1.9 Risk Management
Risk Management at a glance
Cybersecurity risk management is the process of identifying, understanding, prioritising and responding to risks that could affect organisational objectives.
The objective is not to eliminate every possible risk. The objective is to understand risk well enough that informed decisions can be made about what should be treated, transferred, avoided or accepted.
Identify
Understand assets, threats, vulnerabilities and potential events.
What could happen?Assess
Estimate likelihood and potential business impact.
How serious is it?Respond
Decide how the organisation should treat the risk.
What will we do about it?How cybersecurity risk develops
1 Risk Management Fundamentals Asset, threat, vulnerability, exposure and risk
Asset
An asset is something that has value to the organisation.
Assets may include:
Threat
A threat is a potential cause of an unwanted event that could harm an asset or organisational objective.
Cybercriminals, insiders, competitors or nation-state actors.
Human mistakes, configuration errors or accidental deletion.
Hardware failure, software defects or infrastructure failure.
Fire, flood, extreme weather or power failure.
Vulnerability
A vulnerability is a weakness that may contribute to a threat causing harm.
Vulnerabilities are not limited to software bugs.
An internet-facing application contains a vulnerability allowing authentication to be bypassed.
A threat actor could exploit that weakness to access confidential customer information.
The vulnerability is not itself the complete risk. Risk comes from considering the scenario, likelihood and potential consequences.Exposure
Exposure describes the organisation's potential for loss or harm associated with a risk scenario.
Threat = something capable of causing harm.
Vulnerability = weakness that may enable harm.
Risk = uncertainty about the consequences of the scenario, commonly considered through likelihood and impact.
โก Threat and Vulnerability Identification Understand realistic risk scenarios
Identifying vulnerabilities without considering threats can produce a long technical list without explaining the real business risk.
Similarly, identifying threats without understanding the organisation's weaknesses gives an incomplete picture.
"The server has CVE-XXXX-XXXX."
"An external attacker could exploit an unpatched vulnerability on the internet-facing customer portal to gain unauthorised access to customer information, potentially causing a reportable data breach and service disruption."
Useful risk discussions connect:
Threat โ Vulnerability โ Asset โ Event โ Business Impact
โ๏ธ Writing a useful risk statement Translate technical findings into business risk
A good risk statement should communicate the event and its potential consequences clearly enough for a decision-maker to understand.
What threat or condition exists?
What event could occur?
What business impact could follow?
Because privileged accounts do not currently require MFA, there is a possibility that stolen administrator credentials could be used to access production systems, resulting in unauthorised changes, service disruption and exposure of sensitive information.
Security professionals should translate technical weaknesses into business consequences rather than expecting senior leaders to interpret scanner output.
2 Likelihood and Impact The two major dimensions of risk
Likelihood
Likelihood considers the chance that a relevant event or risk scenario will occur.
Factors may include:
Impact
Impact considers the consequences if the event occurs.
Loss of revenue, fraud, recovery costs or penalties.
Loss or degradation of critical business services.
Potential legal obligations or regulatory consequences.
Loss of customer or stakeholder confidence.
Potential harm to people.
Failure to achieve important organisational objectives.
Risk is often taught using:
Risk โ Likelihood ร Impact
This is a useful conceptual model, but real risk methodologies can use more sophisticated calculations, scales and contextual factors.
Simple qualitative risk matrix
Organisations commonly use qualitative scales to help prioritise risks.
| Likelihood โ / Impact โ | Low | Medium | High |
|---|---|---|---|
| High | Medium | High | Critical |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
Risk matrices vary between organisations. This example is illustrative, not a universal scoring model.
3 Qualitative Risk Analysis Describe risk using categories and judgement
Qualitative analysis uses descriptive ratings rather than attempting to assign exact monetary values.
Advantages
- relatively quick;
- easy for stakeholders to understand;
- useful when precise financial data is unavailable;
- effective for prioritising large numbers of risks.
Limitations
- ratings may be subjective;
- different people may interpret categories differently;
- two "High" risks may still represent very different exposures;
- poorly defined scales can produce inconsistent assessments.
Likelihood: High
Impact: High
Overall risk: Critical
4 Quantitative Risk Analysis Estimate risk numerically
Quantitative analysis attempts to express risk using numerical values.
In traditional CISSP study material, several useful terms are commonly used for estimating financial loss.
The monetary value assigned to the asset or loss exposure being analysed.
The estimated percentage of asset value lost during one event.
Estimated financial loss from one occurrence.
Estimated frequency of the event per year.
Estimated annual financial loss associated with the scenario.
Quantitative formulas
One Loss โ SLE ยท One Year โ ALE
๐งฎ Worked quantitative example AV โ EF โ SLE โ ARO โ ALE
Scenario
A business system has an estimated asset value of ยฃ500,000.
A particular incident is expected to cause approximately 20% loss if it occurs.
The incident is estimated to happen approximately once every five years.
AV = ยฃ500,000
EF = 20% = 0.20
SLE = ยฃ500,000 ร 0.20
SLE = ยฃ100,000
Once every five years = 1 รท 5
ARO = 0.2
ALE = ยฃ100,000 ร 0.2
ALE = ยฃ20,000 per year
The estimate provides information that can contribute to decisions about how much it may be reasonable to spend reducing the risk.
Quantitative estimates are only as useful as their assumptions. Asset value, frequency and exposure can all contain uncertainty.
Qualitative vs Quantitative
Qualitative = WORDS ยท Quantitative = NUMBERS
๐ฏ Risk Assessment Scope Know what you are assessing
A risk assessment needs a defined scope.
Without clear scope, important assets or dependencies may be missed and the conclusions may be misleading.
Scope may include
A risk assessment examines a customer-facing application but excludes the external identity provider on which all authentication depends.
The assessment may underestimate risk because a critical dependency sits outside the stated scope.๐ก๏ธ Inherent and Residual Risk Before controls vs after controls
Risk considered before direct or focused management actions are applied to reduce its severity.
Think: Before controls.
Risk remaining after risk responses or controls have been applied.
Think: After controls.
Management needs to understand the remaining residual risk and decide whether further treatment is required.
๐ฝ๏ธ Risk Appetite and Risk Tolerance How much risk is the organisation prepared to take?
Risk appetite
Risk appetite describes the broad level and type of risk an organisation is willing to pursue or retain in support of its objectives.
Risk tolerance
Risk tolerance provides more specific boundaries or acceptable variation around risk-taking.
An organisation may have a very low appetite for risks that could expose large quantities of regulated customer data.
It might establish specific tolerance thresholds requiring particular risk scenarios to be escalated to senior management.
Security professionals provide analysis and advice, but they should not independently decide how much enterprise risk the organisation is willing to accept.
5 Risk Response and Treatment Avoid ยท Mitigate ยท Transfer ยท Accept
Once risk has been assessed, the organisation needs to decide what to do about it.
Stop the activity creating the risk.
Implement controls to reduce likelihood and/or impact.
Shift or share financial or operational consequences through mechanisms such as insurance or contracts.
Make an informed decision to retain the remaining risk.
๐ฒ Risk Treatment examples See the four responses in practice
๐ซ Avoid
An organisation plans to offer a high-risk online service but decides the potential exposure outweighs its business value.
The project is cancelled.
๐ก๏ธ Mitigate
Privileged accounts are vulnerable to password theft.
The organisation introduces phishing-resistant MFA, stronger monitoring and privileged-access controls.
๐ค Transfer
The organisation purchases cybersecurity insurance to reduce some of the financial consequences associated with certain cyber incidents.
โ Accept
A low-impact internal system has a minor residual risk.
Management determines that further remediation would cost far more than the risk justifies and formally accepts it.
Cyber insurance may transfer some financial consequences, but an organisation may still experience operational disruption, reputational damage, regulatory consequences and customer harm.
โ๏ธ Risk Acceptance Acceptance should be informed and authorised
Risk acceptance does not mean:
Doing nothing through neglect is not the same as an informed risk decision.
