top of page

The Fantastic Four.

Writer: Neil Hare-Brown
Neil Hare-Brown
Sep 2
5 min read

When it comes to optimal management of cyber risk there are only four decisions.

Over the first six papers in this series, I've argued for a different approach to cyber investment that seeks to focus thinking in the following analytical stages:


  • Start with what matters.

  • Focus on critical assets.

  • Estimate consequences rather than trying to predict every possible incident.

  • Express those consequences financially.

  • Remove information that doesn't improve the decision.


But eventually analysis has to stop. Someone has to make a decision. And when we strip away the technology, terminology and complexity surrounding cyber risk management, there are only four recognised ways to treat risk:


  1. Reduce it.

  2. Transfer it.

  3. Accept it.

  4. Avoid it.


That's it. Everything else is implementation.


Risk Reduction / Mitigation

This is where cybersecurity is most comfortable. We implement controls to reduce either the likelihood or consequences of an adverse event. Controls such as:

  • Firewalls.

  • EDR.

  • MFA.

  • Backups.

  • Network segmentation.

  • Vulnerability management.

  • Security awareness.

  • Incident response capability.


The list can be extensive. All controls can be entirely appropriate. However, the problem begins when implementing controls becomes the objective rather than a means to an end.


The important question isn't, "Should we implement this control?". It is, "How much risk are we trying to reduce, and is this an appropriate investment for achieving that reduction?"


That subtle change in language moves the discussion from technology to economics. Controls cost money and resources are finite. Every pound invested in one control is unavailable for another control - or indeed another business investment. Risk reduction is therefore an investment decision.


Risk Transfer

Not every risk needs to be reduced and it may not make financial sense to manage it in this way. Some risks can be transferred.


Cyber insurance is the obvious example, but it isn't the only one. Contracts can allocate liability. Suppliers can assume particular obligations. Indemnities can transfer defined financial consequences. Even outsourcing arrangements can alter where particular risks ultimately sit.


Risk transfer is interesting because it behaves differently from mitigation. A firewall may change the likelihood of an incident occurring. An insurance policy generally doesn't but if an insured organisation suffers a £10 million cyber loss, the incident still happened and the economic loss still exists.


What changes is who ultimately bears some of the financial consequence. That distinction really matters. Few organisations are able to absorb the losses of serious cyber incidents on their balance sheet.


Cyber insurance and cybersecurity controls are therefore not competing products. They are different mechanisms for treating the same underlying financial risk. Which leads to a question I think Boards should ask much more frequently:

How much of our cyber risk should we spend money reducing, and how much should we spend money transferring?


That is a capital-allocation question. And I'm not convinced most organisations can currently answer it objectively.


Risk Acceptance

Acceptance is perhaps the most misunderstood of the four treatments. However, it is also the "zombie" option where many organisations - especially those who do not manage risk as I am describing here, are blindly adopting this treatment method without even giving it a thought.


Too often, "accept the risk" sounds like Do nothing. It shouldn't. Proper risk acceptance is an active, informed decision. Management is effectively saying:

We understand the plausible loss within these bounds and have determined that the entity can absorb it.

That is very different from ignoring a risk.


Imagine a critical asset for which a plausible adverse event could create a loss between £100,000 and £250,000. An organisation with substantial financial resources may reasonably determine that spending £500,000 to reduce that exposure makes little economic sense. Acceptance may be the rational decision.


Another entity might be unable to absorb even the lower end of the same loss range. For it, acceptance would be inappropriate. The risk hasn't changed but the capacity to absorb it has.


That is why risk appetite cannot sensibly be discussed independently of financial consequence.


Risk Avoidance

The fourth option is often the most straightforward. Don't take the risk. Stop the activity. Remove the service. Withdraw from the market. Eliminate the dependency. Don't hold the data. Don't implement the technology.


Risk avoidance can sound defeatist in cybersecurity because our instinct is usually to find a control. Sometimes, however, the economically rational decision is simply not to expose the entity to the risk in the first place.


If an activity creates £10 million of plausible financial exposure but only £100,000 of business value, the most sophisticated security architecture in the world may be answering the wrong question. Perhaps the better question is, Why are we doing this at all?


Four Treatments. One Decision.

The four treatments are usually taught as separate options. I think it is more useful to view them together.


Imagine that we have quantified the plausible financial consequences of a cyber incident affecting a critical asset. Management can now ask the following:


  • How much should we reduce?

  • How much should we transfer?

  • How much can we accept?

  • And is there anything we should avoid altogether?


That is risk management. It is not eliminating uncertainty. It is not buying every available security control.

or transferring everything to an insurer.


But it is deliberately determining what combination of treatments leaves the entity within practical, sustainable bounds.


Controls Bound the Future

There is an engineering principle underneath this way of thinking that I've become increasingly interested in:

Effective controls bound the future within practical limits.

A control doesn't guarantee that an incident won't happen. For instance, a backup doesn't guarantee there will never be an outage, MFA doesn't guarantee credentials will never be compromised and a firewall doesn't guarantee that an Internet-facing application cannot be attacked.


However, effective controls do something more realistic. They constrain the range of plausible outcomes.

They help make an uncertain future more manageable.


Risk transfer can perform a related function economically. It may not change the incident itself, but it can constrain the financial consequences retained by the entity.


Risk acceptance then asks whether what remains - sometimes referred to as residual risk, is absorbable.


And risk avoidance removes the exposure altogether. However, it is rare for business leaders to find themselves in a position where they would use such a method.


I think this relationship between the fantastic four risk treatment methods deserves considerably more attention, particularly around how mitigation and transfer interact. But even at a practical level, it provides a useful way of thinking about cyber investment.


The Budget Should Follow the Risk

This brings us back to the question that started this series:


How much cybersecurity is enough?


Perhaps we've been approaching the budget from the wrong direction. Instead of beginning with:

"We have £5 million to spend. What cybersecurity should we buy?", perhaps we should begin with:

"We have quantified financial exposure across the critical assets that matter to this business. How should we treat it?"


Only then do we ask what investment is required. Perhaps some goes towards mitigation, some towards transfer and some risk is [hopefully] consciously accepted. In those rare cases, some activities may even be avoided.


This approach would give the cybersecurity budget a rationale. And, importantly, the cyber insurance budget can be better justified too.


They are no longer separate conversations. They are components of the same risk-management decision.


From Individual Assets to the Portfolio

In considering this approach there is one complication. Controls rarely protect only one critical asset.

A firewall may protect dozens. EDR may protect hundreds and identity controls may protect almost everything. Likewise, one cyber insurance policy may transfer elements of financial risk across the entire organisation.


That means we cannot optimise investment by looking at critical assets entirely in isolation. Eventually, we have to look across them. And when we do, something interesting happens. Cyber risk management begins to look remarkably like portfolio management.


That is where I'll go in the next article.


Thought for the week

"Risk management is not about eliminating uncertainty. It is about making an informed decision about what to reduce, transfer, accept and avoid."

 
 

Speak with a cybersecurity specialist

Contact the team at STORM Guidance:

UK/Europe: +44-203-693-7480

Africa: +230-434-1277

India: 0008001004277

USA: +1-703-232-9015

Your contact details will only be used in connection with this enquiry.

Please read our Privacy Policy.

I'm enquiring as
bottom of page