CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy

A manufacturing company relies heavily on its operational technology (OT) systems for production. A recent risk assessment identified a high likelihood of a cyber-attack disrupting these systems, leading to significant production downtime and financial losses. The company has decided to implement a comprehensive incident response plan, including regular drills and a dedicated OT security team. Which of the following risk response types does this action MOST closely represent?

  1. ARisk Transfer
  2. BRisk Acceptance
  3. CRisk Avoidance
  4. DRisk Mitigation
Show answer & explanation

Correct answer: D. Risk Mitigation

Implementing an incident response plan and a dedicated security team are actions taken to reduce the impact and potentially the duration of a cyber-attack, thereby mitigating the overall risk to the OT systems. This is a classic example of risk mitigation.

Why the other options are wrong

  • A. Risk transfer would involve outsourcing the risk or obtaining insurance, neither of which is described here.
  • B. Risk acceptance would mean taking no action and just absorbing the consequences.
  • C. Risk avoidance would mean ceasing the use of OT systems, which is not the case.

Risk Mitigation

The process of implementing controls and strategies to reduce the likelihood or impact of a identified risk.

  • Aims to lessen the severity or frequency of a risk event.
  • Can involve a variety of controls (technical, administrative, physical).
  • Often the most common risk response strategy.

Memory trick: Mitigation makes the risk less, a plan for success.

More Risk Response and Reporting questions