Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 5 of 15
Introducing the cyber security risk management toolbox

Every organisation is different and so are the risk management challenges they face. This means that organisations will need to use different risk management tools, methods, and approaches to help them deal with their different risk management challenges. There are many approaches, methods and tools that could be included in your organisation’s cyber security risk management toolbox, but no one tool, method or approach will provide the information and perspectives needed to manage all cyber security risk effectively.
Different approaches may be needed to address well-known, complex, or novel technology and risk management challenges - or to provide you with different perspectives on the risks you face. We therefore recommend that organisations use a mix of techniques and variety of risk information to give an appropriately wide and varied view of cyber security risk.
It is important that you understand the benefits and limitations of the choices you make. Ultimately, if the method you are using does not help you to understand what needs to be protected, why and how, then you should seek an alternative approach.
Your choice of tools, methods and approaches will also likely be influenced by business constraints such as finances, resources, and risk management skills available to you, and perhaps by the need to maintain consistency with those used by your partner organisations or those commonly used in your sector.
Some tools, methods and approaches are free and are relatively easy to use, whilst others require subscription, extensive training and supporting governance structures, and so choosing the tools that are right for you and your risk challenge is crucial.
Do we need a formal approach to manage cyber risk ?
Before we start thinking about the tools, methods and approaches that might be in our cyber security risk management toolbox, it is worth stating that there are situations where there might be little or nothing to gain from the conduct of cyber security risk assessment and analysis. These situations might include:
- Those where you face well-known and well-understood problems, where known to be good architecture or risk treatment patterns can be followed and applied.
- Those where risk assessments have already been carried out to support the security baselines you have, or intend to implement, such as the Small Business Guide or Cyber Essentials
- Or where certain customers, sector or business specific regulations require you to apply controls or sets of controls to be compliant with contracts and regulations.
You should only apply additional risk assessment and analysis tools, methods and approaches to areas where you feel that your risk management challenge has moved beyond the scope of any predefined scheme or control sets, and where risk management gaps or deficiencies might exist.
What might be in a cyber security risk management toolbox ?
When developing your risk management toolbox it is important to remember that this doesn’t mean you need to stop using or throw away anything that you already use. If the approaches, methods, and tools you currently use effectively address your cyber security risk challenges and meet your organisation’s need, then you should continue to use them and let them form the foundation of your risk management toolbox. But consider complementing these with new or alternative approaches, methods, and tools to improve your perspective and understanding of cyber security risk.
The following list is intended to propose some tools, methods, and approaches that any organisation may consider adding to their risk management toolbox, whether they are starting from scratch or building upon some existing ones. This list is not intended to be prioritised, exhaustive or complete in any way and organisations will need to make choices about what they use based on the risk management challenges they face, and the resources they have available to them.
Further information on each of the areas covered here can be seen by following the links provided:
- Risk management Information. To at the best possible perspective on risk then a variety of risk management information is needed.
- Cyber security risk quantification Cyber security risk analysis and assessment is predominantly carried out using qualitative approaches. A complementary approach may be to use quantitative methods where appropriate and where they are useful.
- Risk assessment approaches. Thinking about the cyber security risk management challenge from different perspectives helps provide the best possible information to inform decision making. Systemic approaches are different from component approaches, and each provides a different perspective on risk.
- Component driven approaches. These are the most used risk assessment approaches for understanding and managing cyber risk. These analyse the cyber security risks faced by individual system components and are best applied at points in a system’s life cycle, in operation or while in design and development, where its component parts and the relationships between them are well understood.
- Systemic approaches. These approaches provide a systemic perspective of risk and can be used before a system’s exact physical design has been decided upon, such as in the concept phase of a system design. These systems-driven approaches can help you to identify risks which emerge from the interactions between a system’s components and may be useful when interactions between a system’s components are especially complex or less well-understood (such as when a new element is introduced into a previously well-understood system). This type of approach can also help you to bring together different types of risk assessment, such as cyber security and safety risk in cyber-physical systems.
- Assurance should be continually sought from the controls (whether these are procedural, personnel, physical or technical) you apply to treat cyber security risks. Gaining this confidence in your risk treatments (through the effective use of assurance activities) is therefore essential for managing cyber risks.
Complementary tools and methods
There are numerous complementary tools, methods and techniques that can help you understand and manage cyber security risks. A number are covered below but you should seek to expand your toolbox as you see fit, adopting those approaches and techniques that work for you.
- Attack trees can be used to explore the chain of events that might lead to a successful attack and can help you develop an understanding of the feasibility of a range of potential attacks on your system. Attack trees can be used effectively in agile environments as the trees can be built alongside iterative development, allowing you to discover and address security risks alongside development.
- Threat modelling involves the use of a number of different techniques, tools and methods in ways that can help you better understand the technical threats you face in terms of how a system or service you are building or using might be attacked and how to manage the risk posed by those attacks.
- Cyber security scenarios can help you to understand the cyber security risk challenge or challenges you might be facing, and develop your responses to a cyber security incident, in readiness for if and when one occurs.
Note
The above approaches, methods, tools and techniques are not mutually exclusive and so can be used to complement each other at different stages of a system’s life cycle, or to gain different perspectives on the cyber security risks you face, how they might be realised and how you might go about managing them.


