Many organisations have a risk analysis. Fewer have a risk analysis anyone takes decisions from. The difference only shows when money is being allocated, when a supplier is being chosen or when the leadership has to answer how large the exposure actually is. At that point a matrix in yellow and red is not enough, because a colour cannot be weighed against an investment.
The chapter opens with what a risk is in an information security context, and why threat, vulnerability and consequence have to be kept apart for the analysis to be useful. Collapse them together and the result is a feeling rather than an assessment. From there the chapter moves to how risks are identified without the work becoming an endless inventory, how they are valued and where the limit runs for what a qualitative judgement can carry. Quantification is treated as a tool with clear uses rather than an end in itself, and with an honest picture of what the precision is worth. Then comes treatment, the choice between reducing, transferring, avoiding or accepting, and the often overlooked question of who actually has the mandate to accept a risk. One section works through the most common pitfalls of risk analysis, and another deals with the assets organisations routinely forget. The final part covers the gap analysis, which sets the requirements of the Cybersecurity Act against the current state and becomes the plan the rest of the work follows. The strategy cannot be built before that picture exists, which is why this chapter connects to chapter 13 on the management system.
The question sharpened when the Cybersecurity Act entered into force. Risk management is one of the ten requirement areas, and the leadership has to be able to show that the analysis has been done and that it is used, not merely that it exists. In a review it is the documentation that is examined, and a risk register untouched for eighteen months says more about the organisation than any maturity index.
This page shows what the chapter covers and why the question is decisive. The method, the templates and the full examples are in chapter 14 of the book.
Risk that carries no price does not exist in the decisions the organisation takes. Risk that is invisible cannot be managed.
Key insights
- Risk that carries no price rarely competes for budget, because it cannot be weighed against any other decision.
- A qualitative analysis is fine for getting started but becomes a dead end once amounts have to be justified.
- The gap analysis is not an audit but planning material, and it should set the order of the work.
- A risk register is either living or worthless. One updated once a year describes an organisation that no longer exists.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Template collection
The risk register in appendix A.4, ready to fill in.
Control mapping
ISO 27001 against the requirement areas of the Cybersecurity Act, the basis for the gap analysis.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.