Risk mitigation reduces but rarely eliminates threats entirely, leaving a remaining exposure known as residual risk. Understanding the difference between inherent risk and residual risk is essential for accurate risk management planning.
Inherent vs Residual Risk
When we mitigate risk it might not go away completely. In fact it probably won't go away completely in a lot of circumstances.
In our scenario here, we've identified a lot of different risks. We have five different risks that we have, and within those risks what we see here is the risk associated with it. So we have a $100,000 risk, we've got a $10,000, a $30,000, a $120,000 and a $10,000. This is the risk that's associated with it after we do risk analysis on these different risks.
Now let's say we develop a plan, and that plan is going to mitigate some of those risks. Mitigation means that we're reducing the risk, and we're reducing the probability, or, if it were to happen, the impact that it would have. So now, instead of this $100,000 risk, maybe now that is going to be at $30,000. Or maybe instead of this $10,000, maybe that's going to be at $2,000. So we're going to go through and we're going to mitigate the risk here, and we're going to have a certain amount of risk after we've mitigated it.
This is what the terms inherent risk and residual risk mean. Inherent is just what the risk is initially, and then the residual risk is the risk that continues.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →