Courseiva
CISMChapter 7 of 17Objective 2.3

Risk Treatment, Response, and Mitigation

What do you do after you have identified a business risk? How do you decide whether to fix it, ignore it, or buy insurance against it? These questions are the heart of risk treatment and response, and they are tested heavily on the CISM exam. This chapter will give you a decision-making framework that a real-world information security manager uses every day, explained in plain language with no IT jargon.

12 min read
Intermediate
Updated Jul 23, 2026
Reviewed by Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security

A simple way to picture Risk Treatment, Response, and Mitigation

The House Fire Insurance Analogy

Your home is made of wood and sits in a dry forest. You know there is a real, but unlikely, chance it could catch fire. You wouldn't just stand there hoping it doesn't happen; you would plan and act. This is exactly what risk treatment, response, and mitigation are for in information security.

You have a few options. You could buy a fire extinguisher and install smoke alarms (mitigation – reducing the impact). You could build a stone wall around your house (avoidance – removing the risk by building somewhere else). You could take out a comprehensive insurance policy (transfer – letting an insurance company handle the financial loss). Or you could choose to do nothing because the cost of the extinguisher and insurance is more than you can afford, accepting that your house might burn down (acceptance).

When the smoke alarm eventually goes off, that is the moment of response. You grab the extinguisher, call the fire brigade, and evacuate your family. You do not start shopping for extinguishers when the house is already on fire. You practise the evacuation drill with your family so everyone knows what to do without thinking. This is the entire lifecycle of risk treatment: you identify the threat (a spark from a faulty wire), evaluate your options, put protections in place, and then execute your pre-planned response when the event occurs. The goal is not to live in a world with no fires; it is to live in a world where fires don't destroy your life because you were prepared.

How It Actually Works

Once you have performed a risk assessment (discovered what could go wrong and how bad it would be), the next step is risk treatment. Risk treatment is the process of selecting and implementing measures to modify a risk. It is not the same as risk assessment; assessment finds the risks, treatment decides what to do about them. The CISM exam expects you to know the four primary risk treatment options: avoidance, mitigation, transfer, and acceptance.

Risk avoidance means you stop the activity that causes the risk entirely. For example, if a company decides not to launch a new online product because the security vulnerabilities are too expensive to fix, that is avoidance. The risk is gone because the activity is gone. This is the most drastic option and is usually only chosen when the cost of controlling the risk is higher than the benefit of the activity.

Risk mitigation (sometimes called risk reduction) is the most common option. You keep the activity but put controls in place to reduce either the likelihood of the risk occurring, or the impact if it does occur. A firewall that blocks malicious internet traffic is a mitigation control that reduces the likelihood of a network intrusion. A backup system that restores data if a server crashes is a mitigation control that reduces the impact of a failure. Mitigation never eliminates risk entirely; it makes it more manageable.

Risk transfer means you shift the financial burden of a risk to a third party. The most common example is cyber insurance. Your company still experiences the data breach, but the insurance company pays for the forensic investigation, legal fees, and customer notification. Transfer does not eliminate the risk itself (the breach still happens), but it moves the financial consequences. Another form of transfer is outsourcing a service to a cloud provider, where the provider contractually accepts responsibility for certain security controls.

Risk acceptance is the decision to acknowledge the risk and take no action to reduce it. This is not a lazy option; it is a deliberate, documented decision. Every organisation has a risk appetite – the amount of risk they are willing to accept. For example, a small business might accept the risk of a minor credit card theft because the cost of implementing a full payment card industry (PCI) compliance programme is greater than the potential loss. The exam emphasises that acceptance must be an explicit choice, not an oversight.

After you have treated the risk, you develop a risk response plan. This is the detailed playbook for what happens if the risk materialises into an actual incident. It includes who does what, who to call, what systems to shut down, and how to communicate with customers and regulators. The response plan is tested during drills and tabletop exercises.

