At its core, cybersecurity is the process of identifying and managing risk. One of the biggest mistakes many business owners make is believing that their organization is too small to face serious risks. In reality, every business, regardless of size, will encounter various risks throughout its lifespan. Some organizations face more risks than others depending on factors such as size, industry, operational complexity, and the value of their assets. Risks originate from many sources, but within the context of this framework, we are primarily concerned with cyber risk. This document provides an overview of how organizations can conduct cybersecurity risk assessments and develop a cyber risk management strategy.

Risk management is an entire discipline in its own right and could warrant a dedicated framework alongside this one. Before conducting risk assessments and establishing risk management capabilities, organizations should become familiar with several key risk-related terms:

  • Asset = Any resource or collection of resources that the organization values, including intangible assets such as reputation, brand image, and intellectual property.
  • Vulnerability = A weakness within an organization's assets, systems, processes, or controls that could be exploited.
  • Severity = An assessment of the importance of remediating a vulnerability based on its potential impact.
  • Exposure = A condition or circumstance within the organization that increases the likelihood or impact of a threat event.
  • Threat = Any circumstance or event that could compromise organizational assets by exploiting a vulnerability.
  • Threat Vector = The path or means by which an attack or attacker can gain access to a target in order to cause harm
  • Threat Event = A specific occurrence of a threat.
  • Threat Source = Any person, process, system, or event capable of exploiting a vulnerability, either intentionally or unintentionally.
  • Threat Scenario = A sequence of related threat events associated with a particular threat source.
  • Exploit = The specific technique or method used to take advantage of a vulnerability.
  • Payload = The action, code, or malicious activity delivered after a successful exploit.
  • Risk = The potential for a threat to exploit a vulnerability and cause harm to the organization. Risk is calculated using the formula: Risk = Likelihood x Impact
  • Likelihood = The probability that a threat will exploit a vulnerability.
  • Impact = The adverse effect on the organization if a threat successfully exploits a vulnerability.
  • Adversary = A threat source with confirmed or presumed malicious intent.
  • Tactics, Techniques, and Procedures (TTPs) = The methods and behaviors employed by adversaries to carry out attacks.
  • Threat Shifting = An adversary's adaptation of tactics and techniques in response to implemented safeguards or changing objectives.
  • Safeguard/Countermeasure = A control implemented to reduce the likelihood or impact of risk.

Risk management is the process of identifying, analyzing, prioritizing, and mitigating organizational risks. This process involves establishing the organization's risk posture and risk appetite, conducting risk assessments, analyzing findings, reporting results to senior management, prioritizing risks based on severity, and selecting appropriate risk responses to bring overall risk levels within the organization's risk tolerance.

Within cybersecurity, risk management is commonly referred to as Information Risk Management (IRM) or Cyber Risk Management.

At first glance, risk management may appear complex, which is why risk management frameworks exist to provide structure and guidance. The NIST Risk Management Framework (NIST RMF), described in NIST SP 800-37, is one of the most widely recognized frameworks for managing cybersecurity risk. The NIST RMF organizes risk management activities into the following steps:

  1. Prepare – Conduct activities necessary to prepare the organization to manage security and privacy risks.
  2. Categorize – Categorize systems and information based on an impact analysis.
  3. Select – Select appropriate NIST SP 800-53 security controls based on identified risks.
  4. Implement – Implement the selected controls and document their deployment.
  5. Assess – Determine whether controls are implemented correctly, operating as intended, and producing the desired results.
  6. Authorize – A senior official makes a risk-based decision regarding system operation.
  7. Monitor – Continuously monitor controls and risks throughout the system lifecycle.

You may notice that many of the steps within the NIST RMF align closely with the overall process of developing an information security program. This overlap exists because cybersecurity is fundamentally a specialized area of risk management.

Within information risk management, organizations should begin by establishing a structured approach for conducting risk assessments and acting on their findings. The first step is defining a scope. For an initial assessment of the organization's cybersecurity posture, all digital assets should be included within scope. This encompasses networks, servers, workstations, mobile devices, data repositories, cloud resources, IoT devices, and operational technology systems.

As the organization's risk management capabilities mature, more focused assessments may be conducted on specific technology areas, such as server infrastructure, network devices, cloud environments, or critical applications. However, organizations should conduct comprehensive enterprise-wide cybersecurity risk assessments at least annually and prior to implementing significant changes to the technology environment.

Once a scope has been established, the organization should define roles and responsibilities for risk management activities. Because this framework focuses on information risk management, cybersecurity risk assessments should be performed by qualified IT and cybersecurity personnel. The specific assignment of responsibilities will vary depending on organizational size and structure.

Risk assessments are often collaborative efforts due to the large number of assets, systems, and processes that require evaluation. However, the overall process should be overseen by a designated leader, such as an IT Manager, Information Security Manager, or Chief Information Security Officer (CISO). A formal process should also exist for communicating risk assessment results to executive leadership and the board of directors.

Perhaps the most important aspect of risk management is establishing the organization's risk appetite. Risk appetite refers to the types and amount of risk an organization is willing to accept in pursuit of its objectives. Risk appetite is typically established by the board of directors, senior management, and other key stakeholders.

An organization's risk appetite is influenced by numerous factors, including financial resources, regulatory obligations, customer expectations, and operational constraints. The defined risk appetite will significantly influence the direction of the information security program because cybersecurity decisions must be made within its boundaries.

Closely related to risk appetite is risk tolerance, which represents the acceptable variation from desired outcomes and the level of risk the organization is willing to accept in pursuit of specific objectives. Together, risk appetite and risk tolerance guide decision-making regarding cybersecurity investments, control implementation, and risk response activities.

Once the overall risk management structure has been defined, the organization must determine how risk assessments will be conducted. Three primary approaches to risk assessment are commonly recognized: quantitative, qualitative, and hybrid.

A quantitative risk assessment assigns numerical values to risks, often using probability estimates and projected financial impacts.

A qualitative risk assessment evaluates risks using descriptive categories such as Low, Moderate, High, or Critical rather than precise numerical measurements.

A hybrid risk assessment combines elements of both approaches, such as assigning severity rankings while incorporating numerical estimates where appropriate.

Hybrid assessments are among the most commonly used approaches because they balance practicality with analytical depth. Organizations that are new to cybersecurity risk management may find qualitative assessments easier to implement initially and can incorporate quantitative techniques as their capabilities mature.

The risk management strategy should conclude with formal procedures for analyzing assessment results and communicating findings to key stakeholders. Determining the severity of identified risks often requires reference to the Business Impact Analysis (BIA), which identifies the organization's most critical assets and business processes.

A variety of reporting methods can be used to communicate findings to senior management, including dashboards, heat maps, scorecards, and executive summaries. IT and cybersecurity teams should make extensive use of visualizations to help non-technical stakeholders understand risk levels and priorities.

In addition to visual reporting, organizations should maintain formal written risk assessment reports that serve as an authoritative record of assessment findings. Key stakeholders should review these findings and collaborate with technical personnel to determine which risks require prioritization.

Once risks have been prioritized, stakeholders and technical teams can work together to select appropriate risk responses and corresponding controls. Identified risks are often documented within a risk register, a centralized repository that records risks, risk owners, mitigation activities, and current risk status.

At this stage, the risk management process transitions into the implementation of controls and countermeasures, which are addressed in Stage 3 of the CyberLadder Framework.

Once these steps have been completed, a organization has formed the basics on an Enterprise Risk Management (ERM) program. The structure should be formalized within a Risk Management Policy (RMP). This policy serves as the governing document that guides all personnel involved in risk management activities.

The Risk Management Policy should define:

• Scope of information risk assessments
• Roles and responsibilities for risk assessments
• Organizational risk appetite as approved by senior management and the board of directors
• Selected risk assessment methodology (quantitative, qualitative, or hybrid)
• Methods for analyzing and reporting risks
• Communication channels for distributing risk reports to key stakeholders

Subsequent documentation within this stage of the CyberLadder Framework will explore risk assessments, risk reporting, risk response selection, and risk register management in greater detail.