Accepting, mitigating, or avoiding risks: how do you choose?

    Back to blog
    risicobehandeling
    iso27001
    security

    Risk Management: Accept, Mitigate or Avoid?

    In the world of quality management and information security, risk management is a crucial component of an organization's success. Making the right choices regarding risk strategies can still be quite a challenge. Should you accept, mitigate, or avoid a risk? And what does a good risk analysis look like?

    A good risk analysis helps to conduct this discussion more objectively. Not based on feelings, but on a consistent method for identifying, assessing, and addressing risks.

    In this article, we provide practical guidelines to help you make informed risk treatment choices.

    The Basic Principles of Risk Management

    To understand how to effectively manage risks, it is important to first grasp the basic principles of risk management.

    Risks are events or circumstances that, if they occur, can have a negative impact on an organization's objectives. In information security, for example, it concerns risks to the confidentiality, integrity, and availability of information. In quality management, it often relates to risks to customer satisfaction, process quality, delivery reliability, or compliance.

    Risk management involves identifying, analyzing, and responding to these risks. The three main strategies that organizations often employ are:

    • accepting risks;

    • mitigating risks;

    • avoiding risks.

    In some cases, a risk can also be transferred, for example, through insurance or contractual agreements with suppliers. Nevertheless, the organization remains responsible for making a conscious choice.

    What Does a Good Risk Analysis Procedure Look Like?

    A good risk analysis procedure not only describes that risks are assessed but, more importantly, how this is done.

    A mature procedure contains at least:

    1. The method for risk identification
      For example, interviews, workshops, process analyses, supplier assessments, incident analyses, vulnerability scans, or internal audits.

    2. The risk criteria
      The organization must determine in advance when a risk is low, medium, or high. This prevents risks from being assessed arbitrarily.

    3. The assessment of likelihood and impact
      For each risk, it is determined how likely it is that the risk will occur and what the consequences will be if it does.

    4. The risk matrix or calculation method
      For example, likelihood × impact, or a more qualitative classification into low, medium, and high.

    5. The threshold for acceptance
      The organization must document which risks are acceptable and at what level additional measures are needed.

    6. The choice for risk treatment
      For each risk, it is determined whether it will be accepted, mitigated, avoided, or transferred.

    7. The link with control measures
      The risk analysis forms the basis for the selection of control measures. You do not simply choose measures because they are in a standard, but because they fit the identified risks.

    8. Periodic re-evaluation
      Risks change. Therefore, the risk analysis must be reviewed periodically and also updated in the event of significant changes.

    Making Likelihood and Impact More Objective

    A common problem with risk analyses is that likelihood and impact are filled in subjectively.

    One employee may label a risk as "high," while another assesses the same risk as "medium." This makes the outcome unreliable.

    Therefore, it is important to define likelihood and impact as concretely as possible.

    Example of Likelihood

    Instead of:

    • low;

    • medium;

    • high.

    You should work with more concrete definitions. Here are some examples.

    • Low: the risk has never occurred and there are no clear signals that it will occur soon.

    • Medium: the risk has occurred before or there are circumstances that make its occurrence likely.

    • High: the risk occurs regularly or there are strong indications that it may occur in the near future.

    Example of Impact

    Impact can be assessed based on:

    • financial damage;

    • disruption of service;

    • reputational damage;

    • legal or contractual consequences;

    • consequences for customers;

    • consequences for confidentiality, integrity, and availability.

    Here too, it helps to define concrete boundaries.

    For example:

    • Low: limited internal disruption, no customer impact.

    • Medium: noticeable disruption for customers or temporary process downtime.

    • High: severe disruption, data breach, contract violation, legal infringement, or prolonged outage of critical services.

    The more concrete these criteria are, the better subsequent analyses will yield comparable results. Impact is also often expressed in monetary value, where, for example, Low is a risk that costs less than €1000 when it occurs, and High potentially leads to bankruptcy. It is important that the chosen criteria align with the context of the organization. A damage amount of €25,000 may be negligible for a multinational, while it represents a very significant impact for a small organization.

    Comparable Results in Subsequent Analyses

    An important requirement for a good risk analysis is that it is reproducible.

    This means that a risk analysis should not be entirely dependent on the personal opinion of the person conducting the analysis. When the same situation is reassessed later, the outcome should be broadly comparable.

    You achieve this by:

    • clear definitions for likelihood and impact;

    • pre-established acceptance criteria;

    • a consistent risk matrix;

    • justification for each score;

    • involvement of the right process owners;

    • documentation of assumptions and choices.

    This is important for audits. An auditor wants to see that risks have not been assessed arbitrarily, but according to a consistent and repeatable method.

    The Risk Analysis as the Basis for Control Measures

    A risk analysis is not an end in itself. The ultimate goal is to determine which control measures are needed to reduce risks to an acceptable level. Therefore, the risk analysis within ISO 27001 forms the basis for the selection of security measures.

    For each risk, it must be determined which treatment is most appropriate. When a risk cannot be accepted, additional control measures are chosen to reduce the likelihood or impact. The standard states that Annex A must be used to verify that no control measures have been overlooked. The result of this is processed in the Statement of Applicability. Organizations may also design additional measures that do not appear in Annex A when necessary. It is important that measures demonstrably align with the identified risks. An auditor will therefore regularly ask why a specific measure has been implemented and which risk it manages.

