WDTD | 𝗣𝗼𝘀𝘁 #𝟯𝟮𝟰
[Topic: 𝗪𝗲𝗮𝗸 𝗚𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲 𝗢𝘃𝗲𝗿 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗥𝗶𝘀𝗸 𝗔𝗰𝗰𝗲𝗽𝘁𝗮𝗻𝗰𝗲 — 𝗪𝗵𝗲𝗻 𝗔𝗰𝗰𝗲𝗽𝘁𝗲𝗱 𝗥𝗶𝘀𝗸 𝗕𝗲𝗰𝗼𝗺𝗲𝘀 𝗜𝗻𝘃𝗶𝘀𝗶𝗯𝗹𝗲 𝗥𝗶𝘀𝗸]
𝗤𝘂𝗶𝗰𝗸 𝗜𝗻𝘀𝗶𝗴𝗵𝘁:
Organizations formally accept risks — vulnerabilities, exceptions, compensating controls — as part of business operations.
But over time, accepted risks are often 𝗻𝗼𝘁 𝘁𝗿𝗮𝗰𝗸𝗲𝗱, 𝗿𝗲𝘃𝗶𝘀𝗶𝘁𝗲𝗱, 𝗼𝗿 𝗿𝗲-𝗲𝘃𝗮𝗹𝘂𝗮𝘁𝗲𝗱, turning them into 𝗶𝗻𝘃𝗶𝘀𝗶𝗯𝗹𝗲 𝗮𝗻𝗱 𝘂𝗻𝗺𝗮𝗻𝗮𝗴𝗲𝗱 𝗲𝘅𝗽𝗼𝘀𝘂𝗿𝗲.
Risk acceptance is not risk elimination — it is 𝗿𝗶𝘀𝗸 𝗼𝘄𝗻𝗲𝗿𝘀𝗵𝗶𝗽.
Common risk acceptance governance risks include:
- Accepted risks not 𝘁𝗿𝗮𝗰𝗸𝗲𝗱 𝗶𝗻 𝗮 𝗰𝗲𝗻𝘁𝗿𝗮𝗹 𝗿𝗲𝗴𝗶𝘀𝘁𝗿𝘆 🕳️
- No expiration or review cycle for accepted risks ⚠️
- Business justification becoming outdated over time 🔑
- Compensating controls not implemented or validated
- Security teams unaware of previously accepted risks
- Accumulation of accepted risks increasing overall exposure
⚠️ If accepted risks are not actively managed, they silently accumulate until they become systemic vulnerabilities.
𝗔𝘂𝗱𝗶𝘁 𝗧𝗶𝗽:
📋 During risk management and governance audits, validate:
- All accepted risks are 𝗰𝗲𝗻𝘁𝗿𝗮𝗹𝗹𝘆 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁𝗲𝗱 𝗮𝗻𝗱 𝘁𝗿𝗮𝗰𝗸𝗲𝗱
- Each risk has a 𝗱𝗲𝗳𝗶𝗻𝗲𝗱 𝗼𝘄𝗻𝗲𝗿, 𝗷𝘂𝘀𝘁𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻, 𝗮𝗻𝗱 𝗲𝘅𝗽𝗶𝗿𝗮𝘁𝗶𝗼𝗻 𝗱𝗮𝘁𝗲
- Regular reviews reassess 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗶𝗺𝗽𝗮𝗰𝘁 𝗮𝗻𝗱 𝘁𝗵𝗿𝗲𝗮𝘁 𝗹𝗮𝗻𝗱𝘀𝗰𝗮𝗽𝗲
- Compensating controls are 𝗶𝗺𝗽𝗹𝗲𝗺𝗲𝗻𝘁𝗲𝗱 𝗮𝗻𝗱 𝘃𝗲𝗿𝗶𝗳𝗶𝗲𝗱
- Expired risks trigger 𝗿𝗲-𝗲𝘃𝗮𝗹𝘂𝗮𝘁𝗶𝗼𝗻 𝗼𝗿 𝗿𝗲𝗺𝗲𝗱𝗶𝗮𝘁𝗶𝗼𝗻
- Risk acceptance is aligned with 𝗲𝗻𝘁𝗲𝗿𝗽𝗿𝗶𝘀𝗲 𝗿𝗶𝘀𝗸 𝗮𝗽𝗽𝗲𝘁𝗶𝘁𝗲
𝗔𝗰𝘁𝗶𝗼𝗻𝗮𝗯𝗹𝗲 𝗥𝗲𝗺𝗶𝗻𝗱𝗲𝗿:
Ask your risk or security governance team:
- How many risks have we formally accepted — and are they still valid?
- Are accepted risks reviewed periodically?
- Do we verify compensating controls?
- Could accumulated accepted risks create significant exposure today?
If accepted risks are not revisited, they stop being managed — and start being forgotten.
𝗥𝗶𝘀𝗸 𝗮𝗰𝗰𝗲𝗽𝘁𝗮𝗻𝗰𝗲 𝗶𝘀 𝗮 𝗱𝗲𝗰𝗶𝘀𝗶𝗼𝗻 — 𝗯𝘂𝘁 𝘄𝗶𝘁𝗵𝗼𝘂𝘁 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲, 𝗶𝘁 𝗯𝗲𝗰𝗼𝗺𝗲𝘀 𝘀𝗶𝗹𝗲𝗻𝘁 𝗿𝗶𝘀𝗸 𝗮𝗰𝗰𝘂𝗺𝘂𝗹𝗮𝘁𝗶𝗼𝗻.

Leave a Reply