A sound acceptance process may include:
- a clearly documented risk scenario;
- likelihood and impact assessment;
- existing controls;
- residual risk;
- business justification;
- appropriate risk-owner approval;
- review or expiry date;
- ongoing monitoring.
The person accepting the risk should have appropriate authority over the business consequence.
A vulnerability analyst or penetration tester should not normally accept enterprise risk simply because they discovered it.
6 Types of Security Controls What role does the control perform?
Attempts to stop an unwanted event before it occurs.
Example: MFA.
Identifies events that have occurred or are occurring.
Example: intrusion detection or monitoring.
Corrects a problem or reduces its effects after detection.
Example: applying a patch after identifying a vulnerability.
Discourages inappropriate behaviour.
Example: warning notices or visible surveillance.
Helps restore capability after an event.
Example: restoring systems from backups.
Provides alternative protection when the preferred control cannot be implemented.
Control function memory aid
๐งฑ Control implementation categories Administrative ยท Technical ยท Physical
Policies, governance, risk-management processes, training and organisational procedures.
Technology-based controls such as authentication, encryption, firewalls and monitoring.
Controls protecting facilities and physical assets, such as locks, barriers and guards.
A control can have both a type and a function.
For example, a locked data-centre door may be a physical preventive control.
7 Control Assessments Having a control is not enough
Risk management should consider whether security and privacy controls are properly implemented and operating as intended.
A control assessment may examine:
Is the control capable of addressing the risk?
Has it actually been deployed correctly?
Is it operating consistently?
Is it reducing the risk as expected?
Policy requires MFA for privileged access.
MFA technology exists, but 15% of administrator accounts are excluded from enforcement.
The presence of an MFA product does not prove that the control is completely effective.If an assumed control is ineffective, the organisation's real residual risk may be higher than its risk register suggests.
๐ฐ Cost-Benefit Considerations Security investment should be proportionate to risk
Risk treatment has a cost.
Organisations therefore need to consider whether proposed controls provide reasonable risk reduction relative to their cost and business impact.
A low-value internal application produces an estimated annual loss expectancy of approximately ยฃ5,000.
A proposed dedicated security solution would cost ยฃ300,000 every year.
The organisation should consider whether a different treatment provides better value.Risk decisions may also involve safety, legal obligations, regulatory requirements, reputational consequences and uncertainty that are not captured by a simple financial estimate.
๐ Risk Register Document and track important risks
A risk register provides a structured record of identified risks and their management.
Fields might include:
Risk: Theft of privileged credentials could enable unauthorised production access.
Likelihood: High
Impact: High
Treatment: Implement phishing-resistant MFA and PAM.
Owner: Technology service owner.
Risks should be reviewed, updated and actively managed rather than simply recorded once and forgotten.
๐ค Risk Ownership Someone must be accountable for the risk
Identified risks should normally have an appropriate owner.
The owner should be capable of understanding and influencing the business consequences of the risk.
A security consultant identifies a serious weakness in an online banking service.
The consultant can assess and communicate the risk.
The relevant business or service owner is typically better placed to own the resulting business-risk decision.Risk ownership should reflect organisational authority and accountability.
8 Continuous Monitoring and Measurement Risk changes over time
Risk assessments represent a view of risk at a particular point in time.
Threats, vulnerabilities, controls and business conditions change.
Risk therefore needs ongoing monitoring.
Changes that may alter risk
A vulnerability is initially considered low likelihood because no public exploit exists.
Two weeks later, reliable exploitation code becomes widely available and active attacks are observed.
The original risk assessment should be reconsidered.๐ Risk Measurement: KRI and KPI Know what you are measuring
Provides information about exposure or changing risk.
Provides information about the performance of an activity or process.
Number of critical internet-facing vulnerabilities older than the organisation's risk threshold.
Percentage of vulnerability-remediation tickets completed within the agreed service target.
A process can perform efficiently while the organisation still has significant underlying risk.
9 Risk Reporting Internal and external communication
Risk information should reach the people who need it in a form they can understand and act upon.
Internal reporting
External reporting
Depending on circumstances, risk or incident information may also need to be communicated externally.
"There are 84,392 open CVEs."
