Screenata

Beyond SOC 2

What is risk management?

August 18, 20262 min read

What is risk management?

Risk management is the process of identifying what could stop an organisation meeting its objectives, assessing how likely and how damaging each is, deciding what to do, and checking the decision worked. ISO 31000 is the general standard and defines risk as the effect of uncertainty on objectives, which is why the objectives come first: without them there is no way to say what counts as a risk.

The process

StepQuestion it answers
IdentifyWhat could go wrong, and to what?
AnalyseHow likely, and how bad?
EvaluateIs that acceptable against our risk appetite?
TreatAvoid, reduce, transfer, accept, or share
Monitor and reviewDid the treatment work, and has anything changed?

The output of steps one to four is a risk register. Step five is what most programmes drop after the first year.

Risk management, mitigation, and control

These get used interchangeably and are not the same.

  • Risk management is the whole process above.
  • Risk mitigation, more precisely reduction, is one of five treatments: lowering likelihood or impact through controls.
  • A control is the specific safeguard implementing a treatment. MFA is a control; reducing account-takeover risk is the treatment; the register entry is the management.

The five treatments in full: avoid, reduce, transfer, accept, share. See what are the five risk mitigation strategies.

Why compliance frameworks insist on it

Because it is what makes a control set defensible. A company that implements controls without a risk assessment has copied a template, and neither it nor its auditor can say whether those controls address anything the business actually faces.

FrameworkWhere it appears
SOC 2CC3 series, risk identification and analysis
ISO 27001Clause 6.1, with a documented methodology
HIPAASecurity Rule risk analysis, the most frequently cited enforcement gap
NIST 800-53RA control family

HIPAA is the sharpest example. A missing or inadequate risk analysis is one of the most common findings in HHS enforcement actions, more so than the technical failures people expect.

Cyber security risk management specifically

Same process, narrowed to information assets and threats. The differences in practice are that the threat landscape changes faster, so review cadence matters more, and that many risks are concentrated in third parties rather than your own systems, which is why vendor risk gets its own register.

The order that gets reversed

Most small compliance programmes start by collecting evidence, then work backwards to controls, and never do the risk assessment at all. That produces evidence for controls nobody chose, and gaps in the ones that mattered. Risk assessment first, controls from the assessment, evidence from the controls.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.