The Do’s and Don’ts Of Security Risk Management

Managing risk effectively is a balancing act. Leveraging data while safeguarding it requires careful consideration and the application of appropriate controls.

It’s not just a matter of choosing risk methodologies based on contractual or regulatory requirements, although these will play a part, but of selecting these based on the needs of the organisation itself, which means identifying acceptable and unacceptable risks that are aligned to the risk appetite of the business.

There are a number of ways in which risk management can be misapplied. Firstly, it should fit the organisation and this means going beyond identifying risks to having a clear understanding of the goals and priorities of the business. Why? Because this sees risk management enabling the business to meet its goals without breaking either compliance commitments or risk appetite.

Risk As A Business Tool

We also need to understand what matters to the organisation in terms of the information it needs to collect, process, store and share to help it meet these business goals and priorities. This approach then allows risk management to become integral to business decision making to the point where it becomes instinctive. Once specific risk criteria are implemented some business decisions can then rely on these repeatable “canned” mitigations allowing delegated risk decisions which increase agility in the marketplace.

Another key sticking point is how risk is communicated and acted upon. It’s vital to support those at the coalface, so those charged with the responsibility for managing information risk within the organisation must have the right skills and support to be effective. As part and parcel of this, they also need access to sufficient information from every corner of the business, with input from the right people at the right time. This includes SME’s (technical/data protection specialists/vendors etc) to ensure that an accurate picture of information risk can be formed and clearly articulated.

How that risk intelligence is shared is absolutely critical to mitigating that risk. If those responsible for the provision of resources don’t understand the level of risk involved, they can’t make timely, informed and objective risk management decisions, so the risk must be translated.

Avoid ‘risk speak’

For example, risk is often analysed using matrixes and metrics leading to a Red Amber Green (RAG) assessment or perceived risk number ie 42. Although effective when visualising or triaging risk, senior management need this information to be translated into business terms. This can be achieved by stating what the impact of a risk occurring would mean against an agreed set of parameters, such as loss of business, reputational damage, financial impact or punitive measures such as penalties.

Likelihood can be a bit of a moving feast. The impact, whether it is deemed highly unlikely or very likely, will still be realised if the event happens so the risk decisions must be cognisant of this.

Ownership of risk decisions should also be documented and reviewed at planned intervals and also where specific triggers are met. These might include a change in the direction of the business, a heightened risk environment or a re-evaluation following a security incident or other external influences.

Refining Risk

Risk management isn’t a onetime process and will require revaluation and fine-tuning. It must evolve to ensure that any systems used to collect, process or store information have appropriate risk mitigation controls applied throughout their lifespan. We have all heard of the horror stories around IT being disposed of without data sanitisation! Often this can be down to a lack of funding regarding secure disposal or reuse of old IT systems.

Finally, risk management needs to be adaptive to the climate in which it is used and to the evolution of risks or emergence of new ones. We’ve seen countless examples of this over the past few years, from businesses adapting to meet the risks posed by the Internet of Things to those posed by working remotely during the pandemic.

Risk is therefore not static but neither does it need to be restrictive. Done correctly, it can bring about continuous improvement and ultimately leads to gains or growth within the business.

David Adams is a Security Consultant at Prism Infosec

You Might Also Read: 

Four Questions To Ask After An Attack:

 

« How Long Does It Take Before An Attack Is Detected?
Is It Time To Consolidate Systems? »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

CERT.GOV.AZ

CERT.GOV.AZ

Azerbaijan Government Computer Incident Response Team

Coro Cybersecurity

Coro Cybersecurity

Coro (formerly Coronet) empowers organizations to protect against malware, ransomware, phishing, and botnets - across devices, users, and cloud applications.

cPacket Networks

cPacket Networks

cPacket’s distributed intelligence enables network operators to proactively identify imminent issues before they negatively impact end-users.

Riskified

Riskified

Riskified is a leading eCommerce fraud-prevention company, trusted by hundreds of global brands – from luxury fashion houses and retail chains, to gift card and ticket marketplaces.

Silverskin Information Security

Silverskin Information Security

Silverskin is a cyber attack company that specializes in having knowledge of the attacker's mindset to identify vulnerabilities and build effective and persistent defences.

Cyber Craft

Cyber Craft

CyberCraft is an innovative and dynamic software development, outsourcing and consulting company. Services offered include penetration testing.

Trustless Computing Association (TCA)

Trustless Computing Association (TCA)

TCA is is a non-profit organization promoting the creation and wide availability of IT and AI technologies that are radically more secure and accountable than today’s state of the art.

Blaze Information Security

Blaze Information Security

Blaze Information Security is a privately held, independent information security firm born from years of combined experience and international presence.

Authomize

Authomize

Authomize aggregates identities and authorization mechanisms from any applications around your hybrid environment into one unified platform so you can easily and rapidly manage and secure all users.

Cohesity

Cohesity

Cohesity radically simplifies the way businesses back up, manage, protect, and extract value from their data—in the data center, at the edge, and in the cloud.

LTIMindtree

LTIMindtree

LTIMindtree is a new kind of technology consulting firm. We help businesses transform – from core to experience – to thrive in the marketplace of the future.

Guidepost Solutions

Guidepost Solutions

Guidepost Solutions are a diverse, global team of investigators, experienced security and technology consultants, and compliance and monitoring experts.

Identity Digital

Identity Digital

Identity Digital simplifies and connects a fragmented online world with domain names and related technologies that allow people and businesses to build, market and own their digital identities.

CYMAR

CYMAR

CYMAR The “CYBER” Smart Solution to offer sustainability and bring resilience to Global SMART Terminals and protect the supply chain of the World’s economy.

CentriVault

CentriVault

CentriVault is a leading independent provider of Cyber Security and Data protection services to small and medium enterprises (SMEs).

IS4IT Kritis

IS4IT Kritis

IS4IT is your partner for the successful planning, introduction and implementation of company-specific information security concepts.