Risk management is the foundation of any cybersecurity program, focused on identifying, assessing, and responding to threats based on probability, potential impact, and available resources. This content covers the risk equation, the risk management process, risk assessment methods, and the four core risk response strategies.
Cybersecurity Risk Management
If you were to go out and want to buy a safe to put your valuables in and keep them protected, then you would notice that these safes have ratings to them, and the ratings are associated with how long it takes a professional to break into it. That's right, no safe is 100% protected. There's nothing that is going to be uncrackable out there. The question is, how much time and effort does it take to actually break into that safe?
That's similar to cyber security. Nothing we do is going to be 100% protected, but what we have to do is analyze and assess to see how protected we want to be and what the costs are associated with that level of protection. That's really what risk management is all about, and that's really what a cyber security program is about. It's about risk management and figuring out where your time, money and resources are going to be best spent to protect those resources that you're in charge of.
The risk of something happening — like this threat agent getting a hold of this data — has that equation: what is the probability, and what is the impact. We could put a high, medium, low to these, or there are several ways we could go about doing it, but one common way is to put a percentage to the probability. What's the probability that it's going to happen, and then what is the impact going to be?
So let's say it's a 10% possibility that something could happen, and the impact could be $1 million in loss if it does happen. Then the risk level to this is going to be $100,000, that's 10% times 1 million. So that is the risk level.
What is the risk management process? It's going to start out by defining what your risk tolerance is, and that's going to be individual to the company or organization that you're working with. You're probably going to go and talk to some execs, maybe the board of directors, maybe some of the people in the company, to find out what risk tolerance you have.
Then it gets into assessing the risk. We're going to identify the assets that are at risk, we're going to identify the vulnerability of those assets, we'll identify the threats, the impact if something happens, and what the likelihood is. From there, what we can do is identify and prioritize different risk responses to what we found in that assessment process. And then finally we would take action and implement some sort of change.
There are several different ways that we can assess risk. We can do some security risk assessments or some business risk assessments, but essentially we need to find those risks. So we could do a threat assessment, vulnerability assessment, penetration testing, posture assessment, process assessment, vendors — so we're looking at the processes and the vendors. We could approach this in many different ways, and there's more than just what's listed here. So we take this holistic, overall view of trying to figure out what our risks are and where those risks are.
One of the things that we should probably be utilizing is a third-party assessment, especially for things like penetration tests. It's pretty common to go to another organization that does something like your penetration test, and the reason for that is because somebody that's in the company trying to test the company has already protected against the things that they know are the weaknesses, so it's hard for them to think outside the box. But when you have a third party come in and assess — and your vendors and your clients may actually insist upon that — when having a third party come in, that is a separate organization that is not attached to your organization, come in and do an assessment, then they can think outside the box and better do an evaluation of your system.
Once we've found the risks in a system, there are several different strategies which we can take to approach that risk.
Number one, we could do avoidance. An example of this is, let's say we want to roll out a piece of software. It's going to help us do business, but when we look into it, it's going to open some risk up for us, and so we may choose not to roll out that piece of software because we want to avoid that risk. We don't want to even open that up and make it a possibility.
The other thing we could do is reduce the impact that it has. An example is, maybe the reason why the software that we want to roll out is going to expose us is because it has certain data in it — maybe it has some social security numbers and it opens those up so somebody could steal them. What we may choose to do is remove that sensitive piece of data, like the social security numbers, so we are going to reduce the impact if the data was stolen, because some of the data is going to be missing and gone.
Or we could transfer it. Maybe we say, okay, we're going to roll out this piece of software, but what we're going to do is take out extra insurance in case something happens, and so we are going to transfer the risk to insurance. If something happens, then we will actually get paid through insurance as a compensation for it.
Or we could accept the risk and just say, we realize that there's going to be a risk, but we have to have this piece of software and the benefits of this software outweigh the risks, so we are going to still roll that out.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →