About this interactive
Every card here describes something an organization actually did about a risk, and the bin is that action, not the size of the risk or how urgent the sentence sounds. Four questions separate them cleanly. Did the organization stop doing the risky thing altogether? That is Avoid — and the tell is always that some business activity ends: card payments switched off, a product line discontinued, a BYOD rollout cancelled. Did it keep doing the activity but make the risk smaller? That is Mitigate — the WAF, the MFA rollout and the patch cycle all leave the business doing exactly what it was doing before, just with a lower likelihood or a smaller blast radius. Did it keep the activity and arrange for somebody else to absorb the cost? That is Transfer. Did it keep the activity, absorb the cost itself, and write that choice down? That is Accept. The trap this activity is built around is insurance. "Purchasing cyber liability insurance" feels protective, and protective feels like mitigation, so it is one of the most reliably missed items on the exam — but a policy does not make a breach any less likely and does not make it any smaller when it happens. It changes who pays. That is Transfer, and it is the definition rather than a technicality: transfer moves financial liability to a third party while leaving the underlying risk exactly where it was. The same test catches the two quieter transfer items. Outsourcing card processing to a PCI-certified vendor is not mitigation even though the vendor is genuinely better at it, because what moved is the liability for handling that data. A managed security services contract that includes breach response costs is transfer for the same reason — read the clause about who pays, not the part about who monitors. One caution worth carrying past the exam: transfer moves financial liability, never accountability. Regulators and customers still come to you after a breach, and the insurer's cheque does not answer to them. Acceptance is the other half of the vocabulary problem, and it is usually mistaken for its opposite. Accepting a risk is not ignoring one. Every Accept card in this set contains a decision and a record: the CISO documents that a low-probability, low-impact risk waits until next quarter; a small business compares a $5,000 remediation against the expected loss, decides the fix costs more than the risk, and logs it; a theoretical attack vector with no known exploits is recorded as accepted residual risk. Somebody with authority weighed it, chose to proceed, and left a trail. A risk nobody has noticed is not accepted, it is unmanaged — and the difference is the documentation. That is also why acceptance is the strategy every organization ends up using most: once you have avoided, mitigated and transferred what is worth the money, whatever is left is residual risk, and accepting it deliberately, within a stated risk appetite, is what finishing the process looks like.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →