Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 2 of 15
The fundamentals and basics of cyber risk

This section focuses on the fundamentals of risk management. Here, we won’t be talking about standards or policies, or even anything directly to do with cyber security. Rather, we'll be introducing some fundamental principles of risk management, which are relevant whether you’re studying disease outbreaks, the rise and fall of stock markets, or the risks of a cyber attack.
Why risk management matters
Risk management exists to help us to create plans for the future in a deliberate, responsible and ethical manner. This requires risk managers to explore what could go right or wrong in an organisation, a project, a programme or a service, and recognising that we can never fully know the future as we try to improve our prospects. Risk management is about analysing our options and their future consequences, and presenting that information in an understandable, usable form to improve decision making.
Risk can't be abolished
The starting point of risk management is accepting that risk can’t simply be abolished. Risk must be recognised and then managed in some way; classically to either avoid, accept, treat or transfer risk.
Risk Management often requires a relationship between people who analyse risks and the people who make decisions based on that analysis. Communication between these two groups must be clear, understandable and useful. If the people who make decisions can't interpret the analysis they're presented with, then there is little point in doing risk analysis at all.
How different management techniques will define 'risk'
As we will discuss in more detail later, risk can be defined in different ways. For example BS ISO/IEC 27005:2022 defines a risk as being the “effect of uncertainty on objectives”. However, there are a range of different techniques that can be used to analyse risks.
Therefore the precise meaning of the term 'risk' will change depending on what technique you are applying to a given problem. For this reason, it is important not to be wedded to one strict definition, as you might disregard - unnecessarily - those techniques which are not consistent with that definition.
Some cyber risk management techniques define risk as a combination of threat, vulnerability and impact. Others define risk in terms of high-level outcomes to achieve or avoid. You might need to be able to use both, so don't limit yourself unnecessarily.
Managing the undefinable
Go to any risk management conference, and you will hear the following complaint:
We have no clear definition of risk. How on earth can we manage something that we haven't defined?
It's a fair point. If we can’t agree on a definition, how can we really know what everybody else means when they talk about 'risk'?
We see this lack of an agreed definition as an essential driver for good risk management. The fact that organisations won’t necessarily know exactly how everyone defines ‘risk’ forces us to explain to each other what we mean. It makes us ask questions and challenge assumptions. This is the fundamental strength of risk management; it provides a way of talking about the future, the outcomes we care about, and how to work to towards them.
Of course, it may be worthwhile for individual organisations to define what they mean by risk (for the benefit of their supply chains, for example). After all, risks are often analysed from the perspective of organisations, so it is sensible to develop a local definition which is agreed by anyone working on behalf of that organisation.
Uncertainty is an important part of risk
The purpose of risk management is to enable us to make the best possible decisions, based on our analysis of future events and outcomes. The future can be anticipated, but within limits defined by our uncertainty in our analysis.
Risk is a part of everything we do. You not only ‘take risks’ that you are aware of, but you also ‘run risks’ that you’re unaware of all the time. This introduces an important point about risk; because of this uncertainty, it is impossible to know and understand all of the risks that any person, organisation or network is running at any one time. You will always run risks that you are not aware of.
There are some overly bold standards and frameworks out there which claim you will 'know all your risks' if you follow a certain set of procedures diligently and comprehensively. That’s a false and dangerous notion. Instead you should approach risk management with a sense of realism and pragmatism. Breaches of cyber security can and do happen to anyone, even the most diligent.
The purpose of risk management is not to chase the unattainable goal of perfectly secure systems and a risk-free business. Rather, it is to make sure that you have thought about what can go wrong, and that this thinking has influenced your organisation's decisions.
Don't be fatalistic; you can still protect yourself from many cyber attacks, but if something does go wrong, it isn't always the case that someone is to blame, or that your risk manager missed something.
Compliance ≠ risk management
'Improving outcomes' isn’t always the primary driver for carrying out risk management. Often, organisations conduct risk management exercises for 'compliance' reasons, which could include:
- obligations from external pressures (such as regulatory requirements)
- customers' demands
- legal constraints
When done for these reasons, there is a danger of risk management becoming a tick-box exercise. This can lead to organisations believing they have managed a risk, when in reality they have merely complied with a process which may have (albeit unintended) negative consequences.
Compliance and security are not the same thing.