    In ISO 9001, the risk analysis helps to determine where process control, checks, quality measures, or improvement actions are needed.

    A common mistake is that organizations first fill in a standard list of measures and only then look at risks. The correct order is the other way around:

    1. What are our risks?

    2. Which risks are unacceptable?

    3. What measures are needed to reduce these risks?

    4. Who owns these measures?

    5. How do we check if the measures are effective?

    Accepting Risks

    Risk acceptance means choosing to accept a certain risk, usually because the costs of mitigation are higher than the potential impact of the risk itself.

    This can be a wise choice in situations where the risk is relatively small or manageable. For example, an organization may decide to accept a low risk of temporary downtime of a non-critical internal application because additional measures are more expensive than the expected damage.

    Risk acceptance must be done consciously. It should not be a disguised form of doing nothing.

    When Do You Choose Acceptance?

    You choose acceptance when:

    • the impact of the risk is low and has limited consequences for the organization;

    • the likelihood is small;

    • the costs for mitigation are higher than the potential damage;

    • there are already existing measures that sufficiently mitigate the risk;

    • the residual risk falls within the pre-established acceptance criteria.

    It is important that risk acceptance is approved by someone with sufficient authority. An employee usually cannot independently decide that a high risk is acceptable.

    Mitigating Risks

    Risk mitigation involves taking measures to reduce the likelihood of a risk occurring or to lessen its impact.

    This is the most common strategy in risk management. It may involve adjusting processes, implementing technology, performing additional checks, or training employees.

    For example, an organization may decide to provide security training, implement MFA, and conduct phishing tests to reduce the risk of account compromise.

    When Do You Choose Mitigation?

    You choose mitigation when:

    • the likelihood of the risk is significant;

    • the impact could be large;

    • the risk exceeds the acceptance threshold;

    • feasible measures are available;

    • laws or regulations require additional control;

    • customers or contracts demand certain security or quality measures.

    Mitigation does not mean that the risk disappears completely. Often, a residual risk remains. This residual risk must be reassessed and possibly formally accepted.

    Avoiding Risks

    Risk avoidance means completely stopping or not performing the activity that causes the risk.

    This is the most drastic approach, but sometimes also the most sensible.

    For example, if an organization wants to use a new technology that has not been sufficiently tested and introduces significant security risks, it may be better to postpone implementing that technology.

    When Do You Choose Avoidance?

    You choose avoidance when:

    • the risks are too great;

    • the consequences are unacceptable, regardless of the potential benefits;

    • there are no feasible mitigation measures available;

    • the activity is not essential for the organizational objectives;

    • the organization cannot meet legal, contractual, or security requirements.

    Risk avoidance can be difficult from a business perspective, as it means that an opportunity or activity is not utilized. Nevertheless, it can be a wise choice when the potential damage outweighs the expected benefits.

    Making the Choice

    When making choices about risk treatment, it is important to follow a structured approach.

    A practical method is:

    1. Identify the risks
      Make a list of potential risks that could affect the organization.

    2. Assess likelihood and impact
      Use pre-established criteria to assess risks consistently.

    3. Determine the risk level
      For example, use a risk matrix to classify risks.

    4. Compare with the acceptance criteria
      Determine whether the risk is acceptable or whether treatment is needed.

    5. Consider the treatment options
      Choose between accepting, mitigating, avoiding, or transferring.

    6. Select appropriate control measures
      Choose measures that logically align with the risk.

    7. Assign ownership
      Document who is responsible for the risk and the measure.

    8. Monitor and review
      Risks and the context in which they occur can change. Therefore, ensure periodic re-evaluation.

    Risk Owners and Residual Risks

    Point 7 from this list has not yet been discussed: A risk analysis is only effective when it is clear who is responsible for following up on a risk. Therefore, it is important to appoint a risk owner for each risk. This person is responsible for assessing the risk, initiating any control measures, and monitoring progress.

    In practice, risks rarely disappear completely. Even after measures have been implemented, a residual risk usually remains. The organization must therefore consciously determine whether this residual risk is acceptable. This decision should be made by the risk owner or another official with sufficient authority. This way, it is prevented that significant risks are accepted unnoticed without anyone taking responsibility for them. Additionally, explicitly documenting ownership creates more involvement in managing risks and realizing improvements.

    Often, this acceptance is delegated to an executive or, for example, the CISO. Although the executive ultimately remains ultimately responsible, it can be beneficial for the organization to delegate ownership elsewhere, often lower in the organization. The risk owner must have sufficient authority to enable changes in processes and procedures. Therefore, you cannot delegate this too low in the organization, but often it can be placed with middle management.

    Tools for Risk Management

    Often, an Excel sheet is used for the risk analysis. You can also use an (online) tool. A widely used tool in the Netherlands is, for example, RAVIB (available in Dutch, English, German, and French). You can also host the tool yourself. RAVIB also has a good overview of control measures linked to threats. You can find this here.

    Conclusion

    By thoroughly considering how you handle risks, you can not only improve safety and quality within your organization but also enhance the overall performance of your team and organization.

    A good risk analysis procedure ensures that risks are assessed in a consistent, repeatable, and substantiated manner. This makes it easier to make appropriate choices regarding acceptance, mitigation, or avoidance.

    The risk analysis forms the basis for the selection of control measures. Without a good risk analysis, it is difficult to explain why certain measures are necessary and others are not.

    Risk management is therefore not a paper obligation but a practical tool for making better decisions.