Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 3 of 15
Cyber security risk management framework

On this page
- A framework for managing cyber security risk
- Step 1 - Establish organisational context
- Step 2 - Identify decision makers, governance processes and constraints
- Step 3 - Define your cyber security risk challenge
- Step 4 - Select your approach
- Step 5 - Understand risks and how to manage them
- Step 6 - Communicate and consult
- Step 7 - Implement and assure
- Step 8 - Monitor and review
Help understanding what a good approach to risk management looks like, and what approaches to cyber security risk management are right for your organisation.
A framework for managing cyber security risk
This section sets out a series of high-level steps that could form the basis of any cyber security risk management process. Whilst the steps shown here reflect the processes described in ISO/IEC 27005:2018, similar processes or steps will most likely be found in many other cyber security risk management standards, guides, processes and approaches.
These steps will help you understand what a good approach to risk management looks like and help you to decide what approaches to cyber security risk management are right for your organisation.
For those who are new to cyber security risk management and don’t know how to get started with topics such as risk assessment, then we also provide a basic cyber risk method approach.
Step 1 - Establish organisational context
The first step in any cyber security risk management process is to understand the business context within which cyber security risks will be managed. Cyber security risk management should not make achieving your organisation's objectives hard, rather it must enable them. Establishing the organisational and business context will help you to discover and understand what your organisation really does, what it values and what its concerns might be, even before you think about identifying and managing cyber security risk.
You should not create this view by yourself. Rather you should be drawing upon existing organisational knowledge. This may be in the form of a mission statement, enterprise level risk information, or you may talk to appropriate stakeholders in the business. This could be at organisation, programme or project level depending on your particular circumstances. Techniques such as whiteboarding, brainstorming, PESTLE and SWOT analyses may be useful here, in groups or with individuals, to help you establish this context.
Considerations:
- What is your organisation's mission, purpose, goals and priorities?
- What does your business care about, what must be protected and what outcomes can not be tolerated?
- What are the key and critical areas of your business?
- What are the key questions your decision makers want your risk management work to address?
- Are there any external factors such as legal, statutory, regulatory, compliance or contractual requirements that you need to meet?
Step 2 - Identify decision makers, governance processes and constraints
This step is about working out how cyber security risk management will be controlled and directed within your organisation. You should think ‘organisation wide’ to avoid silo-based thinking. Cyber security risk decision making should align with your management of other business risks. The risk owner or decision maker shouldn’t sit within the cyber function alone as decisions about cyber security risk management are business decisions. For example, if you are a larger organisation, it should be the responsibility of the whole Board, and not left to a single person.
To do this, you will need to gain clarity about who your decision makers are, what level of the business they work at, and their authority in terms of risk ownership, responsibility and accountability. Perhaps you don’t report directly to the Board, and your context may be a programme or project. Understanding the process of delegation and escalation for decision making in your particular situation is therefore crucial. Ideally, all cyber security risk management activities should be approved by someone with decision-making authority, and be linked to a decision they have to make. It is therefore important that decision makers have access to cyber security risk management experts and that those experts can effectively communicate risk management information and issues as required.
You will also need to understand your decision makers' constraints (such as budget, resources and time) as well as other organisational factors such as the procurement and development processes you follow (for example, waterfall or agile). Your cyber security risk management activities should align with your organisation's risk appetite and match the rhythm and tempo of your wider business practice to meet project deadlines; if your inputs are late, they will be meaningless.
Considerations:
- Is there an existing risk management governance and decision making process and structure in place within your organisation, and how does it work?
- Does your organisation have a stated appetite for taking cyber security risks?
- Who is responsible and accountable for making cyber security risk management decisions, what are their needs and constraints, and how is that responsibility delegated down in a large or complex organisation?
- How will you escalate a cyber security risk management decision if you don’t know what to do?
- How do you intend to integrate cyber security risk into your organisation's wider objectives and risks?
- Who are your risk, system, service and asset owners, and what cyber security risk management roles already exist?
- How do you manage situations over which you may not have full control, such as in a third party, cloud service or supply chain context? Who is responsible and accountable for making decisions in this regard, and how is cyber security risk management responsibility shared?
- What is your security budget?
Step 3 - Define your cyber security risk challenge
Think carefully, and initially at a high level, about the key characteristics that define your cyber security risk challenge. We are using the term ‘challenge’, but you may think about it as the cyber security risk problem or issue that you are planning to apply risk analysis to. It is important to think about the scope and nature of your challenge before jumping into particular cyber security risk assessment tools. Understanding these key characteristics will help you to decide on the appropriate approach or mix of approaches to take in Step 4.
Considerations:
- How complex is the challenge? Is it a standard, well defined and well understood challenge? Can you apply a solution that is known to effectively address your challenge? If this is the case then is there a need to carry out any further assessment or analysis? Is it something novel or complex that might require a different approach?
- Is the challenge in design, or operation? If it is in design, what is your development practice and tempo (such as waterfall or agile)?
- Does cyber security risk significantly impact on other areas of risk? For example, for cyber-physical systems, do you need to bring together cyber security risk assessment with safety risk assessments?
- Are there elements that may be outside of your direct control but are still part of your risk picture, such as your supply chain, use of third party or cloud services? How much can you rely on their underlying risk assessments, and what do you need to do to fulfil your responsibilities?
- Are you in a heightened threat environment? Are there circumstances that are relevant to your organisation and would affect your understanding of the threat environment? For example, are you a supplier to government, are you about to launch a new product, or have you been more visible in the media recently? These factors may be relevant when thinking about your threat environment.
- Could there be unpalatable low frequency, but high impact events? What time frames are relevant to your cyber security risk management? In the short term you may have greater certainty about your risks, but in the longer term you may need to deal with a greater degree of uncertainty, both in relation to your system and the wider environment.
- Are you constrained by some of the technologies you use, for example Operational Technology (OT), ICS/SCADA or legacy products?
Step 4 - Select your approach
There are many approaches, methods, and tools in the cyber risk management toolbox that can be used to help assess and manage cyber security risk. No one size fits all, and no one tool will solve every problem. Each has its own strengths and weaknesses depending on what you are assessing. Your choice of approach should therefore be tailored to the key characteristics of the risk challenge you have identified. It is worth having a mix of approaches in your own toolbox of capabilities so that you can choose the most appropriate tool for your particular risk challenge.
Your approach may also be influenced by business constraints, such as the finances and resources available as well as the need to maintain consistency internally and with other risk domains, or externally with your business partners or regulators. Some of the techniques described in our cyber risk management toolbox are free and are relatively easy to use, whilst others may require subscription, extensive training and supporting governance structures.
Considerations:
- Do the key characteristics you identified in Step 3 lead you to a particular tool or technique?
- Does your current approach or a baseline meet the needs of your risk challenge?
- What constraints do you need to consider when choosing a tool?
- Does your chosen method help you to understand what needs to be protected and how? If not, what other approaches do you need?
- Do you have the right skills to use a particular tool, method, technique or approach? Or do you need to bring in specialist resource to help you?
- How well does your chosen approach (in its language, process and outputs) fit with other approaches used for risk management in your organisation?
Step 5 - Understand risks and how to manage them
This step is about using cyber risk management toolbox approaches, techniques and tools to identify and assess cyber security risks, so that you can prioritise them, and make decisions about how you are actually going to manage them. It is important that you seek to manage all the cyber security risks you identify. For those who are new to cyber risk management and don’t know where to start a basic risk assessment is also provided, but you should note that this basic method comes with some serious health warnings.
This step will involve the analysis and prioritisation of risks and making decisions about how you are going manage them. You could choose to manage a cyber security risk by:
This means not pursuing or stopping the activity that led to a risk existing. This is sometimes referred to as ‘terminating’ a risk.
This means making an informed decision to do nothing (or nothing further) to treat, mitigate, modify or reduce an identified risk (either as a raw untreated risk or as a residual risk that remains after some treatment has occurred). Accepting a risk means that, if it is realised, you will have to live with the resulting impact and consequences. These decisions can be made because the cost of treating a risk might outweigh the cost of any impact that might be realised, or because the risk is tolerable in the context of an organisation's appetite for taking risk in pursuit of its objectives and priorities. This is sometimes referred to as ‘tolerating' or ‘retaining’ a risk.
This means transferring the impact or consequence of a risk being realised to someone else (for example through insurance). This can sometimes be referred to as ‘sharing a risk’.
This involves the implementation, management and maintenance of technical and non-technical controls that are aimed at either reducing the likelihood of a cyber security risk occurring, or at reducing the impact if one does occur (with the aim of making a cyber security risk acceptable or tolerable in the context of an organisation’s risk appetite). This can sometimes be referred to as taking action to ‘modify', ‘mitigate’ or ‘reduce’ a risk.
If you have chosen to manage the risks you have identified by treating them using technical or non-technical controls, then it is important that you and those who own cyber security risks within your organisation are confident that those controls will work as you expect them to, and that they will continue to do so throughout the life of the system or service you are using. This confidence is known as ‘security assurance’, ‘technical assurance’ or simply ‘assurance’.
