Back to Blog
Cybersecurity
September 20, 2022

Risk Counts for Cyber — and Here Is Why

Risk is one of those standard terms in cybersecurity that many struggle to define. Understanding how to quantify, prioritize, and mitigate risk is the foundation of any effective security strategy.

Originally published on LevelBlue

Risk is one of those standard terms within cybersecurity that, when asked to define, many struggle to explain. To start, we need to understand risk as it applies to security. Risk, like mathematics, is an artificial construct that humans use to understand and describe their environment.

Defining Risk

In a fundamental sense, risk can be defined as the likelihood of an adverse event occurring and the impact should that event be realized. A simple calculation to express this is:

R = f(P × I)

Where P is the probability of the event and I is the impact, often expressed in monetary terms.

Example: A house worth $100,000 with a 1% annual probability of total loss yields an Annualized Loss Expectancy (ALE) of $1,000 per year — the basis for an insurance premium.

Prioritizing Risk: Meteorites vs. Car Accidents

Consider two risks: being struck by a meteorite (approximately one fatality every nine years globally) versus dying in a car accident (roughly 35,000 deaths annually in the US). If you can only choose one control — a titanium helmet or a seatbelt — the math is clear. Wearing the seatbelt mitigates the far greater risk.

This same logic applies directly to cybersecurity. All organizations face infinite risks but have finite budgets. The question is: how does a company most effectively allocate resources to address the greatest risks?

Applying Risk Analysis to Cybersecurity

A risk-based approach allows organizations to quickly identify and prioritize threats based on factors such as:

  • Type of data being protected (PII, intellectual property, NPI, etc.)
  • Industry in which the organization operates (national defense, retail, healthcare, etc.)
  • Technologies employed and their associated exposure surface

The Four Risk Mitigation Strategies

Many companies rely solely on cyber insurance as their risk mitigation strategy — a dangerously incomplete approach. A comprehensive risk management program should consider all four strategies:

  1. Risk Reduction/Control — Implementing technical and procedural controls
  2. Risk Transference — Shifting risk to a third party (e.g., cyber insurance)
  3. Risk Acceptance — Accepting de minimis risks not worth the cost of mitigation
  4. Risk Avoidance — Eliminating the activity or exposure that creates the risk

Conclusion

Choosing only one risk mitigation strategy without considering the others does not allow for a comprehensive risk management posture. By applying a risk-based approach to security, organizations can most efficiently and effectively address threats — getting the greatest return on every security dollar spent.