Business A.M
No Result
View All Result
Thursday, February 26, 2026
  • Login
  • Home
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • About Us
  • Contact Us
Subscribe
Business A.M
  • Home
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • About Us
  • Contact Us
No Result
View All Result
Business A.M
No Result
View All Result
Home Analyst Insight

Managing risk response and mitigation in information security

by Admin
January 21, 2026
in Analyst Insight

To fully manage risk within an organisation and to track the mitigation strategies, a focused approach is required. Most organisations want a positive response to any risk assessment findings. Yet, many IT professionals and consultants approach risk response from a negative standpoint.
Let’s start with a case. A particular consulting firm carries out an information security risk assessment within a particular company. They found a lot of gaps within the business processes and functions. The consultants’ response, according to their client, was alarming.
Every organisation has risk. Stakeholders within the organisation must determine which risk is acceptable, which risk is transferable third parties such as an insurance company or which ones need to be mitigated. Risk is different for various organisations. Therefore, what works in the oil and gas context might not work in the telecommunications space.
As such, to get the right risk response that fits a company’s goals, there needs to be a thorough risk analysis. For example, when looking for privacy risks, the gap analysis revolves around access management, information retention schemes, security, data subject access requests and many more. The search is for these gaps and designing the right response for them. A risk analysis will help an organisation prioritise the response options that are right for them.
In addition to this, it is important that response doesn’t affect the day-to-day business operations. Most IT consultants or professionals forget that the business objectives are top priority, and to maximise efficiency in passing their duties, they must keep this in mind.
One known risk response methodology is the Plan-Do-Check-Adjust (PDCA) life cycle. The model supports continuous improvement. It encompasses the design, implementation, assessing, and adjusting and creating documentation of the controls that will respond to risk.
There are known risk response standards. There is the National Institute of Standards and Technology (NIST) framework, Control Objectives for Information and Related Technology (COBIT) framework, just to mention those two. Organisations must bear in mind that these frameworks have their pros and cons. It is, therefore, imperative to determine the best one that fits the purpose and business missions.
Risk response usually revolves around avoidance, mitigation, sharing and acceptance to lower the risk level organisations face. This will help reduce threats and vulnerabilities, prevent regulatory fines, and help keep the reputation of the company.
A risk mitigation simply put is the application of controls that lower the overall level of risk to reduce the likelihood of the threat exploit, or impact to the asset if the risk were to come to fruition. Some controls can be policies, replacing legacy systems or elimination of a third-party software tool that doesn’t meet ethical standards. The goal is to get the risk down to a level considered acceptable by the leadership in an organisation.
Risk controls fall into broad areas which includes the managerial, technical, operation and preparedness within the organisation. From a managerial standpoint, there needs to be an acceptable use policy to dictate the use information assets.
While from a technical point of view, an organisation can decide to implement additional firewalls to protect internal systems or install an intrusion detection system to monitor for malicious activities or violations of policy.
From an operational perspective, a company can decide to implement segregation of duties procedure to ensure that one person does not have the sole control over key duties, and they can mandate certain baseline knowledge of IT security-related issues and concepts.
There must be tabletop exercises to test the effectiveness of the controls within an organisation. The big question is are the controls working and are they addressing the gaps found out during the risk analysis stage?
Risk response and mitigation are quite interlinked. It is important, however, for companies to design the right response that fits their business missions and determine the right frameworks that fit their business context.

Admin
Admin
Previous Post

Singapore Is Shaping the Future of Mobility

Next Post

South Africa’s big bubble and lowered expectations

Next Post

South Africa’s big bubble and lowered expectations

  • Trending
  • Comments
  • Latest
Igbobi alumni raise over N1bn in one week as private capital fills education gap

Igbobi alumni raise over N1bn in one week as private capital fills education gap

February 11, 2026
NGX taps tech advancements to drive N4.63tr capital growth in H1

Insurance-fuelled rally pushes NGX to record high

August 8, 2025

Reps summon Ameachi, others over railway contracts, $500m China loan

July 29, 2025

CBN to issue N1.5bn loan for youth led agric expansion in Plateau

July 29, 2025

6 MLB teams that could use upgrades at the trade deadline

Top NFL Draft picks react to their Madden NFL 16 ratings

Paul Pierce said there was ‘no way’ he could play for Lakers

Arian Foster agrees to buy books for a fan after he asked on Twitter

N712.26bn MMIA upgrade puts Nigeria’s infrastructure credibility on trial

N712.26bn MMIA upgrade puts Nigeria’s infrastructure credibility on trial

February 25, 2026
Equities rally opens debate over risk controls in stock market

Equities rally opens debate over risk controls in stock market

February 25, 2026
PalmPay deepens customer engagement with #LoveWithPalmPay campaign 

PalmPay deepens customer engagement with #LoveWithPalmPay campaign 

February 25, 2026
Lafarge strengthens trade partnerships at 2025 Customer and Transporter Awards

Lafarge strengthens trade partnerships at 2025 Customer and Transporter Awards

February 24, 2026

Popular News

  • Igbobi alumni raise over N1bn in one week as private capital fills education gap

    Igbobi alumni raise over N1bn in one week as private capital fills education gap

    0 shares
    Share 0 Tweet 0
  • Insurance-fuelled rally pushes NGX to record high

    0 shares
    Share 0 Tweet 0
  • Reps summon Ameachi, others over railway contracts, $500m China loan

    0 shares
    Share 0 Tweet 0
  • CBN to issue N1.5bn loan for youth led agric expansion in Plateau

    0 shares
    Share 0 Tweet 0
  • Glo, Dangote, Airtel, 7 others prequalified to bid for 9Mobile acquisition

    0 shares
    Share 0 Tweet 0
Currently Playing

CNN on Nigeria Aviation

CNN on Nigeria Aviation

Business AM TV

Edeme Kelikume Interview With Business AM TV

Business AM TV

Business A M 2021 Mutual Funds Outlook And Award Promo Video

Business AM TV

Recent News

N712.26bn MMIA upgrade puts Nigeria’s infrastructure credibility on trial

N712.26bn MMIA upgrade puts Nigeria’s infrastructure credibility on trial

February 25, 2026
Equities rally opens debate over risk controls in stock market

Equities rally opens debate over risk controls in stock market

February 25, 2026

Categories

  • Frontpage
  • Analyst Insight
  • Business AM TV
  • Comments
  • Commodities
  • Finance
  • Markets
  • Technology
  • The Business Traveller & Hospitality
  • World Business & Economy

Site Navigation

  • Home
  • About Us
  • Contact Us
  • Privacy & Policy
Business A.M

BusinessAMLive (businessamlive.com) is a leading online business news and information platform focused on providing timely, insightful and comprehensive coverage of economic, financial, and business developments in Nigeria, Africa and around the world.

© 2026 Business A.M

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • About Us
  • Contact Us

© 2026 Business A.M