top of page

Risk Management is not only about Reducing Risk

  • Phil Venables
  • Oct 20, 2019
  • 2 min read

It seems most risk and security programs, and instruction on how to run risk and security programs, focus exclusively on assessing risk, to then implement controls or take other actions to reduce that risk.


Once the risk is at an acceptable level the focus is to keep it like that - but essentially do nothing more - except for a periodic or trigger based revisiting of the assessment. However, a big part of the more successful risk & security programs is to never stop there. In fact, achieving the right risk level is merely the very beginning of a more worthwhile journey that improves the way that risks are mitigated. In other words, keep risk flat but improve the efficiency of the controls that mitigate the risk - across multiple dimensions:


  1. Customer experience. Deliver the same risk level but improve the usability of controls - including reducing friction for the customer to sign-up for services or new features. This typically applies in relation to authentication, authorization and fraud prevention.

  2. Cost. Reduce the cost to sustain or upgrade controls and to direct those savings to other improvements - or to other risks where there is still a need to more actively implement new controls to reduce risk.

  3. Efficiency. Optimize the arrangement of controls, or indeed reduce the number of controls implemented for each specific risk, being careful not to impact defense in depth.

  4. Ease of continuous monitoring. Replace controls that are not amenable to continuous performance monitoring, or that don’t emit the right metrics, with ones that do.

  5. Automation. Replace any manual activities progressively with automation to reduce the administrative or other maintenance load.

  6. Adjacent benefits. Develop adjacent benefits for existing controls such as having security logging capture and synthesize more data to assist with performance monitoring, or enhance distributed recovery to not only improve resilience but to increase change windows.

  7. Reduced negative externalities. Enhance controls to reduce impact on other risks, such as improving any trade-offs made between security, resilience and/or performance.

Bottom line : A true mark of a commercially-oriented security program is to be perpetually optimizing control performance even after risk has been reduced to the right levels.

Recent Posts

See All
Organizational Politics & The Security Program

I first wrote the original of this post over 4 years ago. Having seen a new spurt of discussion about organization politics in various on-line and in-person forums I thought it was time for an update.

 
 
Cybersecurity’s Need for Speed & Where To Find It

As we talked about in the last post , a world going through a massive AI-driven transition means speed becomes vital. This is the speed of adapting to change and the speed of dealing with a world of t

 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
Subscribe for updates.

Thanks for submitting!

© 2020 Philip Venables. 

bottom of page