The four ways to handle risk
Every risk in an organization gets handled one of four ways. There is no fifth option. Learn these and you understand how security money gets spent:
- Mitigate. Lower the risk. Make it harder for the bad thing to happen. Locks on the car, MFA on the login, training for the users.
- Accept. Keep the risk and say so, in writing. You accept when the fix costs more than the problem, or when the risk is genuinely low. Acceptance should be a deliberate, documented decision, not an accident.
- Remediate. Remove the risk entirely. Patch the vulnerability, upgrade the obsolete system, eliminate the exposure. Remediation is the cleanest option when it is available.
- Transfer. Push the financial impact somewhere else. Cyber insurance is the classic example. The risk still exists, but the cost of the bad outcome lands on the insurer.
One example that teaches all four
Take phishing. The risk: someone in the company clicks a malicious email, enters their credentials, and an attacker takes over their account.
Mitigate it: put an email gateway in front of inbound mail, train users to spot phish, require MFA so a stolen password alone is not enough. The risk drops from likely to unlikely. You did not remove phishing, you made it much harder.
Accept it: you look at a tiny internal tool with two users and no sensitive data and decide the risk is fine as is. Write it down, date it, and move on. Acceptance is for small risks, not for the crown jewels.
Remediate it: you remove the thing that makes phishing dangerous. You cannot stop all email, but you can eliminate a vulnerable plugin, patch a known hole, or retire a legacy system the phish exploits. The risk is gone, not lowered.
Transfer it: you buy cyber insurance that covers business email compromise losses. If a $60,000 payment goes out the door because an attacker impersonated the CFO, the insurer makes the company whole, and the premium goes up.
Risk in numbers
Professionals do not just say high or low. They score risk, usually likelihood times impact on a defined scale. A phishing risk with a likelihood of 4 out of 5 and an impact of 4 out of 5 scores 16, which lands high on the register and demands action.
The scoring is not magic. It is informed by threat intelligence: what is actually hitting your industry right now, and how often. That is why GRC professionals read the news every day. A risk analyst who cannot say why a likelihood is a 4 instead of a 2 is guessing, and the business will feel it.
The point of all of it
Risk work exists because the business cannot protect from everything. It decides where the money goes, what gets accepted, and what gets insured. When you can walk into a meeting and say, here is the risk, here is the score, here is why, and here are the options, you have just done the most valuable thing a GRC analyst does.
Next: The final free lesson covers career paths, salaries, entry points, and the honest self-check for whether GRC fits you.