Skip to main content
Guidance

Risk management

How to understand and manage the cyber security risks for your organisation.

Page 5 of 15

Introducing the cyber security risk management toolbox

Having the right risk management techniques, tools, or methods available to deal with the cyber security challenges your organisation faces.

Every organisation is different and so are the risk management challenges they face. This means that organisations will need to use different risk management tools, methods, and approaches to help them deal with their different risk management challenges. There are many approaches, methods and tools that could be included in your organisation’s cyber security risk management toolbox, but no one tool, method or approach will provide the information and perspectives needed to manage all cyber security risk effectively.

Different approaches may be needed to address well-known, complex, or novel technology and risk management challenges - or to provide you with different perspectives on the risks you face. We therefore recommend that organisations use a mix of techniques and variety of risk information to give an appropriately wide and varied view of cyber security risk.

It is important that you understand the benefits and limitations of the choices you make. Ultimately, if the method you are using does not help you to understand what needs to be protected, why and how, then you should seek an alternative approach.

Your choice of tools, methods and approaches will also likely be influenced by business constraints such as finances, resources, and risk management skills available to you, and perhaps by the need to maintain consistency with those used by your partner organisations or those commonly used in your sector.

Some tools, methods and approaches are free and are relatively easy to use, whilst others require subscription, extensive training and supporting governance structures, and so choosing the tools that are right for you and your risk challenge is crucial.




Note

The above approaches, methods, tools and techniques are not mutually exclusive and so can be used to complement each other at different stages of a system’s life cycle, or to gain different perspectives on the cyber security risks you face, how they might be realised and how you might go about managing them.

Published

Reviewed

Version

2.0