CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard

During a quarterly risk committee meeting, the CISO presents a report indicating that the organization's residual risk for ransomware attacks remains high, despite implementing endpoint detection and response (EDR) solutions and regular backups. The committee asks for a strategy to further reduce this residual risk to an acceptable level. Which of the following strategies would be MOST appropriate for addressing high residual risk?

  1. AAccept the high residual risk, as some risks are unavoidable.
  2. BAvoid all systems and data that are susceptible to ransomware attacks.
  3. CTransfer the residual risk by purchasing a comprehensive cyber insurance policy.
  4. DRe-evaluate the effectiveness of existing controls and identify gaps.
Show answer & explanation

Correct answer: D. Re-evaluate the effectiveness of existing controls and identify gaps.

When residual risk remains high despite existing controls, the most prudent and foundational step is to first re-evaluate *why* the controls aren't achieving the desired reduction. This involves identifying gaps, control failures, or new threats, which then informs further mitigation actions.

Why the other options are wrong

  • A. Accepting high residual risk without further action is generally not appropriate for significant threats like ransomware, especially if it exceeds the organization's risk appetite.
  • B. Avoiding all susceptible systems/data is often impractical and could severely impact business operations, especially for a prevalent threat like ransomware.
  • C. Transferring risk via insurance is a valid strategy, but it's often more effective after mitigation efforts have reduced the risk to a lower, insurable level. It doesn't address the underlying control weaknesses.

Residual Risk Response

Actions taken to manage risks that remain after initial risk mitigation efforts have been implemented.

  • Can involve further mitigation, transfer, or acceptance.
  • Requires continuous monitoring and reassessment.
  • Aims to bring risk within acceptable levels.

Memory trick: Rethink, Re-evaluate, Respond (RRR).

More Risk Response and Reporting questions