Enterprise Risk Management
Enterprise Risk Management (ERM) is a systematic, organization-wide approach to identifying the risks a business faces, assessing how likely they are and how much they matter, and managing them so the organization can still achieve its goals. Rather than looking at risks one department at a time, ERM takes an integrated view across the whole organization and its extended networks. It covers many kinds of risk, not just cybersecurity, including financial, operational, strategic, and compliance risks.
Enterprise Risk Management (ERM) is an integrated set of methods and processes applied across an entity to identify potential risks to its mission and objectives, assess their likelihood and impact, and manage them in a coordinated manner to enhance the organization's ability to achieve its objectives and establish the trust needed to support its operations. ERM operates at the enterprise level and its extended networks, aggregating and prioritizing risk across business units rather than treating risks in isolation, and typically informs governance, resource allocation, and decision-making. In many organizations, cyber and information security risk is treated as one input into the broader ERM portfolio; a security leader such as a virtual or fractional CISO may advise on, and help translate, security risk into enterprise risk terms, but accountability for enterprise risk decisions typically remains with the organization's officers and governing body. The value and maturity of an ERM program often varies by organizational maturity, stakeholder cooperation, and the clarity of defined objectives and risk appetite.
Why it matters
Enterprise Risk Management matters because organizations face many categories of risk at once, including financial, operational, strategic, and compliance risks, and cybersecurity is only one of them. When risks are managed in isolation by individual departments, an organization can miss the ways those risks interact or compound, and it can misallocate limited resources toward less consequential threats. ERM provides an integrated, organization-wide view that helps leaders prioritize what genuinely threatens the mission and objectives, rather than reacting to whichever risk is loudest at a given moment.
Who it's relevant to
Inside ERM
Common questions
Answers to the questions practitioners most commonly ask about ERM.