Marcus is three minutes into his first GRC interview when the panel asks the classic: “Can you explain the difference between a threat, a vulnerability, and a risk?” He knows all three words. He has read all three definitions. And under pressure, they blur into one vague cloud of “bad things,” because definitions memorized in isolation always do.
This guide fixes that permanently, because it teaches risk vs threat vs vulnerability through one scenario instead of three dictionary entries. Ten minutes from now, you will be able to pull the three apart in any example an interviewer throws at you.
The 30-second answer
A threat is anything that could cause harm. A vulnerability is a weakness that lets the harm happen. A risk is the potential for loss when a threat meets a vulnerability at something you care about.
Combined in one example: phishing attackers (threat) target Clearwater Financial Services, where staff have had no awareness training (vulnerability), creating the risk that customer data is exposed and the company faces regulatory penalties (risk).
Those definitions align with NIST’s official vocabulary in the NIST glossary; ISO/IEC 27000 defines the terms in compatible language for ISO-aligned organizations. Now let’s make them stick.
Threat, explained through a scenario
Clearwater Financial Services, our example fintech, runs a customer portal where people check balances and move money. Ask “who or what could harm this?” and you are listing threats:
- Criminals running automated password-guessing attacks
- A phishing campaign targeting Clearwater’s customers
- A flood in the data centre region
- A support employee tempted to snoop on accounts
- The hosting vendor going bankrupt
Notice two things. First, threats include people, accidents, and nature; not everything hostile is human. Second, and this is the interview-winning insight: threats exist whether or not Clearwater is weak. Criminals run password attacks against every login page on the internet. The rain does not check your defences before falling. You do not control threats; you can only know them.
Vulnerability, explained through the same scenario
Now ask a different question about the same portal: “where are we weak?”
- Customer logins have no multi-factor authentication
- Staff have never been trained to spot phishing
- Backups exist but have never been test-restored
- Support agents can view any account, and nobody reviews the logs
These are vulnerabilities: gaps in protection that a threat could exploit. Unlike threats, vulnerabilities are yours. They live inside your systems, your processes, and your people, which means they are the part you can actually fix. This asymmetry, threats outside your control and vulnerabilities inside it, is why security work concentrates on closing weaknesses rather than eliminating enemies.
Risk: where the two meet an asset
A threat alone is weather. A vulnerability alone is an unlocked door in a town with no burglars. Risk is created at the intersection, when a real threat can plausibly exploit a real weakness to harm something of value.
Portal example: automated password attacks (threat) meet no MFA (vulnerability) at the asset of customer accounts, producing the risk of account takeover, customer losses, and regulator attention. Remove either ingredient and the risk collapses: add MFA and the attacks still come but mostly fail; if no attackers existed, the missing MFA would be harmless.
That is also the answer to a favourite interview follow-up: can a threat exist without a vulnerability? Yes, constantly. It just produces little risk until a weakness gives it a way in.
The formula mental model (and its limits)
You will see this shorthand everywhere: Risk = Threat x Vulnerability x Impact. As a mental model it is genuinely useful: it reminds you that if any factor is zero, the risk is zero, and that risk grows when threats are active, weaknesses are wide, and the asset is valuable.
Its limit: it is a metaphor, not math. Nobody multiplies real numbers here. In practice, as covered in the step-by-step risk assessment guide, practitioners rate likelihood and impact on simple scales, where the threat and vulnerability evidence feeds the likelihood rating. Use the formula to think, not to calculate.
One more nuance worth having ready: in formal risk management, risk is technically the effect of uncertainty on objectives, which can occasionally be positive. In cybersecurity practice, you will spend your career on the negative kind, but knowing the nuance signals depth.
5 quick-fire examples: identify each component
For each scenario, name the threat, the vulnerability, and the risk before revealing the answer. This mirrors the quiz on Instagram at @tracynarGRC if you want the 60-second version.
1. A hospital’s patient records system runs software the vendor stopped patching two years ago. Ransomware groups actively target healthcare. Answer: threat = ransomware groups; vulnerability = unpatched, unsupported software; risk = patient records encrypted, care disrupted, penalties under health privacy law.
2. A retailer’s employee reuses her work password on a shopping site that gets breached. Answer: threat = criminals trying breached passwords on other services; vulnerability = password reuse and no MFA; risk = attacker walks into the retailer’s systems with valid credentials.
3. A law firm’s only copy of case files sits on one office server. The building has old wiring. Answer: threat = fire; vulnerability = no offsite backup; risk = permanent loss of client files and the firm’s ability to operate.
4. A startup gives every developer full access to production customer data to move fast. Answer: threat = a careless or compromised developer account; vulnerability = excessive access with no separation; risk = mass data exposure from a single mistake or takeover.
5. Clearwater’s finance team receives fake invoice emails imitating a real vendor. Payments over $10,000 require only one approval. Answer: threat = business email compromise fraudsters; vulnerability = single-approval payment process; risk = large fraudulent payments that are rarely recoverable.
Scored five for five? You now sort these faster than many working analysts.
Why interviewers love this question
Because it tests thinking, not memory. A candidate who recites definitions has studied; a candidate who can dissect a fresh scenario into components can do Tuesday’s actual work: writing risks precisely into a register. The strongest interview answer follows exactly the structure you just practiced: define the three in one breath, then immediately ground them in a concrete example, then name the insight that threats are external and vulnerabilities are yours to fix.
These three words are also the raw material for the next skill in this series: turning components into a clean, professional risk statement. That craft, formula and examples included, is Week 6’s article.
Want to practice with real structure? The free GRC Starter Kit includes the Risk Register Template where threat, vulnerability, and risk each have their place, plus the gap assessment and policy templates from the rest of this series. Get the GRC Starter Kit.

