Risk method
MedShield transparent 5x5 qualitative matrix v1.2: likelihood x impact, banded by threshold.
RM-5X5-001 · v1.2Effectiveeffective 15 Jan 2026
Inherent risk matrix
- Low 1-4
- Medium 5-9
- High 10-16
- Critical 17-25
| Impact | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 5 | 10 | 15 | 20 | 25 |
| 4 | 4 | 8 | 12 | 16 | 20 |
| 3 | 3 | 6 | 9 | 12 | 15 |
| 2 | 2 | 4 | 6 | 8 | 10 |
| 1 | 1 | 2 | 3 | 4 | 5 |
Worked example
Attacker sends unauthorized dosing command
TV-000118CriticalSafety-linked
4 x 5 = 20Critical band (17-25)
Reviewed by Marcus Chen · 21 Apr 2026 · RM-5X5-001 v1.2
- Exploitability · Effort, skill, and tooling required to execute the threat against the deployed product.
- Exposure · Reachability of the attack surface: network position, interface openness, deployment model.
- Attacker capability · Capability class of the plausible adversary, from opportunist to well-resourced.
- Preconditions · Access, credentials, configuration, or timing that must hold before the attack works.
- Detectability · Chance the attempt is detected and interrupted before completing its objective.
- Field prevalence · Observed exploitation of the same weakness class in the field or in comparable products.
- Patient safety · Potential physical harm to patients, including hazard-linked dosing or therapy effects.
- Clinical workflow · Disruption of care delivery, availability of therapy, or clinician decision-making.
- Confidentiality · Exposure of PHI, credentials, keys, or proprietary data.
- Integrity · Unauthorized modification of therapy parameters, records, software, or configuration.
- Availability · Loss of device, service, or data availability including denial of therapy.
- Privacy · Regulatory privacy consequence distinct from confidentiality breach mechanics.
Likelihood
- 1 Rare · No known exploit path; requires sustained physical access or nation-state capability.
- 2 Unlikely · Theoretical path with multiple strong preconditions; no field prevalence.
- 3 Possible · Feasible for a skilled attacker with limited preconditions; isolated reports in comparable products.
- 4 Likely · Practical with commodity tooling once network-adjacent; weak or absent preconditions.
- 5 Almost certain · Trivially exploitable or actively exploited in the field; no meaningful precondition.
Impact
- 1 Negligible · No patient impact; cosmetic or informational effect only.
- 2 Minor · Workflow inconvenience or limited data exposure without clinical consequence.
- 3 Serious · Delayed or degraded therapy, protected-data breach, or recoverable service loss.
- 4 Critical · Potential reversible patient harm, wide data breach, or extended loss of clinical function.
- 5 Catastrophic · Potential irreversible patient harm or death; systemic clinical or regulatory consequence.
- Method
- MedShield transparent 5x5 qualitative matrix
- Version
- v1.2
- Owner
- Framework Governance Board
- Effective date
- 15 Jan 2026
- Approved by
- Marcus Chen (Security Lead) · Dr. Lena Fischer (Risk Acceptance Authority)
- Supersession state
- Current; supersedes RM-5X5-001 v1.1 (retired with FR-2025.3)
- Method identity · Name, version, owner, approval, effective date, matrix thresholds, supersession state.
- Likelihood · Exploitability, exposure, attacker capability, preconditions, detectability, field prevalence, and evidence rationale.
- Impact · Patient safety, clinical workflow, confidentiality, integrity, availability, privacy, regulatory, and business consequences.
- Calculation · Formula, factor values, aggregation rule, inherent score, severity band, uncertainty, and confidence.
- Treatment · Avoid, mitigate, transfer, accept, or substitute design; target residual risk and responsible implementer.
- Residual risk · Recalculated only after implementation evidence and retest; acceptance authority must be independent where policy requires.
- Architecture change
- New vulnerability or exploit
- Supplier notice
- Incident
- Field signal
- New standard
- Patch
- End-of-support decision