Cybersecurity risk management centers on two core activities: establishing a measurement framework and conducting structured risk assessments. Together, these allow organizations to identify, prioritize, and respond to threats in proportion to their risk tolerance and available resources.
A cyber security program is all about managing risk. However, there are some specific steps that we need to take in managing risk.
Each one of these functions is what I've already outlined as being part of a cyber security program, and you could take any one of these functions and argue that it is risk management. So what do I mean by risk management, and what does this function look like?
When it comes to risk management I break it into two different objectives — or, since we're thinking of risk management as being a function, I like to think of it as breaking it into two different sub-routines. Number one is measurement, or creating the measurement that we're going to measure everything else against. Second is the risk assessment piece of this.
Let's first tackle the measurement side of this. Risk has an equation, and that equation is probability times impact equals our risk.
Depending on how much resources we have and how in depth we want to go with measuring risk, we might choose different routes in measuring what our risk is. For instance, in this example right here, probability we could just measure by rare, unlikely, possible, likely or certain, and then we would just assess what we feel like this would be at. And the impact: negligible, minor, moderate, major or severe — once again we would choose what level we would feel like that was at.
Or I could actually get some numbers involved in this. Probability would be a percent, the likeliness that something would happen, and the impact would be more the dollar amount of the impact if it were to happen. Then we actually have dollar amounts associated with risk, and this is obviously more ideal, actually having a dollar amount of the cost of that risk. However, there's a lot more that has to go into figuring those numbers out, so it can be a lot more resource intensive to figure out those numbers.
The first step really is to choose what model we're going to use, based off of the business needs and how much resources we have, and then start putting some boundaries around it on how we're going to label these different risks.
Another thing that needs to happen is some sort of assessment on what the business risk tolerance is. There are some businesses that are just starting up and there's not a lot of assets that need to be protected right from the beginning, plus we need to be really agile, so we're willing to take more risks to move forward quickly. The flip side of that is that we may be a more established business with lots of assets that we need to protect and not be willing to take as big of risks, so we're willing to spend more money on mitigating those risks than a company that wants to be more agile.
As an example, in our vendor and supply chain management we want to assess the risk of a new vendor. If we were bringing on a new vendor we would assess the risk of that vendor. What we have now is a measurement to measure against, to see what the risk is of that vendor.
That brings us to the risk assessment. Although each of these functions could have an element of risk assessment in it, what I'm really talking about is a separate risk assessment — a separate risk assessment that's done on some sort of recurring basis, maybe on an annual basis. What would be generated out of it is some sort of report, a risk assessment report, that would then be reported to the leadership so they understand the risk involved in the company. It also would help you get resources to mitigate those risks, and then set out tasks and projects so that way you can mitigate risk within the company.
This risk assessment would have its own process. Once again, you would establish the risk tolerance of the business and make sure that the model is still accurate. You would go into identifying what risks there are to the company, analyze those risks, prioritize those lists based off of what the impact would be to the company or what the risk is to the company, plan to mitigate those risks, go through a mitigation process, and then monitor to see if it was effective or not.
The risk assessment is very comprehensive in nature, so you're going to look at all aspects of the company and do many different types of assessments on the company, and that's all going into this risk assessment report.
You also may utilize things like a risk register, where you would document the risk, who is the owner of the risk, and some details around those risks. Then we would want to choose how we're going to respond to that risk — whether we avoid the risk, reduce the impact of that risk somehow, or transfer the risk.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →