Traditional impact assessment asks one question of each risk: how bad would it be if this happened? The answer is a rating or a figure, and that figure decides where the risk sits on the matrix.
The number hides the path
Consider two risks with the same impact rating. One is self-contained: if it materialises, it hurts, and it stops there. The other has ten processes hanging off it. The rating treats them as equals. The reality does not.
Impact as propagation
In a network, impact is not a label on a single node — it is what a failure reaches. Which services it touches, how far it spreads, where it is absorbed and where it is amplified. The same disruption can arrive somewhere downstream not as an outage but as a surge of work, and a list would never have connected the two.
Why it changes the decision
Once impact is read as propagation, the priorities re-rank themselves. The moderate-severity node that everything depends on turns out to be the bigger threat to continuity than the severe-but-isolated one. You stop defending the loudest risk and start defending the one whose failure travels furthest.