You will need to describe and communicate how you will gain assurance (and maintain it for the controls you recommend) when you present your recommendations to decision makers. For further information refer to the section on how to gain and maintain assurance for your risk treatments.
It is not possible to completely eliminate or treat all risk. When you treat cyber security risks using controls there will always be a risk or a number of risks that are left over, and these are referred to as 'residual risks'. These residual risks themselves also need to be managed.
The amount of risk analysis carried out needs to be proportionate to the risk challenge you are facing, and if your approach is not providing you with information that helps you identify and manage cyber security risks, then you should stop and consider whether you have done enough, or whether you need to try something else to elicit further information.
The cyber security risk management recommendations you make should be delivered to the appropriate decision makers, at the right time and in the right format. In all cases the risks you assess and recommendations you make should be traceable to what the business is doing and cares about. Your recommendations should be feasible and fit with your decision maker’s constraints, but it should also be clear to them what risks they would continue to take, in other words what residual risk would be left over, if they were to accept your recommendations. These and the other analyses and decisions you have made should be appropriately documented to maintain traceability. These documents might include:
- a risk register: this communicates and prioritises risks that have been identified to decision makers and other stakeholders
- a cyber security risk management plan: this sets out how cyber security risks will be managed and describes those controls that will be implemented to treat identified risks
- an assurance plan: this sets out how assurance in the controls used to treat identified risks will be gained and maintained throughout the whole life of a system or service
- a statement of residual risk: this identifies, for decision makers, the risks that are left over after you have treated identified risks, so that they can make informed decisions about how they should be managed
You should be able to justify and defend your recommendations. Any claims you make, or information you provide should be supported by good arguments and evidence. You should understand that controls are only useful when they are addressing identified risks. If your technique does not enable you to do this, then you should consider taking and alternative approach.
Considerations:
- Make the most effective use of different sources of data and information.
- Quantitative information and approaches may be useful in developing cost-benefit analyses to inform decisions about potential controls.
- Be conscious of the limited utility of statements and labels like ‘high’, ‘medium’ or ‘low’ without setting them within a meaningful technology and/or business context. Your understanding of high may not be the same as your audience.
- Be aware of the potential influence of unconscious bias which may skew some of the inputs on which you base your analysis.
Step 6 - Communicate and consult
The next step is to communicate your findings and recommendations to the appropriate decision maker or group of decision makers within your business. Your communications need to be meaningful, and be appropriate to the audience in terms of the level of detail and format used. If, for example, you need to or choose to use standard labels such as high, medium and low, make sure that you have expressed their meaning clearly to both those who apply those labels and those who will be making decisions based on them. Effective two-way communications (face to face and written) are required to build credibility with all interested parties and for effective decision making. The use of overly technical and cyber security jargon where it is not appropriate to the audience or context can result in miscommunication and confusion.
Considerations:
- Consult with cyber security risk management decision makers and other governance stakeholders so that you better understand their needs for risk management information, so that will help them make informed and timely decisions.
- Be concise and tailor recommendations to the audience: distil large amounts of complex risk information into meaningful updates.
- You should be able to trace every risk you identify back to some high level organisational risk or loss. Make sure your language and presentation is impactful and understandable for your decision-maker and addresses what they really care about. Using non-technical and non-security language to achieve this can be very helpful.
- Consider how you present risks in terms of priority, focusing attention on the most critical risks and recommendations, but ensure that all risks are captured and considered.
- The language and risk statements you use should be consistent with existing practices across your business. If everyone else is using labels to describe risks and their components, then you should do the same but remember to contextualise and describe carefully any labels you use to ensure everyone understands what they mean.
Step 7 - Implement and assure
This step is about implementing the recommendations that you have made (and your decision maker has agreed to), and about gaining and maintaining confidence that the controls and measures you apply work, and continue to work, effectively and as expected.
The aim here is to ensure that cyber security has been included in the system or service you are dealing with from the outset and is secure by design. As a risk practitioner, you may not be directly responsible for this activity. For this reason, it is important you ensure that those with responsibility for implementation understand the risks they are addressing, and the recommendations you have made for managing them. This concerns the ‘through-life’ management of those controls as well as management of residual risk. It is often easy to rush or neglect this step, but you should devote as much time and effort to these activities as you do to the earlier steps in the framework.
The systems we use today for business and personal use are sociotechnical in nature, meaning that they involve people, technology, and business processes. The delivery and maintenance of these systems can also involve complicated supply chains. Cyber security risks can affect any of these things and you therefore need to ensure that cyber security controls have been appropriately and effectively implemented as necessary across all of these aspects.
