Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.2.1. Risk Treatment Options

💡 First Principle: Every risk treatment option changes who bears the consequence or how likely it is to occur — none of them make the underlying risk disappear, they only reshape it.

OptionWhat Actually HappensExample
AcceptOwner formally acknowledges and monitors the exposureLow-impact risk on a system being retired next quarter
MitigateControls reduce likelihood and/or impactDeploying MFA to reduce credential-theft likelihood
TransferFinancial impact shifts to a third partyCyber insurance policy, indemnification clause
AvoidThe risky activity itself is stoppedDiscontinuing a product feature with unacceptable exposure

Transfer is the option most often misunderstood: buying insurance moves who pays for the loss, not whether the loss — or the operational and reputational fallout of an incident — actually happens. The organization still has to respond to, contain, and recover from an incident even when insurance later reimburses part of the financial cost; the underlying operational risk was never actually removed, only its financial consequence was reshaped.

⚠️ Exam Trap: Risk transfer via insurance is sometimes treated as eliminating the risk entirely. The correct answer recognizes transfer shifts financial impact only — the operational and reputational risk, and the obligation to respond to an incident, remain with the organization.

Reflection Question: Your organization purchases cyber insurance covering the full estimated financial cost of a ransomware incident. Has the risk been eliminated? What still has to happen operationally if that ransomware incident occurs?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications