top of page

Why Risk Needs a Logarithmic Scale. From starlight and music to event frequency and financial loss

Aug 3
8 min read


We do not experience the world in the same way that measuring instruments record it.

A sensor registers light intensity, sound pressure, frequency or temperature. A person experiences something as bright, loud, high-pitched, warm or heavy.


These are not the same values.


A lamp producing twice as much light does not necessarily appear twice as bright. A sound with ten times greater physical intensity does not feel ten times louder. An extra kilogram is easy to notice when lifting a small package, but almost irrelevant when added to a much heavier load.

Our senses are good at detecting proportions. They are much less interested in absolute differences.



The brain does not record reality. It interprets it


Sensory receptors convert physical energy into neural signals. The brain then filters, compares and interprets those signals.


What we perceive is therefore not a direct copy of the environment. It is a compressed and processed representation of it.


This makes practical sense. The ranges found in nature are enormous. The human eye must work under starlight and in bright daylight. The ear must distinguish a quiet whisper, normal conversation, traffic and an extremely loud impact.


Representing such ranges linearly would be inefficient. Most of the available scale would be occupied by the strongest stimuli, while weaker signals would be compressed into a very small area.


Our sensory system solves this partly by responding to relative changes.


Ernst Weber observed that the smallest noticeable change in a stimulus tends to increase with the initial intensity of that stimulus. Gustav Fechner later proposed that perceived intensity could be represented approximately as a logarithmic function of physical intensity. This relationship is useful as a general model, although it does not describe every sense or every stimulus range with equal accuracy.


A similar principle appears in many scales that people have used for decades or even centuries.



Six levels of stellar brightness


One of the oldest examples comes from astronomy.


Ancient astronomers divided visible stars into six brightness classes. The brightest stars belonged to the first magnitude and the faintest stars visible to the naked eye to the sixth.


This was originally an observational scale. It described how bright stars appeared to a human observer.

The modern definition gave the scale a mathematical structure. A difference of five magnitudes corresponds to a hundredfold difference in observed brightness. One magnitude step therefore represents a brightness ratio of approximately 2.512. The scale is reversed: a lower magnitude means a brighter object.


Six levels can therefore represent a hundredfold range.

Astronomers did not divide that range into one hundred equal brightness intervals. They used a small number of categories based on proportions.


This distinction matters.

A linear scale adds the same amount at each step.

A logarithmic scale multiplies the value by the same factor at each step.



Twelve notes, but not twelve equal frequency differences


Music provides another example.


The frequency of the standard musical note A is 440 Hz. This value is specified in ISO 16, which was most recently reviewed and confirmed in 2022.


An A at 880 Hz is one octave higher. Another octave takes us to 1760 Hz.


The sequence looks like this:

440 Hz → 880 Hz → 1760 Hz → 3520 Hz

The numerical differences are not equal:

  • 440 Hz,

  • 880 Hz,

  • 1760 Hz.


The ratio, however, remains constant. Each octave doubles the frequency.

In twelve-tone equal temperament, an octave is divided into twelve semitones. Each semitone increases the frequency by the same ratio:

2¹⁄¹² ≈ 1.0595


After twelve such steps, the frequency has doubled.

The keys on a piano appear evenly spaced. Their frequencies are not evenly spaced on a linear scale. They become evenly spaced only after the values are expressed logarithmically.

Once again, a limited number of recognisable levels describes a much wider physical range.



Why sound is measured in decibels


Sound intensity covers such a large range that using raw linear values would be inconvenient.


This is why sound levels are commonly expressed in decibels.

The decibel does not represent a direct physical quantity. It expresses the logarithm of a ratio between a measured value and a reference value. ISO defines the bel and decibel as units used for logarithmic ratio quantities based on the decimal logarithm.

For power or sound intensity, an increase of 10 dB represents a tenfold increase in the physical value.


The same pattern appears repeatedly:

  • the physical values vary over several orders of magnitude,

  • the number of useful categories remains relatively small,

  • successive levels are separated by ratios rather than equal numerical differences.



Risk events do not occur at equal intervals


Consider a seven-level frequency scale.

A linear version might describe the levels as one, two, three, four, five, six and seven events per year.


Such a scale covers a very narrow range. It cannot sensibly include both an event expected once in a century and an event occurring every week.


Another option is to use verbal categories:

very rare, rare, possible, likely, very likely


These labels are easy to understand, but different people may interpret them differently. One manager may consider an event occurring once every five years rare. Another may call it possible.


A scale based on measurable frequency is more consistent.

An illustrative seven-level scale could look like this:

Level

Events per 100 years

Approximate interpretation

1

1

once every 100 years

2

4

once every 25 years

3

20

once every 5 years

4

80

approximately once every 15 months

5

300

approximately 3 times per year

6

1,500

approximately 15 times per year

7

6,000

approximately 60 times per year

Successive values increase by roughly a factor of four.


Seven levels can therefore represent frequencies ranging from once in a hundred years to more than once a week.


A linear scale covering the same total range would be almost useless. An interval of approximately one thousand events per century would separate each level. Events occurring once a century, once a decade and several times per year could all end up compressed into the lowest category.


Their management significance is clearly not the same.



Financial losses also span orders of magnitude


The same reasoning applies to financial consequences.


An organisation may need to compare losses of:

€10,000, €100,000, €1 million and €10 million


The differences between these values are not equal.

The difference between €10,000 and €100,000 is €90,000.

The difference between €1 million and €10 million is €9 million.


Yet both changes represent the same proportion: a tenfold increase.

For decision-making purposes, this ratio often tells us more than the absolute difference.


An illustrative seven-level financial impact scale might use the following representative values:

Level

Representative loss

1

€10,000

2

€30,000

3

€100,000

4

€300,000

5

€1 million

6

€3 million

7

€10 million

The values progress by a factor of approximately three.

The scale therefore has an exponential structure. The level number grows arithmetically—1, 2, 3, 4—but the represented loss grows geometrically.


This does not mean that every organisation should use these exact amounts.


A loss of €1 million could threaten the liquidity of a small company. For a large institution, it may be an operational cost that can be absorbed without affecting strategic objectives.


Financial thresholds should therefore be related to the organisation’s context, for example:

  • annual revenue or operating budget,

  • financial reserves,

  • cost of restoring a service,

  • acceptable loss limits,

  • impact on liquidity,

  • consequences for organisational objectives.


The scale should describe the organisation’s reality, not reproduce numbers taken from a template.



The level number is not the measured value


This is one of the most important distinctions in risk assessment.

A scale contains at least three different elements:

  1. the category number,

  2. the interval assigned to that category,

  3. the representative value of that interval.


The number 5 may be no more than a label.

It does not automatically mean five events, €5 million or a consequence five times greater than level 1.


This becomes relevant when risk matrices are used.


Suppose likelihood is rated as 4 and impact as 3. Multiplying the two values gives:

4 × 3 = 12

What does 12 mean?


It is not a frequency.

It is not a financial loss.

It is not an expected annual loss.

It has no unit.


The result is produced by multiplying category indices. Unless those indices were constructed as values on appropriate quantitative scales, the operation has no clear measurement interpretation.


A risk matrix does not become quantitative merely because numbers have been entered into its cells.



When multiplication does make sense


Multiplication can be justified when the values represent measurable quantities.


Suppose an event is expected to occur 0.2 times per year and the average financial loss per event is €300,000.


The expected annual loss is:

0.2 × €300,000 = €60,000 per year


The result has a clear interpretation and a clear unit.


NIST publications describe annualised loss expectancy as a way of expressing risk over an annual period by combining event frequency with financial impact. The method still depends on the quality and uncertainty of the estimates, but the mathematical operation itself is understandable.


This is very different from multiplying two ordinal category numbers.


Mathematics is useful in risk analysis. It must, however, be applied to values that have defined meanings.


How to build a logarithmic risk scale


A useful scale should not begin with the numbers 1, 2, 3, 4 and 5.


It should begin with the phenomenon being measured.


For event frequency, the expected range might extend from once every hundred years to several events per week.

For financial impact, it might extend from €10,000 to €10 million.

For service unavailability, it might extend from several minutes to several weeks.


The design process should then define:

  1. The measured quantity

    Frequency, financial loss, downtime, number of affected individuals or another observable value.

  2. The unit

    Events per year, euros, hours, records or people.

  3. The minimum and maximum values

    The range should reflect scenarios relevant to the organisation.

  4. The number of levels

    Usually a few to a dozen categories are sufficient. More categories can create an impression of precision that the available evidence does not support.

  5. The interval boundaries

    Every assessed value should fall into a clearly defined category.

  6. The representative value

    This value can be used in calculations or comparisons when a single estimate is required.




The middle of a logarithmic interval


For a logarithmic interval, the arithmetic mean is usually not the proportional midpoint.

Consider a financial range from €10,000 to €100,000.


The arithmetic mean is:

€55,000


But €55,000 is not halfway between the boundaries in proportional terms.

The geometric mean is:

√(€10,000 × €100,000) ≈ €31,623


The proportions are now symmetrical:

  • €31,623 is approximately 3.16 times €10,000,

  • €100,000 is approximately 3.16 times €31,623.


The geometric mean is therefore the midpoint when the values are viewed on a logarithmic scale.


This is useful when a category needs a representative value for calculations.



A scale should support a decision


The purpose of a risk scale is not to make uncertainty disappear.


It is to organise information so that people can compare scenarios, allocate resources and decide which treatments are justified.


When a €10,000 loss and a €1 million loss are placed in the same category, the organisation loses information needed to prioritise security spending.


When an event expected once every ten years receives the same likelihood rating as an event occurring every month, the risk register hides a material difference.


The result may be excessive spending on low-consequence scenarios and insufficient treatment of risks that could prevent the organisation from achieving its objectives.


A logarithmic scale does not remove uncertainty. It does, however, prevent wide value ranges from being flattened into a few poorly defined categories.


It also makes the method easier to audit. The organisation can show what each level means, where the boundaries are and why a particular scenario received its rating.



From a coloured matrix to usable information


A GRC system should store more than the name and number of a risk category.

It should also record:

  • units of measurement,

  • interval boundaries,

  • representative values,

  • calculation rules,

  • assumptions and sources,

  • changes made during subsequent assessments.


In Gladius 6.0, risk scales can be structured in this way. Category numbers support presentation, while the underlying intervals and representative values provide a basis for consistent analysis.


Seven levels are no longer seven arbitrary fields in a matrix.


They become a manageable representation of real differences in event frequency, financial loss, service downtime and other consequences.


The same principle has long been used to describe stars, musical pitch and sound intensity.


There is no reason for risk analysis to ignore it.

 
 
 

Comments


© 2025 by Rigil sp. z o.o. 

bottom of page