Cyber security controls and measures should be applied to systems in layers. This approach is sometimes referred to as ‘defence in depth’, whereby the failure or compromise of a single control or measure will not result in an attacker gaining immediate and complete access to something we care about. To do that, they would need to overcome or compromise more than one control or measure.
In some cases, for instance when using cloud services, the responsibility for implementing cyber security controls may be shared with a third-party service provider. You should note that whilst responsibility for the implementation of a control may be shared with a third party, the responsibility and accountability for a risk (and the way it is being managed) remains with you and your organisation.
Whether you are implementing security controls and measures, applying security to your supply chain, or defining a shared security model with a third party supplier, you and the risk owners within your organisation should seek confidence (or assurance) that the controls and measures you are using will work as you expect them to (and that they will continue to do so for as long as you need them to).
For example:
- you could seek assurance in the people that use, manage and maintain your systems and services by requiring that they have the training and skills they need to do their jobs securely
- you could seek assurance in the technology and processes you use by for example ensuring that they have been designed and built with security in mind, independently assessing them against standards, carrying out security testing on them prior to their deployment and whilst in operation, and by monitoring and auditing how they are used
The NCSC website contains detailed information about products and services, assured by the NCSC that protect your organisation and reassure your customers that you take cyber security seriously.
Good cyber security risk management is a continuous activity, so you cannot rely on implementation decisions forever. You will need to constantly consider whether the cyber security controls and assurance arrangements you have in place remain relevant in the context of the cyber security threats and risks you face.
Considerations:
- Consider the financial and resource implications of potential controls and whether they meet PACE principles (pragmatic, appropriate and cost effective). They should also align with your risk appetite, business goals and stated risks.
- Use a mix of risk management options as appropriate (ie not all risks need to be managed by treating them with controls, it may be possible to avoid, transfer or accept them).
- Seek to achieve defence in depth and use a range of controls to address people, business processes, physical and technology; avoid focusing solely on technology and put people at the heart of your thinking.
- Consider how to make best use any existing controls already in place, and make best use of the security features that are built in to products, systems and services (but might not enabled by default or they could be easily adapted to address identified and relevant risks).
- Ensure you manage your highest priority risks first.
- Adopting a common baseline will help you defend against the most common threats. You may refer to a common control set or framework but do not follow these blindly, only choose those controls that are relevant to your threat model and risks. You may also need to adapt or enhance a common baseline by implementing bespoke or targeted controls that manage cyber security risks that are unique to your setting or context.
- Consider building the assurance model into your processes for designing, operating and maintaining your technology systems and services to provide confidence in the ways cyber security risks are being managed.
- Check that any decisions you made about accepting or tolerating cyber security risk remain safe, and that it is possible for all those risk acceptance decisions to be seen and understood at an organisational or enterprise risk level, to inform those higher-level risk management perspectives and decisions.
- Regularly review the cyber security controls you use to ensure that they remain effective and relevant to the risks you face.
Step 8 - Monitor and review
Cyber security risk management is a continuous process and your approach needs to be regularly reviewed and adapted to deal with an ever changing threat and risk landscape. It is important to monitor and review not only the efficacy and performance of the controls you have put in place, but also your risk assessments and the cyber security risk management approach itself. Cyber security should be designed to be in place for the lifetime of the business that a system or service is supporting, not simply for the lifetime of the project/programme delivering the system or service.
Considerations:
- Regularly review your overall approach to cyber security risk management to provide your organisation with continuous assurance that it is operating effectively to meet the business need, and to identify areas where improvements might be needed or where additional and/or alternative methods or techniques may need to be added to your existing cyber security risk management toolbox.
- Don’t be afraid to roll back on or undo previous risk treatment decisions: This is because a treatment decision you made when a system or service was first implemented may not be appropriate today.
- Monitoring your system will allow you to observe if it is behaving outside your defined parameters, for example to comply with cyber security policies, and help you understand where additional interventions, measures or controls might be needed. In this way you can use monitoring as a control in its own right, for example using protective and transaction monitoring.
- Continually confirm that the controls in place are appropriate and proportionate in terms of managing cyber security risks.
- Develop metrics and performance indicators to measure the effectiveness of controls
- Revisit your risk assessments and analysis when something significant changes. This may be when there is a change in the threats you face, or when you change the technology used to deliver and manage a system or service, or the way you use a system changes significantly.
- Use a variety of mechanisms to monitor and review your systems and services, such as periodic reviews, penetration tests, security audits, IT health checks and security monitoring solutions or your own logging. These mechanisms will help you identify cyber security incidents and provide information on how well or otherwise the measures and controls you are using to manage cyber security risks are working.


