Risk as a relationship

Risk as a relationship

Share this content

Facebook
Twitter
LinkedIn

In the first of a three-part series, Tim Wenzel, Chief Operating Officer at Fortis Security, examines “risk” as one of the most overused and misunderstood words in security.

Risk. Possibly the most overused and misunderstood word, or concept, in security.

It is often used to manipulate the emotions of stakeholders to achieve a premeditated outcome. It’s no wonder our stakeholders are often skeptical of this discussion.

A few years ago, I spoke at a security conference in Anaheim. While I was discussing the evolving role of the CSO, I was illustrating the story of risk and someone asked what exactly I was referring to when I said “risk”.

I asked him if he was a CSO, he replied “No”. My entire panel said in unison: “You should be.”

He was stepping out and engaging to further define the material nature of this often vague concept. Fortis Security has embraced Enterprise Security Risk Management (ESRM) as its risk framework and philosophy of choice. Why is this?

ESRM provides a program management framework to understand the most critical risks to the most critical assets to any type or size of enterprise at any given time. It allows for strategic and operational agility on behalf of all stakeholders.

It applies to all types of security risk and is discipline agnostic. It works equally well with physical security, logical security, portfolio governance, strategic forecasting, crisis management, operational decision making etc.

ESRM can serve as a fusion philosophy to bring all security disciplines in alignment and partnership with the Enterprise Risk Management (ERM) function.

It also trains security managers to think about and discuss risk in a similar fashion to the business we serve, helping us gain relevancy and that coveted “seat at the table.”

This last point really cannot be overstated. Recently, I was assessing a corporate security program. During interviews with leadership, I asked the General Counsel to describe her role within the company. Her answer was pleasantly surprising.

She paraphrased the opening two sentences of my resume, excluding any reference to security. My colleague was also smiling because we had just discussed the nature of risk at dinner the night before.

As a result, we had a fascinating conversation with this GC on her perspective, definition and framework surrounding the concept of risk in the legal setting… and we were speaking the same language.

Risk is the language of business. Legal, HR, Compliance, Audit, Finance, Governance – all conduct their business through the lens of risk management.

If security professionals were fluent in the communication of risk, we could contribute to EVERY discussion within the business.

ISO 31000:2018 defines risk as “the effect of uncertainty on objectives.” The openness of this definition is very useful for us. It allows us to get away from “threats” as our only talking point.

The time has come for the security industry to reject vague generalizations such as:

  • This facility or business activity is high risk
  • That person is a risk
  • There is a lot of risk involved in…
  • This risk is negligible

Statements such as these are often conclusions to a discussion. They are incomplete and devoid of logic.

They have become a knee-jerk reaction, the least thoughtful way to describe the condition of an asset, relating to threat and loss potential.

Statements like these should always be challenged, just as the astute gentleman in Anaheim challenged me… to create clarity.

Risk is often discussed as an intangible idea. An almost spiritual phenomenon which magically appears at inconvenient times. Risk should always describe a relationship between:

  1. An asset
  2. Specific uncertainty or threat scenarios
  3. Vulnerabilities: environmental, behavioral or activity-based portals exposing assets during specific periods of time
  4. The severity of categorical loss experienced by the organization

Defining the concept of risk

Classically, risk is assigned a probability of a threat acting upon a protected asset in varying degrees of severity which produces a projected loss to the business.

There are problems associated with relying upon probability to rank how likely a threat event will transpire:

  1. Probability is static, unchanging until it is reassessed
  2. Probability quickly becomes 100% as a threat event unfolds, leaving no understanding of what changed until after the fact
  3. Probability carries bias based on who conducted the calculation – and with which criteria
  4. Probability often feels certain. The conversation around risk is closed… until it’s not

If we commit to expressing and discussing risk as a relationship, we can understand the risk environments surrounding an asset in a way that doesn’t predict probability but instead defines environmental conditions which must be present for a threat event to manifest itself.

This further materializes the concept of risk in a specific environment with vulnerabilities – or portals – which can be seen, tested, manipulated, documented and monitored.

This lends itself to program management and the ability to monitor the threat landscape through the lifecycle of an asset and decide how to best implement risk management options.

This approach lends itself to Corporate Governance, infusing the risk ledger with practical information which can be tracked over time, changes in leadership and organizational priorities.

We can see and document the mission and objectives of the organizations we serve and their effect on the risk environments that their most important assets live within.

We can close the gap between business and security with a proper understanding of risk and the options to treat or manage it.

As security leaders, we suddenly have the ability to do something we’ve never been allowed in the past – to be creative and innovative in how we apply the principles of security, protection and risk to the world’s most interesting problems and environments.

This article is the first in a three-part series aiming to help security leaders think through the logic of risk, making the concept tangible, able to be easily communicated, and its strategies tailored to our modern environments. Next time, we will get to the bottom of this question: What creates risk? When is risk born?

This article was originally published in the August edition of Security Journal Americas. To read your FREE digital edition, click here.