated impact, you can combine it with likelihood to prioritise action.

Suppose the stolen prototype design has:

  • Impact: high, because it could permanently weaken competitive advantage.
  • Likelihood: reasonably possible, because designers share files through an unprotected shared folder.

The risk matrix would place that scenario at a high overall risk. The organisation should prioritise controls such as appropriate access rights, encryption, monitoring, and secure sharing methods. You will study the selection of controls in later modules; for now, the important point is the reasoning:

The impact rating can stay high even after a control reduces the likelihood. For instance, multi-factor authentication may make unauthorised access less likely, but it does not make a leaked trade secret less valuable if a breach succeeds.

Cybersecurity Risk Assessment (Easy Step by Step)

Watch The Infosec Academy’s “Cybersecurity Risk Assessment (Easy Step by Step)” for a concise explanation of methodical impact and likelihood assessment. It reinforces why risk ratings should be based on defined criteria rather than guesswork.

Watch methodical assessment. Focus on the difference between estimating likelihood and judging the impact of a successful event. Then watch the risk grid to see how impact and likelihood are combined only after each has been assessed.


Exam language: turn a rating into analysis

For a short-answer question, use this sentence structure:

The affected asset is [asset]. If [type of compromise] occurs, [specific people/process/objective] will be affected because [causal explanation]. This loss is difficult to recover from / affects a core service / could undermine trust / could expose sensitive information. Therefore, I would rate the impact as [low, medium, or high].

For an extended response, add comparison and conditions:

This is more serious than the loss of [lower-value asset] because the organisation can replace or work around that asset. The rating could be reduced only if [realistic condition, such as a tested backup or unaffected alternative service] exists; however, this would not remove a confidentiality or reputational loss.

Avoid these weak phrases unless you explain them:

  • “It is important.”
  • “The company will lose money.”
  • “There will be a GDPR fine.”
  • “It is high risk.”
  • “They should have better security.”

Instead, make the value visible through the effect on people, services, obligations, trust, or competitive advantage.


Key takeaways

  • A non-monetary loss can be severe when the affected asset supports a core function, protects people, fulfils a duty, preserves trust, or creates competitive advantage.
  • Assets include information, systems, services, processes, people, reputation, and brand—not just physical hardware.
  • Judge severity by considering the type of compromise, affected people and processes, sensitivity, recoverability, duration, and long-term consequences.
  • Backups mainly reduce availability loss. They do not undo stolen data, lost trust, or disclosed intellectual property.
  • Define what low, medium, and high mean, then support the chosen rating with scenario evidence.
  • Do not confuse high impact with high overall risk: likelihood is needed to calculate risk priority.

Next, you will look outward at the changing threat landscape and practise using a reputable cybersecurity advisory source to summarise a current development.

Can't find a good explanation? Sign up and we'll make it for you

Sign up