Risk transfer
Also known as: risk sharing
Moving the financial cost of a risk to another party, usually through insurance or a contract with a supplier.
Draft - this entry has not been reviewed yet.
Formal
The risk treatment option in which some or all of the consequences of a risk are shared with or passed to a third party - for example through cyber insurance or contract terms with a supplier - while accountability for the risk stays with the organisation.
In plain English
Like hiring a removal firm that pays if it drops your piano - you get the money back, but you still have no piano for the party on Saturday.
In practice
A Danish online furniture shop takes out cyber insurance that pays for outside experts and lost income after an attack, and its contract makes the hosting provider cover losses from the provider's own outages.
Why it matters
Money can be moved, but the lost trust, the lost data and the legal duties cannot - an insured organisation must still report breaches and answer to its customers.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Identify the residual risks that remain after reasonable controls and have low likelihood but high impact, since these are the ones worth transferring.
- Estimate the financial loss of the worst credible scenarios, such as several days of downtime or a large data breach, to size policy limits and retentions.
- Document your current controls accurately before buying cyber insurance, because insurers set conditions such as MFA, EDR and offline backups and can refuse a claim on the basis of a wrong answer.
- Have legal, finance and IT read the policy together, checking sublimits, the waiting period before business interruption is covered, exclusions such as war or state-backed attacks, and the response providers you must use.
- In supplier contracts, set security requirements, liability caps and indemnities that match the harm a supplier failure could cause, not just a year's fees.
- Record in the risk register which part of each risk is transferred and which stays with you, including legal duties such as breach notification that cannot be transferred.
- Add the insurer's hotline and panel providers to the incident response plan so they are called at the start of an incident.
- Review cover and contracts at every renewal and after major changes or incidents, and update the answers you give the insurer.
Common pitfalls
- Treating insurance as a replacement for controls, when it pays only part of the money and none of the lost trust or data.
- Discovering exclusions, sublimits or waiting periods only after an incident.
- Assuming a supplier contract covers the loss when liability is capped at a small amount.
- Giving the insurer inaccurate answers about your controls, which can cost you the claim.
Good guides
- Cyber insurance guidance(opens in a new tab) · NCSC UK
- NIST SP 800-161 Rev. 1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations(opens in a new tab) · NIST
- Cybersikkerhed i leverandørforhold(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
ISO 31000:2018 and ISO/IEC 27005 call this option risk sharing, and the choice of word is deliberate: what moves is part of the financial consequence, while the likelihood of the event and the accountability for it stay where they were. The two main instruments are insurance and contract. Neither changes the probability of a breach; both change who pays for some of its consequences, and only up to the limits written into the policy or agreement.
Cyber insurance typically combines first-party cover (incident response and forensics, data restoration, business interruption after a waiting period, extortion costs where lawful) with third-party cover (liability to customers and data subjects, defence costs, sometimes regulatory proceedings). The details decide how much risk is really transferred: sublimits for particular loss types, retentions, waiting periods of several hours before business interruption applies, requirements to use the insurer's panel of breach coaches and forensic firms, and exclusions. War and state-backed attacks are the most debated exclusion. In Merck v. ACE American, a dispute over roughly 1.4 billion dollars of NotPetya losses claimed under all-risk property policies, New Jersey's Appellate Division held in May 2023 that a traditional hostile or warlike action exclusion did not apply, and the case settled in January 2024; in parallel, Lloyd's Market Bulletin Y5381 required state-backed cyber-attack exclusions in stand-alone cyber policies incepting or renewing from 31 March 2023. Underwriters also make controls such as MFA, EDR and offline backups conditions of cover, so an inaccurate application can jeopardise the claim when it matters. The insurability of regulatory fines is limited and depends on national law.
Contractual transfer uses indemnities, liability clauses and service credits with suppliers. In practice liability caps, often tied to a year's fees, and exclusions of indirect or consequential loss mean the transferred amount is usually small compared with the actual business impact of a major outage. Regulation limits what can be shifted: under GDPR Art. 82(4), where several controllers or processors are involved in the same damaging processing, each can be held liable for the entire damage towards the data subject, with recourse among them under Art. 82(5); DORA Art. 28(1) keeps financial entities fully responsible for compliance when they use ICT third-party providers; and NIS2 Art. 21(2)(d) makes supply chain security part of the entity's own obligations.
Transfer therefore complements mitigation rather than replacing it. It is best suited to low-likelihood, high-impact residual risk that remains after reasonable controls, and quantitative analysis of the loss tail is what makes it possible to choose sensible limits and retentions.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk transfer
Relationships
- A kind of
- Risk treatment
- Don't confuse with
- Risk mitigation
Sources & further reading
Standards & official texts
- ISO/IEC 27005:2022 (8.2 - Risk treatment options)
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 5 og Ordliste (Risikohåndtering - overføre)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…