A key concept for the exam is residual risk. This is the risk that remains after you apply your controls. If you install a firewall, you reduce the risk of a network attack, but a sophisticated attacker might still get through. That leftover risk is residual risk. The goal of risk treatment is to reduce residual risk to a level that is within the organisation's risk appetite.

Another critical concept is inherent risk. This is the risk before any controls are applied. If a company stores 10 million customer records with no password protection, that is a very high inherent risk. After applying encryption and access controls, the residual risk is much lower. The difference between inherent and residual risk is a measure of how effective your controls are.

The CISM exam also tests the difference between control types. Preventive controls stop a risk event from happening (e.g., a lock on a door). Detective controls identify that a risk event is happening or has happened (e.g., an alarm that sounds when the door is forced open). Corrective controls fix the problem after it has occurred (e.g., a repair crew that replaces the broken door). A complete security programme uses a mix of all three.

Finally, you must understand that risk treatment is ongoing. Risks change as the business changes, as technology evolves, and as new threats emerge. The information security manager does not do this once and then walk away. They revisit the risk register regularly, reassess controls, and adjust treatment strategies as needed.

The risk treatment decision process: from assessed risk through option selection, control implementation, and residual risk evaluation.

Walk-Through

1

Identify and assess risks

Before you can treat a risk, you must find it and evaluate its likelihood and impact. This step produces a list of risks ranked by severity, which becomes the input for all treatment decisions.

2

Select treatment option

For each risk, choose one of the four treatment options: avoid, mitigate, transfer, or accept. The choice depends on the organisation's risk appetite, the cost of controls, and the nature of the risk. This decision is documented in the risk register.

3

Implement controls

If you selected mitigation, deploy the specific controls (e.g., firewalls, backups, training). If you selected transfer, purchase insurance or sign contracts with third parties. This step turns the decision into action.

4

Document residual risk

After controls are in place, recalculate the risk level. The remaining risk is the residual risk. Compare it to the organisation's risk appetite. If it is still too high, you may need to add more controls or change the treatment option.

5

Develop a response plan

Create a detailed incident response plan for the most likely or most damaging risks. The plan specifies roles, communication protocols, containment procedures, and recovery steps. This plan is tested through drills and tabletop exercises.

6

Monitor and review

Risks and controls change over time. Regularly review the risk register, test control effectiveness, and update the treatment strategy as new threats emerge or business objectives shift. This step ensures the treatment remains relevant.

What This Looks Like on the Job

Consider a mid-sized retail company that sells products online and in physical stores. They have just completed their annual risk assessment and identified several important risks. Let's walk through how the information security manager (ISM) handles each one.

The first risk is a potential data breach of customer credit card information from the online store. The ISM recommends a combination of risk mitigation and risk transfer. For mitigation, they implement a Web Application Firewall (WAF) to block malicious traffic and require multi-factor authentication for all administrative accounts. For transfer, they purchase a cyber insurance policy that covers up to 2 million dollars in breach response costs. The residual risk is now much lower, but it is not zero because no control is perfect.

The second risk is a fire in the main warehouse that could destroy inventory. The ISM installs smoke detectors and an automatic sprinkler system (mitigation). They also create a detailed fire response plan: the fire marshal is assigned, evacuation routes are posted, and quarterly fire drills are scheduled. This is the response plan in action. The remaining residual risk is that the sprinklers might not work if the water supply is cut off. The company decides to accept that residual risk because the cost of a backup water source is too high.

The third risk is the possibility that a key supplier might go out of business, disrupting the supply chain. The ISM cannot control whether the supplier fails, so they recommend risk transfer by contracting with a backup supplier. If the primary supplier fails, the backup supplier can fill the gap. They also recommend risk acceptance for a small amount of delay (a few days) because the backup supplier is slightly slower.

The fourth risk is that an employee might accidentally click on a phishing email and install ransomware. The ISM uses a combination of preventive controls (email filtering technology), detective controls (user awareness training and phishing simulation exercises), and corrective controls (automated backup recovery). After these controls are in place, the residual risk is reviewed by the risk committee. The risk committee approves the treatment plan and documents it in the risk register.

