Why ‘high risk’ won’t win a prevention budget


A risk register, the organization’s running list of identified risks, can label a threat high, medium, or low, but budget decisions require translating that rating into a financial estimate.

According to a new blueprint from Info-Tech Research Group, many organizations still use qualitative risk assessments that don’t consider the business impact. Missing financial context makes it harder for CIOs, CISOs, and risk leaders to prioritize mitigation, compare spending choices, and make the case to boards and executives.

Qualitative scoring still has a role, since it can quickly sort risks by likelihood and impact. Info-Tech recommends using that first pass to identify the most serious exposures, then doing deeper financial analysis on those risks.

For risks rated the most severe, Info-Tech recommends estimating what a single incident could cost, how often it could happen, and what the organization could expect to lose over a year. That turns a ‘high’ risk rating into a financial estimate executives can weigh against the cost of prevention.

“When risk is only described as high, it becomes difficult to secure funding or drive action,” says Carlene McCubbin, AVP at Info-Tech Research Group. “IT leaders are then held accountable when incidents occur, despite not having the financial clarity needed to justify preventative investment. Translating risk into business terms enables more informed, shared decision-making at the executive level.”

Info-Tech says the assessment process has problems of its own. Risk scores can be subjective, the underlying data may be incomplete or spread across different teams, and more detailed financial models can take too much time and effort to maintain.

“If risk cannot be expressed in financial terms, leaders cannot justify mitigation investments or influence board-level decisions,” says Anubhav Sharma, principal research director at Info-Tech Research Group.

Many traditional risk assessments were built for compliance reporting, the research finds, and their outputs don’t give executives much to work with when deciding where to spend. That leaves CIOs, CISOs, and other risk owners accountable for what happens, even when the assessment itself hasn’t given them a strong financial case for prevention.

Final shots

  • A “high” risk rating can flag a problem, but it still leaves executives without a clear basis for deciding how much to spend on it.
  • If the data behind a risk assessment is scattered across teams or based heavily on judgement calls, the funding case gets harder to defend.
  • Risk reporting needs to help leaders choose where limited prevention dollars should go, not simply document what could go wrong.



Why ‘high risk’ won’t win a prevention budget

#high #risk #wont #win #prevention #budget

Leave a Reply

Your email address will not be published. Required fields are marked *