Cyber security is just another risk.
And just like any risk, you can accept it or reduce it.
How do you choose?
It’s simple:
1. You decide whether a risk is something you’re happy to live with.
2. If you’re not happy to live with it, you do things to reduce the risk to a level that you are happy with.
So what?
Congrats. you’re now a risk management expert!
Because when you are thinking about whether a risk is something you’re happy to live with, you’re really thinking about your “Risk Appetite“.
So what?
Different people have different risk appetites.
If you’ll be held accountable (e.g. by clients or regulators) if things go wrong, you probably have a very low risk appetite.
What’s my point?
Are you sure that your staff and third parties understand your low appetite for cyber security risk?
Or do their other priorities make them act like they’re at an ‘All You Can Eat’ buffet?
Where to start?
If your organisation has a Risk Management Policy: Make sure it is clear about your current risk appetite and then see how this is being reflected in the security operations / improvements on the ground – The risk register and action plans should be a good place to look.
If you’re a small organisation without such a policy: Talk to your staff and key third parties about what they are doing (or could do) to reduce the risks so they are within your risk appetite.
(PS Let me know if you need some more pointers on this.)