"Three critical vulnerabilities affect the service responsible for approximately 40% of online revenue. Two are internet-accessible and one has confirmed active exploitation."
Decision-makers need enough context to understand business exposure and make informed risk decisions.
10 Continuous Improvement Risk management should become more mature over time
Mature risk management is not a one-time annual assessment exercise.
Organisations should learn from:
Signs of increasing maturity
Teams assess similar risks using comparable approaches.
Important risks have accountable owners.
Cybersecurity risk feeds into wider enterprise decisions.
Risk indicators provide meaningful information.
Significant changes trigger reassessment.
Lessons from incidents and assessments improve future decisions.
๐ถ Risk Maturity From reactive to integrated
Risk maturity models help organisations evaluate how developed and repeatable their risk-management capability is.
Models differ, but a simplified maturity progression might look like:
Risk decisions are inconsistent and mainly reactive.
Some common processes exist but may vary between teams.
Organisation-wide processes and responsibilities are documented.
Risk performance and outcomes are monitored using meaningful data.
Risk management is integrated into strategic decisions and continuously improved.
Maturity models use different names and numbers of levels. The important concept is progression from inconsistent risk management toward repeatable, measured and continuously improved processes.
11 Risk Frameworks Structured approaches to managing security risk
Organisations can use established frameworks to create consistent approaches to cybersecurity risk.
๐บ๐ธ NIST
NIST provides extensive guidance for identifying, assessing, responding to and monitoring cybersecurity risk.
The NIST Risk Management Framework and IR 8286 series connect cybersecurity risk with organisational and enterprise risk management.
๐ ISO
ISO/IEC standards provide internationally recognised approaches to information security and risk management, including the ISO/IEC 27000 family.
๐๏ธ COBIT
COBIT provides governance and management guidance connecting enterprise information and technology risk with business objectives.
๐๏ธ SABSA
SABSA provides a business-driven security architecture approach in which security requirements are derived from business needs.
๐ณ PCI
Payment Card Industry standards establish security expectations for environments handling payment-card information.
Framework selection should reflect organisational requirements, industry, objectives, regulatory environment and risk-management needs.
A useful NIST risk-management view
๐ข Cybersecurity Risk and Enterprise Risk Cyber risk is business risk
Cybersecurity risks should not remain trapped inside a security department.
Major cybersecurity risks can affect:
A ransomware risk affecting a manufacturing plant is not merely an "IT risk".
It may affect production, customer delivery, revenue, safety, contractual obligations and corporate reputation.
Significant cybersecurity risk therefore belongs within wider enterprise-risk discussions.โ ๏ธ Common mistakes Risk concepts people frequently confuse
A vulnerability is a weakness. Risk requires consideration of the threat scenario and potential consequences.
Technical severity is important, but organisational risk also depends on exposure, likelihood, business context and impact.
Zero risk is rarely achievable. Organisations manage risk in the context of objectives, cost, appetite and tolerance.
Insurance may transfer some financial consequences but cannot remove every operational, legal or reputational consequence.
Controls commonly reduce rather than completely eliminate risk. Residual risk is the portion remaining afterward.
Proper acceptance is an informed, documented and authorised business decision.
A technically severe vulnerability may present limited organisational risk if the vulnerable component is not exposed or does not support important assets.
A lower-severity technical weakness could still create significant risk in a sensitive business context.
Security provides expertise and assessment. Risk acceptance should be made by an appropriately authorised risk owner.
Significant changes in threats, controls, systems or business context may require reassessment before the next scheduled review.
Think like a risk advisor, not only a technician
CISSP questions often present a technical problem but ask for the best risk-management response.
Understand the business context before jumping directly to a technical control.
โก Identify
๐ Analyse
๐ก๏ธ Respond
๐ค Governance
๐๏ธ Monitor
๐ฃ Communicate
๐ Practice scenarios Apply risk-management thinking
Scenario 1 โ Vulnerability discovered
A vulnerability scanner reports a critical vulnerability.
What should happen next?
Understand the affected asset, exposure, relevant threats, existing controls and potential business impact before determining the appropriate risk response.
