In your opinion, who SHOULD own the risk in your organization?
IT Director/Other Senior IT Manager17%
CISO/Other Senior Security Manager51%
Senior Manager in another part of the organization11%
CEO/other board member16%
operational risk2%
Other (comment below)1%
What I have seen in risk management, is that risk owner varies depending on the organization. A risk can be assigned to a person or persons responsible for the day-to-day management of a risk. By assigning an owner, the designated risk owner ensures someone in the organization is accountable for the said risk. If there is no one person or a group charged with managing a risk, then by default, the entire organization will own the risk, and therefore, it is highly likely the risk may fall through the cracks and nothing done to address it (well run organizations assigned ownership) . Having a risk owner is an important step toward ensuring that a plan to mitigate (or accept) the risk is developed and acted upon in a timely manner to protect the organization from that risk exposure. In my career, I have seen SVP shown the door because they never took action to address risks identified in audits and the risk became realized.
Pproviding the person owning the risk is held accountable to address, mitigate, or accept the risk.
Content you might like
Insider threats – rogue admins19%
Encrypting my data51%
Deleting my backup copies11%
Resident malware8%
Data theft – data exfiltration11%
Other1%
We are not doing regression testing10%
25% manual, 75% automated50%
50% manual, 50% automated27%
100% manual, 0% automated8%
Don't know2%