How often do you survey your organization for new, emerging risks? My company currently does quarterly surveys and I am contemplating dropping it down to 2x/year. Appreciate the insights!

1.6k viewscircle icon5 Comments
Sort by:
Director of Marketing in IT Services23 days ago

“Great question! Quarterly surveys can definitely give a strong pulse on emerging risks, but I’ve seen many organizations succeed with twice-a-year assessments as long as they complement them with ongoing monitoring and open communication channels. Reducing the frequency could actually improve response quality and reduce survey fatigue, as long as other feedback loops stay active. Curious to hear what others have found effective!

Director - Enterprise Risk Manager in Insurance (except health)24 days ago

We have an emerging risks committee that is scheduled to meet quarterly but usually ends up twice per year. The committee maintains an emerging risks inventory that is provided to our ERM committee.

Director of Legal and Compliancea month ago

We currently do a formal ERM risk assessment annually however through business conversations, it's an ongoing risk discussion, as risks emerge, we evaluate impact to the company and adjust our Top/Watch ERM list if necessary.

Lightbulb on1
Chief Cybersecurity Strategist & CISO in Healthcare and Biotecha month ago

2x ideally, but honestly really once a year generally around annual assessment time

Lightbulb on1
Director of Design in Healthcare and Biotecha month ago

It sort of depends how formal processes are related to taking action on the risks identified. We do one annual comprehensive enterprise risk assessment followed by an semi-annual update. If our process was more formal with clear risk owners, there may be a reason for more frequent updates.

Lightbulb on1

Content you might like

It gets in the way!62%

We are smooth sailing!37%

Disruption via ransomware40%

Exploitation via phishing64%

Exfiltration of PII (Personally identifiable information)43%

Disruption via DDoS attacks26%

Disruption of a business-critical application21%

Other (comment below)

View Results