Now, the ISM must monitor these controls. They schedule quarterly review meetings, track control effectiveness metrics, and update the risk register when new vulnerabilities are discovered. When an actual incident occurs, the ISM leads the response team, follows the pre-defined playbook, and then conducts a post-incident review to improve controls. This iterative cycle is what the CISM exam expects you to understand in detail.

How CISM Actually Tests This

The CISM exam tests risk treatment, response, and mitigation extensively. You must memorise the four treatment options (avoidance, mitigation, transfer, acceptance) and be able to apply them to a scenario. The exam will describe a business situation and ask you to choose the most appropriate treatment. For example: 'A company operates in a high-risk region and decides to shut down that office entirely.' The correct answer is risk avoidance.

One common trap is confusing risk mitigation with risk transfer. The exam will describe a scenario where a company buys cyber insurance. Many beginners assume this is mitigation because it reduces the impact. It is actually transfer, because the financial burden is moved to a third party. The company still owns the security problem; they just paid someone else to cover the cost.

Another trap is treating risk acceptance as a default or careless option. The exam will present a scenario where the company fails to implement a control and simply ignores the risk. That is not acceptance; it is an oversight. Acceptance requires a formal, documented decision by senior management. If the question says the company 'did nothing because they forgot', that is not acceptance.

The exam also tests the difference between inherent risk and residual risk. You will see questions that say: 'The organisation has a risk assessment score of 80 out of 100 before controls, and 30 after controls. Which is the residual risk?' The answer is 30. They love to reverse these terms to test your understanding.

Control types (preventive, detective, corrective) are another favourite topic. You must be able to identify which type of control each example represents. A firewall is preventive. An intrusion detection system (IDS) is detective. A backup restoration procedure is corrective. The exam will mix them up and ask you to pick the right category.

Key definitions to memorise:

Risk treatment: the process of selecting and implementing measures to modify risk.

Risk response: the execution of planned actions when a risk materialises.

Residual risk: risk remaining after controls are applied.

Inherent risk: risk before any controls are applied.

Risk appetite: the amount of risk an organisation is willing to accept.

Risk register: a document that lists identified risks, their scores, planned treatments, and owners.

The exam also asks about the relationship between risk assessment and risk treatment. You must know that assessment comes first (find and analyse risks), then treatment (decide what to do). Some questions will try to reverse the order; that is a trap.

Finally, expect scenario-based questions about the response process. They will describe a data breach and ask: 'What is the FIRST step the information security manager should take?' The answer is usually to activate the incident response team and follow the pre-defined response plan, not to investigate the cause or notify the press. Prioritising containment and communication is a common exam theme.

Key Takeaways

Risk treatment has four options: avoid, mitigate, transfer, and accept — memorise them in this order and learn to identify each from a scenario.

Mitigation reduces risk but never eliminates it; the remaining risk is called residual risk and must be within the organisation's risk appetite.

Risk acceptance must be a formal, documented decision by management, not a default action or an oversight.

Risk response is the plan you execute when a risk materialises; it includes communication, containment, and recovery steps.

Preventive controls stop a risk event, detective controls identify it, and corrective controls fix the damage — all three are necessary.

The difference between inherent risk (before controls) and residual risk (after controls) is a measure of control effectiveness.

Cyber insurance is a form of risk transfer, not mitigation, because it moves the financial burden but does not reduce the likelihood of the event.

Risk treatment is an ongoing process; risks must be reassessed regularly as the business and threat landscape change.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Risk Mitigation

Reduces likelihood or impact through controls (e.g., firewalls, backups)

The organisation retains ownership of the risk event

The cost of controls is borne by the organisation

Risk Transfer

Shifts financial burden to a third party (e.g., insurance, outsourcing)

The organisation still experiences the event but does not pay for it

The premium or contract cost is the price of transfer

Inherent Risk

Risk level before any controls are applied

Represents the worst-case scenario

Used as a baseline to measure control effectiveness

Residual Risk

Risk level after controls are applied

The actual exposure the organisation lives with

Must be within the organisation's risk appetite

Preventive Control

Stops a risk event from happening

Examples: firewall, lock on a door, antivirus software

Implemented before the event

Detective Control

Identifies that a risk event is occurring or has occurred

Examples: intrusion detection system, security camera, log monitoring

Implemented to enable timely response

Risk Avoidance

Eliminates the risk by stopping the activity

No risk remains because there is no activity

The most drastic option, used when risk is too high to manage

Risk Acceptance

Retains the risk with no controls applied

Risk remains at its original level

Used when the cost of treatment exceeds the potential loss

Watch Out for These

Mistake

Risk treatment and risk response are the same thing.

Correct

Risk treatment is the selection of controls and strategies to address a risk. Risk response is the execution of the plan when the risk actually occurs. Treatment is planning; response is action.

The words sound very similar, and many resources use them loosely. The CISM exam draws a clear distinction between planning and doing.

Mistake

Mitigation means eliminating the risk completely.

Correct

Mitigation reduces the likelihood or impact of a risk but never eliminates it entirely. There is always some residual risk left.

The word 'mitigate' in everyday language often means 'make something better', but in security, people might assume it means 'fix it' completely. The exam is precise about this.

Mistake

If you buy cyber insurance, you don't need to worry about security controls.

Correct

Cyber insurance transfers the financial cost of a breach, but the breach still harms the company's reputation, operations, and customer trust. You still need controls to prevent the breach from happening.

Insurance feels like a magic fix, but it only covers money, not data or trust. Beginners often think insurance is a complete solution.

Mistake

Risk acceptance means you ignore the risk and hope it doesn't happen.

Correct

Risk acceptance is a deliberate, documented decision made by management after considering the risk. Ignoring a risk because you forgot is negligence, not acceptance.

The word 'accept' sounds passive, so beginners assume it's the lazy option. The exam requires explicit documentation as proof of acceptance.

Mistake

Inherent risk is the risk level after you have put controls in place.

Correct

Inherent risk is the risk level before any controls are applied. Residual risk is the risk level after controls. The two terms are frequently reversed.

The natural language meaning of 'inherent' suggests something that is built-in or present, but beginners often associate it with the current state rather than the initial state.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between risk treatment and risk response?

Risk treatment is the process of selecting controls and strategies before a risk event occurs. Risk response is the execution of a pre-defined plan when the event actually happens. Treatment is planning; response is doing.

Can you give an example of risk avoidance?

Yes. If a company decides not to launch a new online service because the security vulnerabilities are too expensive to fix, that is risk avoidance. The activity is stopped entirely, so the risk is eliminated.

Is buying cyber insurance risk mitigation or risk transfer?

It is risk transfer. The financial impact is moved to the insurance company, but the risk event (the data breach) still occurs. Mitigation would reduce the likelihood or impact through controls like firewalls or encryption.

What is residual risk?

Residual risk is the risk that remains after all controls have been applied. For example, if a firewall blocks 99% of attacks, the 1% that gets through is residual risk. The goal is to bring residual risk within the organisation's risk appetite.

Can a company use more than one treatment option for the same risk?

Yes. Many risks are addressed with a combination of options. A company might mitigate a data breach risk with encryption (mitigation), purchase cyber insurance (transfer), and formally accept a small amount of residual risk (acceptance).

What does risk acceptance look like in practice?

The risk is documented in the risk register, and a senior manager (like the Chief Information Security Officer or board member) signs a formal acceptance statement acknowledging the risk and agreeing to bear the consequences without further controls.

Terms Worth Knowing

Keep going

You've finished Risk Treatment, Response, and Mitigation. Continue through the CISM study guide to build a complete picture of the exam.

Done with this chapter?