They may overlap, but compliance with common security standards can coexist with, and mask, very weak security practices.
Risk management performed for compliance reasons is sometimes described as ‘defensive risk management’. Risk management that's done in this way can cause an excessive focus on protecting the organisation’s reputation (or to protect it from being sued, fined or subject to similar external sanctions). Defensive risk management is about being able to show that you haven't been negligent should something bad happen. The emphasis is on proving that something has been done.
This is not necessarily a bad thing. In many industries, compliance requirements are unavoidable. However, if you are conducting defensive risk management, make sure that:
- staff understand that cyber risk management goals will be to meet external demands (rather than addressing specific security objectives)
- you are aware of the limitations of the risk management techniques that you apply in order to be compliant
- you adopt further techniques that address the limitations of compliance (some of the categories of technique presented in this guidance can help you do this)
The risks in compliance
The goals of a compliance-focused team can become misaligned with the organisation's wider goals. When this separation occurs, the compliance-focused team can develop an unrealistic view of what the rest of the organisation does, leading to poor decisions. The NCSC's advice here is for organisations to be clear and honest about why they conduct cyber risk management. If this is for compliance reasons, lay out a plan for how you propose to prevent some of the behaviours outlined above.
It may sound counter-intuitive, but managing the risks inherent in 'compliance' are just as important as managing any other risk.
A word (or two, or three or more) about cyber risk
This section we are setting out some very basic concepts about cyber security risk, and exposes some myths that have some traction in the cyber community which can lead to some unintended outcomes. This section represents the NCSC's take on cyber risk, but there are other ways of approaching risk, as discussed in the introduction. You are free to use those approaches and definitions if you assess they better suit your business.
Definitions of risk
There are several definitions of risk. The NCSC is a part of GCHQ and a government agency and as such we should first look to the Treasury Orange Book which defines a risk in this way:
Risk is the effect of uncertainty on objectives. Risk is usually expressed in terms of causes, potential events, and their consequences:
- A cause is an element which alone or in combination has the potential to give rise to risk;
- An event is an occurrence or change of a set of circumstances and can be something that is expected which does not happen or something that is not expected which does happen. Events can have multiple causes and consequences and can affect multiple objectives;
- the consequences should the event happen – consequences are the outcome of an event affecting objectives, which can be certain or uncertain, can have positive or negative direct or indirect effects on objectives, can be expressed qualitatively or quantitatively, and can escalate through cascading and cumulative effects.
Certainly, HMG readers of this guidance should familiarise themselves with the Orange Book and the Principles and Concepts set out there, because cyber risk must always be set within the context of the wider business risk.
However, there are simpler definitions which the NCSC also like to use like this, from the Oxford English Dictionary:
(Exposure to) the possibility of loss, injury, or other adverse or welcome circumstance; a chance or situation involving such a possibility.
And from the Cambridge Advanced Learner’s Dictionary the pithy:
The possibility of something bad happening.
In NCSC we tend to look to the latter definition for cyber risk. That is, we are absolutely concerned with the possibility of something bad happening.
But we also look to that Orange Book definition because there are elements to cyber risk that we need to define and understand if we are to assess, analyse and address them. However, the words we use to break down cyber risk are a quite different from the Orange Book definitions of risk and we’ll talk about that next.
The key takeaway here is that for cyber risk the NCSC is concerned with the possibility of something bad happening.
The components of cyber risk
The NCSC describe and think of the components of cyber risk as follows:
Threats are individuals or organisations that could cause something bad to happen. Quite often these are referred to as threat actors; whereas hazards are events (usually but not always natural events) that could cause something bad to happen. The key difference is that a threat will intend to cause something bad to happen, whereas a hazard is an event that happens and causes harm.
Threats should be considered in the context of four components: capability, intent, motivation and opportunity. Intent and motivation are often interchanged, but this is incorrect as they are two different things, and each will have bearing on how the threat should be assessed.
Capability
Capability is the skills, techniques and resources that the threat actor might bring to bear and will vary from extremely capable threat actors (who will have high-end skills and techniques and huge resources at their disposal) to low capability threat actors who will attempt to use cyber tools that are freely available on the internet. Constraints should be considered when assessing capability as some threat actors will act without constraint unfettered by the proportionality, ethical or legal constraints of their actions, whilst others will operate within clearly defined legal, ethical and proportionality limitations (which will mean that they will not necessarily use their full capabilities depending on the target).
