3.2.1. Risk Treatment Options
💡 First Principle: Every risk treatment option changes who bears the consequence or how likely it is to occur — none of them make the underlying risk disappear, they only reshape it.
| Option | What Actually Happens | Example |
|---|---|---|
| Accept | Owner formally acknowledges and monitors the exposure | Low-impact risk on a system being retired next quarter |
| Mitigate | Controls reduce likelihood and/or impact | Deploying MFA to reduce credential-theft likelihood |
| Transfer | Financial impact shifts to a third party | Cyber insurance policy, indemnification clause |
| Avoid | The risky activity itself is stopped | Discontinuing a product feature with unacceptable exposure |
Transfer is the option most often misunderstood: buying insurance moves who pays for the loss, not whether the loss — or the operational and reputational fallout of an incident — actually happens. The organization still has to respond to, contain, and recover from an incident even when insurance later reimburses part of the financial cost; the underlying operational risk was never actually removed, only its financial consequence was reshaped.
⚠️ Exam Trap: Risk transfer via insurance is sometimes treated as eliminating the risk entirely. The correct answer recognizes transfer shifts financial impact only — the operational and reputational risk, and the obligation to respond to an incident, remain with the organization.
Reflection Question: Your organization purchases cyber insurance covering the full estimated financial cost of a ransomware incident. Has the risk been eliminated? What still has to happen operationally if that ransomware incident occurs?