QUESTION 1
1. After identifying the risks and security weaknesses within a client's organisation,
management must select the most cost-effective risk management strategy. Discuss the four
decisions available to management for managing risks cost-effectively and provide your own
examples.
Management has four primary strategic options for treating risks cost-effectively: avoidance,
reduction (or modification), sharing (or transfer), and retention (or acceptance) (ISO 31000:2018,
Clause 6.5). The core of cost-effective risk management lies in selecting the option that provides the
greatest risk reduction for the resources invested, balancing the cost of treatment against the potential
financial impact of the risk itself (Hillson, 2009, p. 87).
Risk avoidance is the most definitive decision, aiming to completely eliminate the risk by ceasing or
not starting the activity that gives rise to it. According to the Institute of Risk Management (IRM,
2002, p. 9), this strategy is best suited for situations where the potential negative impact of a risk is
unacceptably high, making the cost of any other form of treatment economically unviable. For
example, a company may decide against entering a new, highly volatile international market after a
thorough risk assessment identifies significant political and financial risks that could threaten its
stability. Similarly, an organisation might terminate a project to transfer sensitive data to a new cloud
service provider upon discovering that the move would expose it to an unacceptably high risk of
cyber-attack, effectively choosing to avoid the risk altogether rather than attempt to control it
(Hopkin, 2018, p. 156).
Risk reduction, also known as modification, involves implementing controls and measures to lower
the probability of a risk occurring or to minimise its potential impact. As noted by the Committee of
Sponsoring Organizations of the Treadway Commission (COSO, 2017, p. 64), this is often the most
common and practical risk management strategy, and cost-effectiveness is achieved by focusing on
the most critical risks where intervention can have the greatest effect. For example, a logistics
company could invest in a fatigue management system for its drivers, implementing mandatory rest
breaks and monitoring technology. While this incurs a cost, it is significantly less than the potential
financial and reputational damage from a major accident caused by driver fatigue. In a more complex
scenario, a chemical plant might evaluate the cost-effectiveness of different protection plans, such as
fireproofing versus video motion detection systems, to determine which provides the best security
and safety for its investment (Hillson, 2009, p. 92).
Risk sharing involves transferring a portion of the financial or operational burden of a risk to a third
party, most commonly through insurance contracts or outsourcing arrangements (IRM, 2002, p. 11).
Hopkin (2018, p. 160) emphasises that this strategy does not eliminate the risk, nor does it absolve
the organisation of its ultimate accountability, but it distributes the financial consequences. For
instance, a business can purchase professional indemnity insurance to protect against the cost of legal
claims arising from its services. The decision to share risk is cost-effective when the premium for
transferring the risk is less than the cost of the potential loss the business would have to bear itself.
Another example is using outsourcing for non-core activities; a company might contract a specialised
cybersecurity firm to manage its IT security, thereby sharing the operational and technical risk of a
data breach with experts (COSO, 2017, p. 71).