Risk assessment is an important step in the development of a secure system: its goal is to identify the possible threats to
a system, their impact and, henceforth, to evaluate the connected risks. Although several systematic approaches have been
developed to perform a risk assessment task, the current methodologies rely on the quantitative evaluations of experts in
a substantial way. This paper addresses the problem of detaching the methodology results from the subjective judgements of
experts, by formalising a risk assessment methodology in an appropriate mathematical framework that reduces the subjective
aspects in experts’ evaluations