Scenario 2 โ Remove the risky service
Management decides that a risky service provides insufficient business benefit and permanently closes it.
Risk treatment:
Avoidance.
Scenario 3 โ Install MFA
The organisation introduces MFA to reduce the likelihood that stolen passwords can be used successfully.
Risk treatment:
Mitigation.
Scenario 4 โ Cyber insurance
The organisation purchases an insurance policy covering certain incident-response costs.
Risk treatment concept:
Transfer or sharing of some financial consequences.
Scenario 5 โ Low residual risk
Existing controls reduce a risk to a level management considers acceptable.
Risk response:
Formal acceptance of the residual risk may be appropriate.
Scenario 6 โ SLE calculation
Asset Value = ยฃ200,000
Exposure Factor = 25%
What is the SLE?
ยฃ200,000 ร 0.25 = ยฃ50,000.
Scenario 7 โ ALE calculation
SLE = ยฃ50,000
ARO = 0.5
What is the ALE?
ยฃ50,000 ร 0.5 = ยฃ25,000 per year.
Scenario 8 โ Control exists
Management believes MFA protects every privileged account, but an assessment discovers that several legacy administrator accounts bypass MFA.
What should be reconsidered?
Control effectiveness and therefore the residual risk.
Scenario 9 โ Threat environment changes
A vulnerability previously had no known exploitation. Active attacks are now being widely reported.
What should happen?
Reassess the risk because likelihood has changed.
Scenario 10 โ Who accepts?
A penetration tester identifies a serious weakness and decides that the organisation should simply accept it.
What is wrong?
The tester can advise on risk, but acceptance should be made by an appropriately authorised risk owner.
Scenario 11 โ Qualitative assessment
A risk is described as "High likelihood and Medium impact."
Analysis type:
Qualitative.
Scenario 12 โ Quantitative assessment
A risk is estimated to produce an average annual financial loss of ยฃ75,000.
Analysis type:
Quantitative.
Risk Management thinking flow
Quick memory aid
Identify. Analyse. Treat. Monitor.
Risk treatment memory aid
Stop. Reduce. Share. Keep.
Quantitative risk memory aid
SLE = ONE EVENT ยท ALE = ONE YEAR
Key takeaways
Risk management supports informed business decision-making. Its purpose is not simply to produce vulnerability lists or eliminate every possible risk.
A useful risk scenario connects assets, threats, vulnerabilities, events and business consequences.
Risk is commonly considered through likelihood and impact.
Qualitative analysis uses descriptive categories such as Low, Medium and High.
Quantitative analysis uses numerical estimates.
Traditional quantitative CISSP calculations include SLE = AV ร EF and ALE = SLE ร ARO.
Inherent risk represents risk before focused management action, while residual risk remains after risk treatment and controls.
Risk can be avoided, mitigated, transferred/shared or accepted.
Cybersecurity insurance can transfer some financial consequences but does not make the underlying operational or security risk disappear.
Controls can serve functions including preventive, detective, corrective, deterrent, recovery and compensating purposes.
Controls should be assessed for implementation and effectiveness rather than assumed to work simply because they exist.
Significant risks should have appropriate risk ownership and should be recorded, monitored and reviewed.
Risk changes as threats, vulnerabilities, systems, controls and business conditions change.
Cybersecurity risk is ultimately business risk. Important cyber risks should therefore connect to wider enterprise-risk management and organisational objectives.
Most importantly: security professionals identify and explain risk so that the right people can make informed decisions about it.
๐ Sources & Further Reading Authoritative references
- ISC2 โ CISSP Certification Exam Outline
View official CISSP exam outline - NIST SP 800-30 Rev. 1 โ Guide for Conducting Risk Assessments
View NIST risk-assessment guidance - NIST IR 8286 Rev. 1 โ Integrating Cybersecurity and Enterprise Risk Management
View NIST ERM guidance - NIST IR 8286A Rev. 1 โ Identifying and Estimating Cybersecurity Risk
View NIST cybersecurity-risk guidance - NIST โ Residual Risk
View NIST definition - NIST โ Inherent Risk
View NIST definition
