In your opinion, who SHOULD own the risk in your organization?
IT Director/Other Senior IT Manager16%
CISO/Other Senior Security Manager46%
Senior Manager in another part of the organization12%
CEO/other board member16%
operational risk5%
Other (comment below)2%
Sort by:
Every StakeHolder should own risk
Pproviding the person owning the risk is held accountable to address, mitigate, or accept the risk.
Owned by Application (Budget) owner. In my experience the risk can come from older or unmaintained systems, so if the owner wont' fund for upgrades, enhancements, closing security gaps, it's on the owner and the budget to decide to keep the systems and the risk, or shut it down, or fund remediation.
The question is loaded as there are multiple definitions of risk. A well structured risk governing body consists of the multiple lens.
No one person should 'own' risk for an organization. Risk should be transparent and shared among the appropriate stakeholders.
What I have seen in risk management, is that risk owner varies depending on the organization. A risk can be assigned to a person or persons responsible for the day-to-day management of a risk. By assigning an owner, the designated risk owner ensures someone in the organization is accountable for the said risk. If there is no one person or a group charged with managing a risk, then by default, the entire organization will own the risk, and therefore, it is highly likely the risk may fall through the cracks and nothing done to address it (well run organizations assigned ownership) . Having a risk owner is an important step toward ensuring that a plan to mitigate (or accept) the risk is developed and acted upon in a timely manner to protect the organization from that risk exposure. In my career, I have seen SVP shown the door because they never took action to address risks identified in audits and the risk became realized.
Who owns the risk entirely depends on the nature of the risk. It doesn't make much sense for sales to own infosec risk, or for IT to own revenue risk.