Risk Treatment
Risk treatment is the step in risk management where an organization decides what to do about a risk it has identified and assessed. Depending on how serious the risk is, the organization may try to remove it, reduce it, shift it to another party, or accept it. The goal is to bring the remaining, or residual, risk down to a level the organization is willing to live with.
Risk treatment is the process of selecting and implementing options to address assessed risks that are deemed unacceptable, typically occurring after risk identification and assessment within the broader risk management lifecycle. Treatment options commonly include eliminating the hazard or source of risk, reducing likelihood or impact through controls, transferring or redirecting risk (for example, via insurance or contracts), and accepting residual risk. The chosen approach is documented in a risk treatment plan that specifies the actions and methods for handling each identified risk, with the objective of removing, reducing, or redirecting residual risk to a level aligned with the organization's objectives and risk appetite. In practice, a virtual CISO typically advises on and helps develop risk treatment strategies and plans, but accountability for accepting residual risk and authorizing treatment decisions generally remains with the client organization and its officers.
Why it matters
Risk treatment is where risk management stops being an analytical exercise and starts driving decisions. An organization can identify and assess risks with great rigor, but without a treatment step, those findings sit unaddressed and the organization gains no protection from the work it has done. Treatment forces a deliberate choice, eliminate, reduce, transfer, or accept, for each risk deemed unacceptable, and it ties those choices back to what the organization is actually willing to tolerate.
The concept also matters because it makes residual risk explicit. Few risks can be removed entirely, so the practical question is how much risk remains after controls, insurance, or contractual arrangements are applied, and whether that remaining level is acceptable. Documenting this in a risk treatment plan creates a record of what actions were selected and why, which supports accountability and helps stakeholders understand where the organization has chosen to accept exposure rather than spend more to reduce it.
For organizations engaging a virtual CISO, this distinction is important: a vCISO typically advises on and helps develop risk treatment strategies and plans, but the decision to accept residual risk and authorize treatment generally remains with the client organization and its officers. Treating a vCISO's recommendations as a transfer of accountability is a common misunderstanding, the value of the engagement lies in structuring and informing these decisions, not in assuming ownership of them.
Who it's relevant to
Inside Risk Treatment
Common questions
Answers to the questions practitioners most commonly ask about Risk Treatment.