Skip to content
atlas

Risk treatment

Also known as: risk response

Choosing what to do about each risk - accept it, reduce it, share it with someone else, or avoid it altogether.

Draft - this entry has not been reviewed yet.

Formal

The step in risk management where each assessed risk gets one of four responses - retained as it is, reduced with controls, shared with or transferred to another party, or avoided by stopping the activity - each with an owner and a plan.

In plain English

Like facing a leaky roof - you can live with it, patch it, buy insurance, or move out.

In practice

A shipping company's board buys cyber insurance to share the cost of a ransomware attack, adds MFA to reduce the risk from stolen passwords, and accepts the small risk of an office printer failing.

Why it matters

Finding risks is pointless without a decision about each one, and that decision shows who owns it and what it costs.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Take the ranked risks from the assessment and, for each one above the acceptance level, decide with the risk owner whether to reduce, share, avoid or accept it.
  2. For risks you reduce, choose the controls needed from any source and compare them with ISO 27001 Annex A so nothing necessary is missed.
  3. Record in the Statement of Applicability which Annex A controls apply, why, and why any are excluded.
  4. Write a risk treatment plan listing each action with owner, deadline, budget and the expected residual risk.
  5. Have management approve the plan and the risk owners formally accept the residual risks, and keep the signed decision.
  6. For shared risks, check that contracts, supplier terms or cyber insurance actually cover the scenario, and note what stays with you.
  7. Implement the actions, track them in the risk register and report overdue items to management.
  8. Reassess each treated risk after implementation to confirm the control works and the residual risk matches what was expected.

Common pitfalls

  • Accepting risks by default without a named owner with authority signing off.
  • Assuming cyber insurance removes the risk, when it only covers part of the financial loss.
  • Picking controls straight from Annex A without linking them to a specific risk.
  • Never checking whether the chosen controls actually reduced the risk.

Good guides

Technical deep dive

The familiar four options are a simplification. ISO 31000:2018 clause 6.5.2 lists seven: avoiding the risk by not starting or continuing the activity; taking or increasing the risk to pursue an opportunity; removing the risk source; changing the likelihood; changing the consequences; sharing the risk, for example through contracts or insurance; and retaining the risk by informed decision. NIST SP 800-39 uses five risk responses, separating sharing from transfer, while ISO/IEC 27005 has traditionally grouped the options as modification, retention, avoidance and sharing. The options are not mutually exclusive: a typical ransomware treatment combines mitigation (MFA, segmentation, offline backups), sharing (cyber insurance for the tail) and formal retention of what is left.

ISO/IEC 27001:2022 clause 6.1.3 turns treatment into a sequence of auditable steps: a) select treatment options in light of the assessment results; b) determine all controls necessary to implement them, from any source; c) compare those controls with Annex A to verify that nothing necessary has been omitted; d) produce the Statement of Applicability with justification for inclusions and exclusions; e) formulate a risk treatment plan; and f) obtain the risk owners' approval of the plan and their acceptance of the residual risks. Clause 8.3 then requires the plan to be implemented and its results retained.

ISO 31000:2018 clause 6.5.3 describes what a treatment plan should contain: the rationale for the chosen options including expected benefits, who is accountable for approving and implementing it, the proposed actions, resources, performance measures, constraints, required reporting and monitoring, and timing. In practice this means each treated risk is linked in the register to named actions, an owner, a deadline, a budget line and the expected residual rating, so that monitoring can later compare the expected with the achieved effect.

Selection is a cost-benefit decision bounded by obligations. Legal and contractual requirements can rule options out entirely (a mandatory control cannot simply be retained away), stakeholder expectations and ethics count alongside expected-loss arithmetic, and ISO 31000 notes that treatment can introduce new risks and may not work as intended, so treatments must themselves be monitored. Treatment differs from incident response despite the similar-sounding synonym risk response: treatment decides in advance how a risk will be handled, whereas incident response deals with an event that has already occurred.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Security control
  9. →Risk assessment
  10. →Risk treatment

Relationships

Sources & further reading

Standards & official texts

  • ISO/IEC 27005:2022

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.