What Is a Risk in Security

In cybersecurity, risk is the potential for loss, damage or destruction of assets or data. Threat is a negative event, such as the exploit of a vulnerability. And a vulnerability is a weakness that exposes you to threats, and therefore increases the likelihood of a negative event.

What is the difference between security and risk?

So, what’s the difference between ‘security’ and ‘risk’ – e.g., ‘cyber security’ vs ‘cyber risk’? ‘Security’ is about doing things right. … ‘Risk’ is about doing the right things. It is strategic, having to identify and execute the correct actions under conditions of uncertainty.

What is security and risk management?

Security Risk Management is the ongoing process of identifying these security risks and implementing plans to address them. Risk is determined by considering the likelihood that known threats will exploit vulnerabilities and the impact they have on valuable assets.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest