Articles

Treating a risk: mitigate, avoid, transfer, accept

Five ways to respond to a risk: what each one changes, what is left, and who answers.

Reading: 6 minCybersecurity Governance

Article cover: Treating a risk: mitigate, avoid, transfer, accept

A risk is not managed by finding it; it is managed by deciding what to do about it. NIST SP 800-39 names five responses to risk — accepting, avoiding, mitigating, sharing, or transferring — and SP 800-30 Revision 1 hands the same set to the decision as the output of a risk assessment. The choice is made per risk, against the organisation’s risk frame and its risk tolerance. It does not end the matter: every response leaves a residual risk that must be monitored and re-decided. The distinction this sheet owns is between the responses that change the risk and the ones that move responsibility or liability for it. Only mitigation reduces the risk itself; sharing and transfer shift that responsibility or liability to another party, not the risk.

The model: one risk, five responses, and what is left

identified risk  (from the risk assessment, assigned to a risk owner)
        ↓
choose a response against the risk frame and the risk tolerance
        ↓
avoid  |  mitigate  |  share  |  transfer  |  accept
        ↓
residual risk  →  monitor  →  verify and measure  →  re-decide

A response is chosen for one identified risk, not for a project or a department, and it is chosen against the risk frame the organisation has set and its risk tolerance — the level of risk it is willing to accept in pursuit of its objectives (SP 800-39). Whatever is chosen, the assessed risk does not reach zero. What remains is the residual risk: “the portion of risk remaining after security measures have been applied” (SP 800-30r1), and it is the object of the monitoring step.

Choosing a response, step by step

  1. Start from a single risk with its own likelihood and impact (SP 800-30r1), and read it against the risk frame and the stated risk tolerance (SP 800-39).
  2. If the risk is within tolerance, accept it. Acceptance is described as the appropriate response when the identified risk is within the organisational risk tolerance; it is a decision on the record, not a silence.
  3. If it exceeds tolerance, the other four are available. Avoid by removing the activity or technology that carries the risk. Mitigate that portion of the risk which cannot be accepted, avoided, shared or transferred. Share the responsibility with another, better-placed party, or transfer the liability — typically by insurance or contract (SP 800-39).
  4. Prioritise across risks, because resources are finite: higher risks receive more, which does not mean the lower ones are ignored (SP 800-39, risk response decision).
  5. Implement the chosen course of action and fix who is responsible for it, the criteria by which its effectiveness will be judged, the plan for monitoring it and the triggers that will reopen the decision (SP 800-39, outputs of the risk response step).

What each response changes, and what it does not

Response What it changes Typical means What stays with the organisation
Accept nothing about the risk; the decision to live with it is recorded a documented acceptance within tolerance the risk itself, and the duty to monitor it
Avoid removes the risk by removing the activity or technology that carries it not adopting a process or technology; an air gap in place of a network link the lost capability, and the residual risk of whatever replaces it
Mitigate the risk itself — its likelihood or its impact common controls, process redesign, new or strengthened safeguards residual risk, and the obligation to verify the controls work
Share part of the liability or the responsibility joint responsibility, partnership, contract accountability for the decision, and the residual risk
Transfer the whole liability or responsibility insurance, or a contract that shifts liability the consequence, and the responsibility for the decision

Only mitigation reduces the risk while the activity continues. SP 800-39 notes that the five overlap — a shared risk is one each party accepts, and avoidance can be read as mitigating the risk to zero — but the separation is worth holding: acceptance changes nothing, and transfer moves the liability without touching the likelihood or the consequence. Sharing moves only a portion, and can hand a better-placed party the job of mitigating. The document is blunt about transfer: it “reduces neither the likelihood of harmful events occurring nor the consequences in terms of harm…”.

The misconception: “the risk is no longer ours”

Two sentences fail in the same way. The first is “transferring the risk means it is no longer ours.” Transfer moves liability, not consequence. SP 800-39 states that risk transfer reduces neither the likelihood of a harmful event nor the harm it does, and SP 800-37 Revision 2 makes the boundary explicit for supply chains: the responsibility for responding to risks from the use of component products, systems and services from external providers remains with the organisation and its authorising official. Insurance pays after the loss; it does not prevent it, and it does not answer for the decision.

The second is “mitigation means the risk is gone.” The response is a decision about a residual: SP 800-39 says that regardless of the decision there still remains a degree of residual risk that must be addressed, and SP 800-30r1 defines residual risk as the portion remaining after security measures have been applied. A mitigated risk is a smaller risk, not an absent one, and the monitoring step exists because the residual is what is left to watch.

What to remember

  • The five responses are accept, avoid, mitigate, share and transfer; the choice is per risk, not per project.
  • The choice is bounded by the risk frame and the risk tolerance.
  • Mitigation reduces the risk; acceptance leaves it; sharing and transfer move responsibility or liability, not the risk.
  • Moving responsibility does not remove the risk: accountability for the decision stays with the organisation.
  • Every response leaves residual risk, so monitoring, effectiveness measurement and re-decision follow.
  • An accepted risk is a recorded decision, not an unmanaged one.

Level and prerequisites

L1 — fundamentals: the vocabulary of risk response and the decision model, with no procedure, no control selection and no configuration. Prerequisites: the risk-factors and risk-appetite sheets; neither is published yet.

Where to go next

  • Cybersecurity Governance — the area this sheet belongs to.
  • Which control reduces which risk, and how it is implemented, belongs to the technical areas (roadmap §6): Networking, Server & Virtualization, AI & LLM.

References

  • NIST, Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System View (March 2011) — the risk response component and the five responses; risk tolerance; the residual risk that remains after any decision; the risk monitoring component; risk sharing and transfer.
  • NIST, Special Publication 800-30 Revision 1, Guide for Conducting Risk Assessments (September 2012) — the same five risk responses as the input an assessment informs; the definition of risk; the definition of residual risk.
  • NIST, Special Publication 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy (December 2018) — risk tolerance as the acceptable degree of risk; residual risk regardless of the response; the responsibility remaining with the organisation for risks from external providers.
  • NIST, NISTIR 8286r1, Integrating Cybersecurity and Enterprise Risk Management (ERM) (December 2025), DOI 10.6028/NIST.IR.8286r1 — the risk register as the record of the risk response and of its owner, and the place residual risk is documented and analysed against risk appetite and tolerance. This is the current edition; the NISTIR 8286 of October 2020 that it supersedes was withdrawn on 18 December 2025 and superseded in its entirety.
  • NIST, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (February 26, 2024) — GV.RM-04, strategic direction on risk response options, and ID.RA-06, responses chosen, prioritized, planned, tracked and communicated.