We who live risk management know there are four responses when confronted with a credible risk to our organizations. We can treat the risk to reduce it. We can avoid the risk by altering our organization’s behavior. We can transfer the risk with insurance or outsourcing, though the transfer is rarely complete. Lastly, we can accept risk and hope for the best.
Let’s get this out of the way first: no security professional wants to accept risk. If we had our way, the organization would mitigate or avoid all risks. But that’s almost never the case in the real world. Risks often must be accepted. This can be due to unpatchable security vulnerabilities or expensive remediation requirements.
Read the full article published November 23, 2018 here: https://www.helpnetsecurity.com/2018/11/23/dont-accept-risk/ by Help Net Security.