TechKnowSurge
NIST CSF GV.RM-06 NIST CSF ID.RA-04 ISC2 CC 1.2 Cisco CCST Cybersecurity 4.3 NIST 800-53 RA-3 NIST 800-53 RA-7 NIST CSF GV.RM-04 ISC2 CC 2.1
VideoSecurityFree

Protection - Risk Management

Risk management is the foundation of any cybersecurity program, focused on identifying, assessing, and responding to threats based on probability, potential impact, and available resources. This content covers the risk equation, the risk management process, risk assessment methods, and the four core risk response strategies.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cybersecurity is fundamentally a risk management discipline. Just as physical safes are rated by how long they resist a professional attack rather than being considered unbreakable, no digital defense is absolute. The practical question is always how much time, money, and effort it takes for an attacker to succeed — and whether the cost of better protection justifies the reduction in risk. Every organization must decide where its resources are best spent based on what it is protecting and how much exposure it is willing to tolerate. Risk is quantified through a straightforward equation: probability multiplied by impact. If there is a 10 percent chance of a breach that would cause one million dollars in damage, the calculated risk level is one hundred thousand dollars. This figure gives decision-makers a concrete basis for prioritizing investments. The broader risk management process starts with establishing risk tolerance — typically defined in consultation with executive leadership or a board — then proceeds through asset identification, vulnerability analysis, threat modeling, likelihood estimation, and finally the selection and implementation of appropriate controls. Assessing risk requires a comprehensive view of the organization, drawing on threat assessments, vulnerability scans, penetration tests, process reviews, and vendor evaluations. Third-party assessments are especially valuable for exercises like penetration testing, because external evaluators are not constrained by internal assumptions and can surface vulnerabilities that in-house teams have inadvertently worked around. Clients and business partners frequently require independent assessments as a condition of doing business, reinforcing their role as an industry standard. Once risks are identified and prioritized, four core response strategies apply. Avoidance means declining to take an action that would introduce unacceptable risk, such as not deploying a piece of software that exposes sensitive data. Reduction involves lowering the potential impact — for example, removing sensitive fields like Social Security numbers from a dataset before deployment. Transference shifts the financial consequence of a risk to a third party, typically through insurance or contractual agreements. Acceptance acknowledges that a risk exists but concludes that the business benefit of proceeding outweighs the potential downside. Choosing among these strategies is central to operating a mature, sustainable cybersecurity program.

What you'll learn

What's covered

Cybersecurity Risk Management

Aligned to

NIST CSF
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.
GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated.
ISC2 CC
1.2 Understand risk management concepts
2.1 Plan Governance, Risk, and Compliance (GRC)
Cisco CCST Cybersecurity
4.3 Explain risk management
NIST 800-53
RA-3 Risk Assessment
RA-7 Risk Response

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Threat
Any potential event or action that could cause harm to a system, network, or organization.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Risk Tolerance
The level of risk an organization is willing to accept before taking action to reduce or eliminate it. Risk tolerance is determined by leadership and reflects the organization's risk appetite, regulatory environment, and available resources.
Risk Avoidance
A risk response strategy that eliminates exposure to a risk by choosing not to engage in the activity that creates it.
Risk Reduction
A risk response strategy that takes steps to decrease the probability or impact of a risk.
Risk Transference
A risk response strategy that shifts the financial or operational burden of a risk to a third party, such as through insurance.
Risk Acceptance
A risk response strategy that acknowledges a risk and proceeds without additional mitigation because the benefits outweigh the potential harm.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.

Topics

Risk Management Risk Assessment Risk Response Strategies Cybersecurity Threat Analysis Risk Equation

Transcript

If you were to go out and want to buy a safe to put your valuables in and keep them protected, then you would notice that these safes have ratings to them, and the ratings are associated with how long it takes a professional to break into it. That's right, no safe is 100% protected. There's nothing that is going to be uncrackable out there. The question is, how much time and effort does it take to actually break into that safe?

That's similar to cyber security. Nothing we do is going to be 100% protected, but what we have to do is analyze and assess to see how protected we want to be and what the costs are associated with that level of protection. That's really what risk management is all about, and that's really what a cyber security program is about. It's about risk management and figuring out where your time, money and resources are going to be best spent to protect those resources that you're in charge of.

The risk equation

The risk of something happening — like this threat agent getting a hold of this data — has that equation: what is the probability, and what is the impact. We could put a high, medium, low to these, or there are several ways we could go about doing it, but one common way is to put a percentage to the probability. What's the probability that it's going to happen, and then what is the impact going to be?

So let's say it's a 10% possibility that something could happen, and the impact could be $1 million in loss if it does happen. Then the risk level to this is going to be $100,000, that's 10% times 1 million. So that is the risk level.

The risk management process

What is the risk management process? It's going to start out by defining what your risk tolerance is, and that's going to be individual to the company or organization that you're working with. You're probably going to go and talk to some execs, maybe the board of directors, maybe some of the people in the company, to find out what risk tolerance you have.

Then it gets into assessing the risk. We're going to identify the assets that are at risk, we're going to identify the vulnerability of those assets, we'll identify the threats, the impact if something happens, and what the likelihood is. From there, what we can do is identify and prioritize different risk responses to what we found in that assessment process. And then finally we would take action and implement some sort of change.

Risk assessments

There are several different ways that we can assess risk. We can do some security risk assessments or some business risk assessments, but essentially we need to find those risks. So we could do a threat assessment, vulnerability assessment, penetration testing, posture assessment, process assessment, vendors — so we're looking at the processes and the vendors. We could approach this in many different ways, and there's more than just what's listed here. So we take this holistic, overall view of trying to figure out what our risks are and where those risks are.

One of the things that we should probably be utilizing is a third-party assessment, especially for things like penetration tests. It's pretty common to go to another organization that does something like your penetration test, and the reason for that is because somebody that's in the company trying to test the company has already protected against the things that they know are the weaknesses, so it's hard for them to think outside the box. But when you have a third party come in and assess — and your vendors and your clients may actually insist upon that — when having a third party come in, that is a separate organization that is not attached to your organization, come in and do an assessment, then they can think outside the box and better do an evaluation of your system.

Risk strategies

Once we've found the risks in a system, there are several different strategies which we can take to approach that risk.

Number one, we could do avoidance. An example of this is, let's say we want to roll out a piece of software. It's going to help us do business, but when we look into it, it's going to open some risk up for us, and so we may choose not to roll out that piece of software because we want to avoid that risk. We don't want to even open that up and make it a possibility.

The other thing we could do is reduce the impact that it has. An example is, maybe the reason why the software that we want to roll out is going to expose us is because it has certain data in it — maybe it has some social security numbers and it opens those up so somebody could steal them. What we may choose to do is remove that sensitive piece of data, like the social security numbers, so we are going to reduce the impact if the data was stolen, because some of the data is going to be missing and gone.

Or we could transfer it. Maybe we say, okay, we're going to roll out this piece of software, but what we're going to do is take out extra insurance in case something happens, and so we are going to transfer the risk to insurance. If something happens, then we will actually get paid through insurance as a compensation for it.

Or we could accept the risk and just say, we realize that there's going to be a risk, but we have to have this piece of software and the benefits of this software outweigh the risks, so we are going to still roll that out.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →