Risks. We all face them, every day, at every moment. Most of them pass us by. When we get into a car or board a train to work, there is always a very small chance we will not arrive. Yet we take that risk. A life free of risk is impossible.
But we do act on some risks. Perhaps addressing them takes little effort, such as not leaving your laptop behind when you visit the toilet in a café. Or perhaps the potential damage is so great that you simply cannot take the risk, such as crossing a motorway because it happens to be the shortest route.
Risk analysis
As a business, you do not want to handle risks unconsciously. An information security standard such as ISO 27001 requires a deliberate approach. You regularly examine your risks and discuss them with stakeholders. During that conversation, you brainstorm the risks you face and visualise the consequences if they occur.
You then try to quantify the risk along two axes, for example on a five-point scale. One is the likelihood that it will occur; the other is the impact if it occurs. Multiply the two numbers to get a risk score. That score gives you a sense of how urgently the risk should be treated.

The real benefit: an in-depth conversation
Ultimately, risk analysis is only a tool: a process for starting a substantive conversation. We take time to consider what could go wrong, reflect on it, discuss how serious we consider it and decide whether to accept the risk or treat it.
Some risks occur very frequently, but their impact is so small that addressing them is barely worthwhile. Think of a technical problem that causes no inconvenience because a simple workaround exists.
Other risks have an enormous impact, but their likelihood is extremely small and the costs very high, or treatment options are simply not feasible for an individual party. We call these Black Swans, after the book of that name by Nicholas Nassim Taleb. You are aware of the risk but have no choice but to accept it. For Europe as a whole, one example would be the US deciding to stop supplying IT infrastructure to Europe. There is a reason data sovereignty is high on Europe's agenda.
Treatment options
For the risks we want to address, we brainstorm possible solutions. If specialist knowledge is needed, we schedule separate deep-dive sessions to develop treatment options that mitigate the risk. This can work along several dimensions. For example, when considering the risk of fire:
- reduce the likelihood of fire; replace a gas cooker with an induction hob
- reduce the impact of fire; keep valuables out of the building, have a plan to move to a ready-to-use fallback location, or insurance covering everything
- fight a fire; provide firefighting equipment in the building and people trained to use it
- detect a fire; install smoke detectors throughout the building
How does our customer benefit?
Besides the direct benefit that our information security quality brings to customers in the operational chain, our customers can use our risk analysis process too. This is useful because we combine process expertise with knowledge of their business and the tools we have already built for them.
We recently carried out this process for a customer. We adapted our internal risk analysis procedure to the customer's domain, particularly in relation to likelihood and impact. During the session, we systematically worked through the entire workflow and identified pain points.
The end result of the risk analysis is a clear report that the customer can hand to an auditor as evidence. Alongside the report, the treatment options are developed into practical steps to make the process safer. The customer can choose which to implement. Both the customer and we were very satisfied with the process and its outcome.