TechKnowSurge
Cisco CCNA 5.2 Cisco CCST Cybersecurity 1.1 CompTIA SecurityX 1.2 Cisco CCST IT 5.3 CompTIA SecurityX 1.3 Cisco CCST Cybersecurity 4.3
VideoNetworkFree

Risk Management

A strong security program requires consistent policies, frameworks, and risk management practices to protect an organization from threats that individual employees often underestimate or overlook. This content covers how to build that program, select a security framework, and apply structured strategies to assess and respond to risk.

Complete this video to capture a CTF flag worth 1 point.

About this video

Most employees believe they are unlikely to be hacked, that their passwords are strong enough, and that they would recognize a phishing attempt — yet security incidents driven by exactly these assumptions happen constantly. This disconnect is why a formal security program is critical. Without one, security knowledge and behavior vary by individual role and experience, legacy systems fall outside anyone's direct oversight, and there is no consistent standard to hold people accountable to. A security program addresses this by establishing organization-wide policies that set clear expectations, procedures that define how those expectations are carried out, and controls that create measurable standards for auditing and enforcement. Regular employee testing, such as simulated phishing campaigns, is a key component — and evidence shows that without ongoing monitoring and education, the same individuals make the same mistakes repeatedly. A security program is built on a security framework, which serves as the architectural blueprint for what secure operations should look like. Widely adopted frameworks include NIST 800-53, the NIST Cybersecurity Framework, COBIT, and ISO 27001, each providing structured guidance that organizations can adapt to their specific environment and risk profile. Risk management is the operational core of any program built on these frameworks. It begins with assessment — identifying threats, analyzing system vulnerabilities, conducting penetration testing through third-party specialists, evaluating overall security posture, and reviewing business processes and vendor agreements for gaps. Risk itself can be quantified: multiplying the probability of an incident by its financial impact produces a calculated risk value that allows different risks to be compared and prioritized objectively. Once risks are ranked, organizations select from four primary response strategies. Avoidance means deciding not to pursue a system or process whose risk level is unacceptable. Reduction involves implementing additional controls — such as enhanced firewall configurations — to lower either the likelihood or the potential impact of an incident. Transference shifts the financial exposure to a third party through cybersecurity insurance or by outsourcing a high-risk component entirely. Acceptance is appropriate when the probability or impact is low, or when the business value of moving forward clearly outweighs the residual risk. Together, these elements — a structured security program grounded in an established framework and supported by disciplined risk management — form the foundation of a credible, organization-wide security strategy.

What you'll learn

What's covered

Security Program & Risk Management

Aligned to

Cisco CCNA
5.2 Describe security program elements
Cisco CCST Cybersecurity
1.1 Define essential security principles
4.3 Explain risk management
CompTIA SecurityX
1.2 Given a scenario, implement the appropriate risk management strategies, policies, and controls
1.3 Explain the importance of risk management for an enterprise
Cisco CCST IT
5.3 Recognize how company policies and confidentiality guidelines protect user data

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Threat
Any potential event or action that could cause harm to a system, network, or organization.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.
Security Program
An organized set of policies, procedures, and controls that coordinates an organization's approach to protecting its information assets.
Security Framework
A structured blueprint of standards and best practices used to guide the development of an organization's security program.
Quantitative Risk Calculation
A method of measuring risk by multiplying the probability of a threat occurring by its financial impact to produce a numeric risk value.

Transcript

The Need for a Security Program

Your networks are prone to a lot of risk, so how do we manage that?

My guess is that if you were to go and ask the employees of a business how likely they are to get hacked — how likely it is that their email is going to get hacked, how likely it is that their password will be compromised, how likely it is that they will fall for a phishing technique, how likely it is that somebody will leverage that employee to get into the business and hack the business — almost 100% of people are going to say, "No, that's not going to happen to me. That's unlikely to happen to me. My password is secure enough and I'm not going to fall for any phishing." Yet it happens all the time. The thing is that we have different experiences and we have different positions.

From a security program standpoint, I've got some people listed out here as part of a business. We've got HU, who has been in sales for 5 years selling products, and he's never got hacked before. Perhaps what he feels is that because he hasn't been hacked, he's in a comfortable position and he's thinking of everything correctly, when in fact his password might be terrible. He just might have got lucky and not have been hacked yet. Then you have Rick over here, who has some knowledge of security. He's a programmer, so he's security-minded, but he has this silo and he just does security for this position.

My point is that your security is only good to the point that these people are educated to, and they don't know any better. If you don't have a security program, you can never have consistency among these people to know what standard they need to be at. Another example that I have in here is a system, a process, that's 15 years old and very outdated, and it outdates all of these people. Maybe this system doesn't fall under anybody's umbrella, and it's a system that's out there and maybe has some security risk to it. That is a problem.

A security program identifies all of this and trains the people in what the expectation is. It does audits to make sure people are following through with what they need to be following through with. It captures these processes that are outside of other people's purview. A good security program is going to take a look at all of these different aspects and make sure that the whole company is coordinated with this.

Let me put it another way. This is somebody's network, and this network has a wall built around it for security purposes. But there are all of these doors to get into it. These doors, these gates, are individual employees' accounts, and these individuals will have a username and password to get into these gates. Supposedly this network is secure, but it just takes one person to leave the door open — a bad password that they have, or they've left it written on a message, or somebody has gotten a hold of this password — and now it doesn't just expose this little area, it exposes the whole network behind this. Once they're in there behind it, they can see everything, and it exposes everything.

A good security program makes sure that everybody is up to speed, that everybody understands they need to have these gates closed, that they need to have good passwords, and that they need to understand what phishing techniques are out there. Even with a good security program, I test the employees at the company I'm working for on a regular basis. Every couple of weeks they get phishing messages in their inbox, coming from a system that we manage, and it is testing them to see if they click on the links. And I have the same people that click on the same links over and over again.

So you have to watch out for this from a security program standpoint. You have to be monitoring this, you have to be educating people, and you have to be testing them. You have to have this full security program to really say that you are doing security, because without it you're all operating in these little different silos and operating at the experience that you have in the position that you have. It's not a true security program unless you dedicate resources towards security.

What a Security Program Is

In its simplest form, it's really just about setting policies. Policies are expectations of how things are going to be, and you set those expectations. You make sure everybody agrees to those expectations, so everybody's on the same page. Then you set procedures and processes, and you implement changes that people are going to follow to make sure that they are being secure.

It also encompasses these things called controls. Controls are where you set aside a measurable standard, and then you hold people to those measurable standards. You hold those processes to those measurable standards. A security program has to have these elements of policies, procedures and controls to make sure that people are educated on what they're supposed to be doing, and that they are in fact doing what they should be doing.

Security Frameworks

Now, what should they be doing? What should you be doing? You need some sort of security framework, something that outlines what this looks like. I look at it as a blueprint. A security framework is a blueprint. There are many different security frameworks out there. You would select a security framework, and then you would build your security program off of this security framework. Some examples of this would be NIST 800-53, the NIST Cybersecurity Framework, COSO or COBIT, or ISO 2700. There are different frameworks out there that can be utilized to start building this security program around.

Risk Management

A good security program has risk management. Risk management is the process of taking and analyzing risk, figuring out what risks are going to be detrimental to the company, and figuring out how to mitigate those risks.

A couple of areas that this can be done in: first of all, the security risk assessment. Through a security risk assessment you look at what threats are out there and what threats you should be worried about. You look at vulnerabilities — what systems do you have out there, and what vulnerabilities do those systems have. You conduct something called penetration testing. Penetration testing, or pentesting, is a third party that comes in and starts testing out your network to see how they can penetrate it, where the vulnerabilities are, and how they can leverage the different systems. There's also posture assessment, which analyzes your whole security platform, your whole security program, to make sure that it is at a level that it needs to be for the size of business that you are.

There's also business risk assessment: assessing processes to make sure there are no gaps in the processes of the business. One of those is the vendor assessment as well. Make sure that the vendors are the appropriate vendors, and that there are no gaps with the agreements with the vendors and how the vendors operate. So there are some assessments that go into this to analyze the risk and see what the risk level is within each one of these different components.

Calculating Risk

Risk can actually be calculated. We can come up with quantitative data for risk, and this is helpful so we can compare different risks and prioritize different risks. What I mean by that is that risk is probability times impact, and that's how we calculate it. Probability is a percent, and the impact is a dollar amount, a monetary amount.

Let's give an example. We have a certain particular system that we're analyzing, and the probability that it would get hacked in the current state is 10%. If it got hacked, it would cost us $100,000 to fix — or maybe loss of productivity, or maybe loss of our reputation, or maybe some sort of impact like that. So the risk involved with this would be $10,000, 10% of $100,000. That would be the risk level, whatever's come out of the assessment.

So we can actually put calculated data, something that is solid information, with this. Once again, this helps if we have a lot of different risks. We can figure out the probability that each one of those would occur, figure out the impact that it would have on the business, and calculate what we figure the loss would be for this. Then we can prioritize based off of that.

Strategies for Responding to Risk

With risk management, we assess the risk, we prioritize the risk, and then we take some sort of action against that risk. So what actions can we take against the risk? There are a few different options that we have.

  • Avoid it. Maybe if we're rolling out this new system and we figured 10% that it's going to get hacked, that seems really high. That seems a little crazy to me, so perhaps we just don't roll out that system, and therefore we practice the avoidance of rolling out this system.
  • Reduce it. Maybe we'd reduce the impact, or reduce the likelihood that it's going to get attacked and that it's going to get compromised. So we put extra security in front of it — maybe some extra firewall security in front of it to make sure that it's extra secure. We're reducing the chances of that happening.
  • Transfer it. What that means is maybe we go out and get insurance, or maybe we hire that component out to another agency, so we are going to transfer it to another agency. An example of that is an insurance policy out on whatever it is that we're putting out there. Maybe we take out some extra cybersecurity insurance, or something to that effect.
  • Accept the risk. There are times when we recognize yes, this is a risk, but the probability is low, or the impact is low, or the reward is high by doing whatever it is that we're doing, and so we're just going to accept it.

These are some strategies for when we discover risk. What are we going to do? Are we going to avoid it? Are we going to reduce the impact? Are we going to transfer it, or are we going to accept it?

The first thing that we talked about is the security program and the need for a security program. It is so important, because otherwise you just have people doing whatever they think is secure, and that is not a form of security at all. We talked about different security frameworks, things that you can start building that foundation with and build the security program off of that foundation.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →