Lesson 1 of 4
What a risk actually is
A cause, an event and a consequence — not a one-word category.
13 min 3-question quiz 3 guides to read next
On this page
Most risk registers fail at the first column. "Phishing" is not a risk; it is a topic. Nobody can own it, score it or decide anything about it.
Write a sentence
A risk has three parts: a cause, an event and a consequence.
An employee enters credentials on a phishing page (cause), an attacker signs in to the finance system and initiates payments (event), costing up to £250,000 before detection and requiring disclosure to our bank (consequence).
Written this way, several things fall out immediately: the controls that matter, who owns it, what evidence would tell you the likelihood, and what the organisation would actually lose.
Separate the layers
Teams routinely mix three different things in one register: threats (what might happen), vulnerabilities (why it could) and risks (the consequence to the organisation). Keep them apart. "Unpatched internet-facing VPN" is a vulnerability; the risk is what happens through it, and the same vulnerability may feed several risks.
Keep the register small
Fifty live risks is a programme leadership can engage with. Five hundred is a filing system that nobody reads. Aggregate the detail — individual vulnerabilities belong in a remediation backlog, not the risk register.
Start from assets, briefly
You cannot assess risk to things you have not listed. But a six-month asset discovery project before any risk work is a way of never doing risk work. List what matters most — the systems that hold the data, move the money or run the product — and start there.
The test of a good entry
Show it to the person who would have to fund the fix. If they can tell you whether they care, it is written well. If they ask "what does that mean for us?", rewrite it.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Risk Registers That Stay Useful
Recording risk so decisions get made, rather than producing a spreadsheet nobody reads.
2 min read
-
Threat Modelling AI Applications
A structured way to identify how an AI system could be attacked or misused before building defences.
1 min read
-
Building a Secure AI Programme
How organisations can organise AI security: ownership, inventory, policy, controls and continuous improvement.
1 min read