CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentHard

A manufacturing company is assessing the risk of a cyber-attack disrupting its production line. The risk management team uses a qualitative risk matrix, where 'likelihood' is rated from 1 (rare) to 5 (almost certain) and 'impact' is rated from 1 (insignificant) to 5 (catastrophic). A specific scenario, 'Ransomware Attack on Production Control Systems', is assessed as having a likelihood of 4 and an impact of 5. The company's risk appetite states that any risk with a total score (likelihood × impact) above 15 is unacceptable. What is the MOST appropriate immediate action for this risk?

  1. AImplement additional controls to reduce either likelihood or impact.
  2. BDocument the risk and monitor it closely.
  3. CTransfer the risk through a specialized cyber insurance policy.
  4. DSeek formal acceptance from senior management.
Show answer & explanation

Correct answer: A. Implement additional controls to reduce either likelihood or impact.

The risk score is 4 (likelihood) × 5 (impact) = 20. Since 20 is above the company's risk appetite of 15, this risk is unacceptable. The MOST appropriate immediate action for an unacceptable risk is to implement additional controls to reduce it (mitigation) to bring it within the acceptable threshold. While transfer (D) is a valid response, mitigation is often the first line of defense for critical operational risks.

Why the other options are wrong

  • B. Monitoring is insufficient for an unacceptable risk.
  • C. Transferring the risk via insurance is a valid response, but mitigation is generally prioritized for critical operational risks to prevent the event from occurring if possible.
  • D. Formal acceptance is for *residual* risks that are still above appetite but deemed necessary to operate, not for initial unacceptable risks where mitigation is still possible.

Risk Appetite Threshold

The level of risk that an organization is willing to accept in pursuit of its objectives, often expressed as a limit or range for specific risk metrics.

  • Defines acceptable and unacceptable risk levels.
  • Guides risk treatment decisions.
  • Should be formally approved by senior management.

Memory trick: If risk is 'Unacceptable', 'Act' to 'Reduce' it, don't just 'Accept'.

More IT Risk Assessment questions