Intent
This is what the threat actor intends to achieve. This might vary from simple theft of information through to causing actual physical damage to cyber-physical systems such as an iron foundry, and any and all points in between.
Motivation
This is what motivates a threat actor to undertake a cyber attack. A low-end threat actor might be seeing how far they can enter an IT system without any intent to cause harm. Whereas cyber criminals will want to make money and may not care who their intended victims are, or the wider impact their actions might have. Then there are state threat actors, who may wish to gain or deny strategic advantage, or make a geopolitical statement through their actions.
Opportunity
This is the opportunity a threat actor has to undertake a cyber attack. This opportunity is usually provided by the relationship and accesses a threat actor has to a technology system or service. For example someone who works in an organisation as a system administrator would have a much greater opportunity to attack that organisation than (for example) a cleaner who works at the organisation and has no authorised access to systems. Opportunity can also be provided to threats via vulnerabilities; for example a misconfigured cloud based storage system might provide an attacker with the opportunity to read, change and or delete the information stored within it.
The possibility or chance that something bad will happen. There are many approaches to assessing likelihood and these will be addressed elsewhere in the risk management guidance portfolio.
This is any weakness in a system that can be exploited by a threat actor, or can be affected by a hazard. These vulnerabilities do not have to be technical in nature (such as software, hardware and firmware). They can also be weaknesses in procedures, in physical and environmental security, and in personnel security.
Security Controls are technical and non-technical measures that are put in place to mitigate identified risks. They broadly fall into four categories: procedural, physical, personnel and technical control (sometimes known as P3T). Most security mitigation approaches will include a mix of all four types of control. These are methods to treat a risk.
Procedural security
Procedural security is the provision of security controls that seek to mitigate or treat identified risks by way of policies, procedures, processes, or guidelines.
Physical security
Physical security is the provision of controls that seek to mitigate or treat identified risks through the physical protection of assets such as buildings, facilities, IT equipment, personnel etc.
Personnel security
Personnel security is measures put in place to mitigate or treat risks from authorised users of cyber systems. These measures could include vetting, training and threat awareness campaigns.
Technical security
Technical security is measures built into the cyber system to mitigate or treat identified risks. These controls might for example include firewalls, secure configuration, access controls, anti-malware software, and software updates and patching. Essentially these are controls that are designed into the cyber system to address cyber security risks.
This is the impact to the business, the ‘something bad happening’ we are trying to avoid. Traditionally this has been centred on information and the properties of confidentiality, integrity, and availability. This is sometimes referred to the as C/I/A triad. Whilst this remains a useful definition when considering information security impacts, we need to remember that cyber security is not just about the security of information. The ‘something bad happening’ could be the cyber system becoming unusable, unreliable, or unsafe, or cyber event leading to a loss of money, or loss of a contract, or reputation or even to the business failing.
Note: constraining the definition of business impact solely to information and properties of confidentiality, integrity and availability is a limiting approach. It's important to note that the NCSC's guidance is designed for use on all cyber systems (including operational technologies or for online services), and not just those where risk to information is the primary concern.
Risk appetites are how we define the risk red lines associated with business or operational opportunities. This could include for example, what an organisation, project, operation or system owner is absolutely unwilling to accept risk on, such as fulfilling its legal/regulatory obligations to the protection of personal information, or continued plant operations. These risk red lines must be communicated to those who need to work with them, in a way that is accessible and understood. More information on risk appetites (including how to define and communicate them) is available at Are you hungry? A two-part blog about risk appetites.
Whilst there is no 'one size fits all' approach to risk assessment that will work for all organisations, most formal and informal approaches to risk assessment cover the same kind of ground. A good high level overview of the ground covered by a risk assessment is provided by Jack Jones of the FAIR institute at Risk Analysis vs. Risk Assessment: What's the Difference? (fairinstitute.org) where he sets out the things that a typical risk assessment process will include:
- identification of the issues (threat/hazard, likelihood, vulnerability) that contribute to risk
- analysing the potential business impacts presented by the risks
- identifying options for treating, transferring, avoiding or accepting the risks presented
- determining which options are the best approach for your business
- communicating results and recommendations to decision makers within the business


