CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

During a quarterly risk committee meeting, the CISO presents a report indicating that the organization's residual risk related to external cyber threats has increased significantly due to newly identified zero-day vulnerabilities. The board expresses concern and asks for immediate action. What is the MOST appropriate next step for the risk committee to recommend?

  1. ARe-evaluate the existing controls and explore additional risk response options.
  2. BAccept the increased residual risk and continue current monitoring.
  3. CTransfer the entire risk to a cybersecurity insurance provider.
  4. DCommunicate the increased risk to all employees and issue a general warning.
Show answer & explanation

Correct answer: A. Re-evaluate the existing controls and explore additional risk response options.

When residual risk increases beyond acceptable levels, the most appropriate action is to re-evaluate existing controls and explore further risk response options (mitigate, transfer, avoid) to bring the risk back within acceptable parameters, rather than simply accepting it or taking an unrelated action.

Why the other options are wrong

  • B. Accepting increased significant risk without further action contradicts good risk management practice, especially when the board is concerned.
  • C. Transferring the entire risk might not be possible or cost-effective, and it's usually one of several options to explore, not the sole immediate step.
  • D. While communication is important, a general warning to employees does not address the underlying technical risk of zero-day vulnerabilities and is not a primary risk response here.

Residual Risk Response

Actions taken when the remaining risk after implementing controls (residual risk) is deemed too high, requiring further treatment.

  • Involves re-assessing and re-treating risk
  • May lead to new controls or different strategies
  • Aims to bring risk within acceptable appetite

Memory trick: Rethink, Re-plan, Respond – Don't just sit there!

More Risk Response and Reporting questions