GRC & Compliance for Critical Infrastructure

Risk Treatment: Mitigate, Transfer, Accept, Avoid

Back to program
Risk Treatment: Mitigate, Transfer, Accept, Avoid
Identifying a risk is only half the job. Every risk in a mature program eventually needs a treatment decision, and there are really only four honest options: mitigate it, transfer it, accept it, or avoid it. Programs that only ever choose "mitigate" usually end up with a backlog of controls that never gets finished, because not every risk deserves the same level of investment. Mitigation means reducing likelihood or impact through a control -- network segmentation, monitoring, hardened configuration, MFA on remote access, and so on. This is the default instinct for most engineers, but it is not always the right call, especially when the cost of the control exceeds the realistic cost of the risk it is reducing. Transfer means shifting the financial consequence elsewhere, most commonly through cyber insurance or contractual liability with a vendor or integrator. Transfer does not reduce the likelihood of an incident and it rarely helps with safety or availability consequences, which is exactly why it is a poor primary strategy for OT risk and a reasonable secondary strategy for residual financial exposure. Accept means a named, authorized owner formally decides the risk is within tolerance and signs off on leaving it as-is -- ideally with a documented rationale and a review date. Acceptance without a named owner and a documented rationale is not risk management, it is just risk ignoring. Avoid means removing the risk entirely by not doing the thing that creates it -- decommissioning an unnecessary remote access path, retiring an unsupported legacy system, or redesigning a process so the exposure no longer exists. Avoidance is often the cheapest long-term option and the most underused, because it requires operational change rather than a technical purchase.
Reading 6 minutes
Lesson Reflection