TechKnowSurge
NIST CSF ID.RA-05 CompTIA Security+ 5.2 ISC2 CISSP 1.9 CompTIA SecurityX 1.3
VideoSecurityFree

Inherent and Residual Risk

Risk mitigation reduces but rarely eliminates threats entirely, leaving a remaining exposure known as residual risk. Understanding the difference between inherent risk and residual risk is essential for accurate risk management planning.

Complete this video to capture a CTF flag worth 1 point.

About this video

Risk mitigation is a core component of any security or business continuity strategy, but it is important to understand that reducing risk is not the same as eliminating it. Even after controls and countermeasures are put in place, some level of exposure typically remains, and organizations must account for that reality in their planning. Two key terms define this distinction: inherent risk and residual risk. Inherent risk is the level of threat that exists before any mitigation measures are applied, often quantified through risk analysis in financial terms or impact severity. Residual risk is what persists after mitigation has reduced the probability of an event occurring or limited the damage it would cause if it did. For example, a risk initially valued at one hundred thousand dollars might be reduced to thirty thousand dollars following mitigation, and a ten-thousand-dollar risk might drop to two thousand, but neither reaches zero. Recognizing and planning around residual risk ensures that organizations maintain realistic expectations and continue to monitor and manage exposure even after controls are in place.

What you'll learn

What's covered

Inherent vs Residual Risk

Aligned to

NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts.
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Inherent Risk
The level of risk that exists before any mitigation controls or countermeasures are applied. Understanding inherent risk helps organizations determine where to prioritize security investments.
Residual Risk
The level of risk that remains after security controls have been applied to reduce inherent risk. No control eliminates risk entirely; residual risk must be formally accepted by management or addressed with additional mitigations.
Risk Mitigation
The process of reducing the probability or potential impact of a risk through the implementation of controls, countermeasures, or process changes. Risk mitigation is one of four standard risk response strategies alongside avoidance, transfer, and acceptance.

Topics

Inherent Risk Residual Risk Risk Mitigation Risk Management Cybersecurity Risk Assessment

Transcript

Inherent and residual risk

When we mitigate risk it might not go away completely. In fact it probably won't go away completely in a lot of circumstances.

In our scenario here, we've identified a lot of different risks. We have five different risks that we have, and within those risks what we see here is the risk associated with it. So we have a $100,000 risk, we've got a $10,000, a $30,000, a $120,000 and a $10,000. This is the risk that's associated with it after we do risk analysis on these different risks.

Now let's say we develop a plan, and that plan is going to mitigate some of those risks. Mitigation means that we're reducing the risk, and we're reducing the probability, or, if it were to happen, the impact that it would have. So now, instead of this $100,000 risk, maybe now that is going to be at $30,000. Or maybe instead of this $10,000, maybe that's going to be at $2,000. So we're going to go through and we're going to mitigate the risk here, and we're going to have a certain amount of risk after we've mitigated it.

This is what the terms inherent risk and residual risk mean. Inherent is just what the risk is initially, and then the residual risk is the risk that continues.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →