1
00:00:06,450 --> 00:00:08,040
- Welcome to lesson 24,

2
00:00:08,040 --> 00:00:10,980
Explain Elements of the
Risk Management Program.

3
00:00:10,980 --> 00:00:14,160
In lesson 24.1 we're gonna discuss

4
00:00:14,160 --> 00:00:17,070
Fundamental Risk Concepts.

5
00:00:17,070 --> 00:00:20,790
Now, if I asked you what
risk was, what would you say?

6
00:00:20,790 --> 00:00:21,697
Well, most people would say,

7
00:00:21,697 --> 00:00:24,270
"Ah, the fact that
something bad would happen."

8
00:00:24,270 --> 00:00:27,300
But in fact, we're gonna define risk

9
00:00:27,300 --> 00:00:29,520
as the uncertainty of outcome.

10
00:00:29,520 --> 00:00:31,440
The more risky something is

11
00:00:31,440 --> 00:00:33,990
the less certain we are of the outcome.

12
00:00:33,990 --> 00:00:36,270
Outcome could be good,
outcome could be bad,

13
00:00:36,270 --> 00:00:40,803
but risk is really broadly
defined as uncertainty.

14
00:00:42,480 --> 00:00:44,730
Now, risk or uncertainty is assessed

15
00:00:44,730 --> 00:00:47,550
by evaluating the
combination of the likelihood

16
00:00:47,550 --> 00:00:52,080
of something happening and
the impact if it does happen.

17
00:00:52,080 --> 00:00:55,710
That the impact could be
positive or negative, right?

18
00:00:55,710 --> 00:00:57,870
You put money maybe in the stock market

19
00:00:57,870 --> 00:00:59,400
in a retirement fund, right?

20
00:00:59,400 --> 00:01:02,160
Because you're hoping
to have a really good,

21
00:01:02,160 --> 00:01:04,710
solid financial requirement.

22
00:01:04,710 --> 00:01:06,750
If you are very risk adverse,

23
00:01:06,750 --> 00:01:07,980
you don't like a lot of uncertainty,

24
00:01:07,980 --> 00:01:11,670
maybe you're putting it
into CDs or treasury bills.

25
00:01:11,670 --> 00:01:14,490
If you are pretty
comfortable with risk, right?

26
00:01:14,490 --> 00:01:17,400
You may go, "Oh, I wanna
go into emerging markets

27
00:01:17,400 --> 00:01:18,510
or new companies."

28
00:01:18,510 --> 00:01:21,150
Less certainty, but maybe a better return.

29
00:01:21,150 --> 00:01:24,123
So your outcome could
be positive or negative.

30
00:01:25,080 --> 00:01:27,660
But generally in an organization,

31
00:01:27,660 --> 00:01:29,550
risk is studied from the perspective

32
00:01:29,550 --> 00:01:33,090
of a negative outcome or consequences.

33
00:01:33,090 --> 00:01:35,670
It'd be awesome if the
positive thing happened,

34
00:01:35,670 --> 00:01:37,620
but we're really concerned with is, okay,

35
00:01:37,620 --> 00:01:39,180
but what if it doesn't work out?

36
00:01:39,180 --> 00:01:42,393
What would be the negative
outcome or consequence?

37
00:01:43,410 --> 00:01:45,360
The negative risk is also a function

38
00:01:45,360 --> 00:01:47,280
of likelihood and impact.

39
00:01:47,280 --> 00:01:49,350
The likelihood or probability

40
00:01:49,350 --> 00:01:52,530
of the chance of a particular
risk event occurring,

41
00:01:52,530 --> 00:01:56,850
and impact being the measure
of the magnitude of harm.

42
00:01:56,850 --> 00:01:59,730
So likelihood and impact.

43
00:01:59,730 --> 00:02:01,770
Now, there are a number of factors

44
00:02:01,770 --> 00:02:04,080
that influence likelihood and impact.

45
00:02:04,080 --> 00:02:07,380
Threat, the vulnerability,
the control strength,

46
00:02:07,380 --> 00:02:12,380
the risk volatility, the risk
velocity, and cascading risk.

47
00:02:13,170 --> 00:02:14,910
The threat could be adversarial.

48
00:02:14,910 --> 00:02:17,340
We've talked a lot about
our adversarial threats,

49
00:02:17,340 --> 00:02:19,140
or they could be non-adversarial.

50
00:02:19,140 --> 00:02:20,310
Where non-adversarial means

51
00:02:20,310 --> 00:02:21,750
we don't really have an opponent.

52
00:02:21,750 --> 00:02:23,940
But non-adversarial could be, for example,

53
00:02:23,940 --> 00:02:25,473
a weather related issue.

54
00:02:26,340 --> 00:02:30,990
Vulnerabilities are inherent
or unmitigated weaknesses.

55
00:02:30,990 --> 00:02:33,360
The control strength is
how strong our controls,

56
00:02:33,360 --> 00:02:36,330
and how much work factors
required to bypass

57
00:02:36,330 --> 00:02:37,863
or get through our controls.

58
00:02:39,090 --> 00:02:40,500
Then we have risk volatility,

59
00:02:40,500 --> 00:02:42,570
which is the variance of conditions,

60
00:02:42,570 --> 00:02:45,570
and risk velocity, which
is the speed of impact.

61
00:02:45,570 --> 00:02:48,270
If this thing happened,
how fast would it happen?

62
00:02:48,270 --> 00:02:50,220
And then cascading risk

63
00:02:50,220 --> 00:02:54,390
is all about a chain reaction of events.

64
00:02:54,390 --> 00:02:56,010
So we've already talked about threats

65
00:02:56,010 --> 00:02:57,360
and vulnerabilities and controls.

66
00:02:57,360 --> 00:03:00,513
Let's talk a little bit about
velocity and volatility.

67
00:03:01,620 --> 00:03:05,430
Volatility describes the extent
to which the level of risk

68
00:03:05,430 --> 00:03:07,950
is likely to change over time.

69
00:03:07,950 --> 00:03:10,830
So low-risk volatility
means that the level of risk

70
00:03:10,830 --> 00:03:14,250
is relatively stable and
it's predictable over time.

71
00:03:14,250 --> 00:03:17,220
But high-risk volatility
means that the level of risk

72
00:03:17,220 --> 00:03:20,313
is likely to fluctuate
significantly over time.

73
00:03:21,930 --> 00:03:24,540
Risk velocity means how fast an exposure

74
00:03:24,540 --> 00:03:26,463
can impact an organization.

75
00:03:27,752 --> 00:03:29,940
Now, risk velocity is the time that passes

76
00:03:29,940 --> 00:03:31,770
between the occurrence of an event

77
00:03:31,770 --> 00:03:33,690
and the point at which the organization

78
00:03:33,690 --> 00:03:35,640
first feels its effect.

79
00:03:35,640 --> 00:03:37,410
When the velocity is low,

80
00:03:37,410 --> 00:03:40,470
there's time to detect and respond.

81
00:03:40,470 --> 00:03:43,080
But when the velocity is very high,

82
00:03:43,080 --> 00:03:45,570
detection and response
are much more challenging

83
00:03:45,570 --> 00:03:48,093
because you have such
a small, small window.

84
00:03:49,740 --> 00:03:52,200
And then cascading risk is a principle

85
00:03:52,200 --> 00:03:56,010
that often risks are linked
and failing to address one risk

86
00:03:56,010 --> 00:03:59,163
could cause a chain reaction or a cascade.

87
00:04:00,450 --> 00:04:03,300
Cascading risk is divided
into three categories.

88
00:04:03,300 --> 00:04:07,020
Parallel risk, serial
risk, and mixed risk.

89
00:04:07,020 --> 00:04:09,330
Where mixed risk refers to the combination

90
00:04:09,330 --> 00:04:10,830
of parallel and serial.

91
00:04:10,830 --> 00:04:13,890
So parallel is things
happening at the same time.

92
00:04:13,890 --> 00:04:16,170
Serial is one after another.

93
00:04:16,170 --> 00:04:19,143
Mixed risk is really the
combination of the two.

94
00:04:21,630 --> 00:04:23,790
Now, many organizations have what's known

95
00:04:23,790 --> 00:04:25,950
as a risk appetite statement,

96
00:04:25,950 --> 00:04:29,220
and very often it is a
compliance requirement.

97
00:04:29,220 --> 00:04:31,290
Risk appetite is the level of risk

98
00:04:31,290 --> 00:04:34,980
that an organization is
comfortable engaging in,

99
00:04:34,980 --> 00:04:36,990
but it's never just one level of risk

100
00:04:36,990 --> 00:04:39,000
because there's all kinds
of different risks, right?

101
00:04:39,000 --> 00:04:41,400
There is strategic risk, compliance risk,

102
00:04:41,400 --> 00:04:44,340
cybersecurity risk, capital
risk, financial risk,

103
00:04:44,340 --> 00:04:48,720
transactional risk, ESG risk,
and the list goes on and on.

104
00:04:48,720 --> 00:04:51,990
So generally, a risk
appetite will be determined

105
00:04:51,990 --> 00:04:55,290
for each of those
different risk categories.

106
00:04:55,290 --> 00:04:58,110
So again, there are multiple
categories of business risk,

107
00:04:58,110 --> 00:05:00,600
including strategic,
reputational, operational,

108
00:05:00,600 --> 00:05:04,800
financial, compliance, ESG,
capital, and resilience.

109
00:05:04,800 --> 00:05:07,950
Now, the board of directors or equivalent

110
00:05:07,950 --> 00:05:11,790
will determine the risk appetite
on a per category basis,

111
00:05:11,790 --> 00:05:14,460
and then they'll publish
the risk appetite statement

112
00:05:14,460 --> 00:05:16,980
for use by the organization.

113
00:05:16,980 --> 00:05:18,990
And it is really, really useful

114
00:05:18,990 --> 00:05:22,200
because that lets management
know the level of risk

115
00:05:22,200 --> 00:05:24,420
that the organization is willing to take

116
00:05:24,420 --> 00:05:25,410
in these different areas.

117
00:05:25,410 --> 00:05:27,333
Remember, the level of uncertainty.

118
00:05:29,670 --> 00:05:32,790
Now, there tends to be three
risk appetite approaches.

119
00:05:32,790 --> 00:05:36,030
Expansive, conservative, and neutral.

120
00:05:36,030 --> 00:05:38,670
Expansive risk appetite
indicates a willingness

121
00:05:38,670 --> 00:05:41,970
to take on a high degree of risk

122
00:05:41,970 --> 00:05:44,310
in pursuit of significant gains.

123
00:05:44,310 --> 00:05:46,290
Now, that might be
investing in new ventures,

124
00:05:46,290 --> 00:05:48,000
pursuing aggressive strategies,

125
00:05:48,000 --> 00:05:49,773
or taking on significant debt.

126
00:05:50,850 --> 00:05:54,060
Conservative risk appetite
indicates a preference

127
00:05:54,060 --> 00:05:56,160
for more low-risk activities,

128
00:05:56,160 --> 00:05:59,610
and a focus on preserving
money, preserving wealth,

129
00:05:59,610 --> 00:06:01,353
and minimizing losses.

130
00:06:02,650 --> 00:06:03,960
A neutral risk appetite

131
00:06:03,960 --> 00:06:07,140
falls somewhere in between
expansive and conservative,

132
00:06:07,140 --> 00:06:09,660
with a focus on balancing risk

133
00:06:09,660 --> 00:06:13,980
and reward in pursuit of
long-term stability and growth.

134
00:06:13,980 --> 00:06:17,760
And of course, the organization's
strategic objectives.

135
00:06:17,760 --> 00:06:22,760
Now, these will be determined
on a per risk category basis.

136
00:06:23,400 --> 00:06:26,220
So it is very likely an organization

137
00:06:26,220 --> 00:06:29,460
could be expansive one area,
conservative in another area,

138
00:06:29,460 --> 00:06:31,743
and neutral yet in other areas.

139
00:06:34,320 --> 00:06:37,170
Risk management implies
that actions are being taken

140
00:06:37,170 --> 00:06:41,010
to either mitigate the impact
of an unfavorable outcome,

141
00:06:41,010 --> 00:06:44,613
and, or enhance the likelihood
of a positive outcome.

142
00:06:45,510 --> 00:06:48,330
Now, every organization really
has to manage risk, right?

143
00:06:48,330 --> 00:06:50,010
And they manage risk in alignment

144
00:06:50,010 --> 00:06:52,050
with their strategic objectives,

145
00:06:52,050 --> 00:06:54,390
their compliance and legal requirements,

146
00:06:54,390 --> 00:06:57,030
and their risk appetite.

147
00:06:57,030 --> 00:07:00,030
Now, risk tolerance is
an acceptable variation

148
00:07:00,030 --> 00:07:03,360
in outcomes related to
specific performance measures.

149
00:07:03,360 --> 00:07:05,040
There's a lot of confusion
about risk tolerance.

150
00:07:05,040 --> 00:07:08,280
Sometimes it gets conflated
with risk appetite.

151
00:07:08,280 --> 00:07:09,720
Risk tolerance always refers

152
00:07:09,720 --> 00:07:12,990
to when we have specific
performance measures about risk,

153
00:07:12,990 --> 00:07:17,130
how much variation or variance
can we have in that measure

154
00:07:17,130 --> 00:07:18,243
that we'll accept.

155
00:07:20,100 --> 00:07:23,370
And that my friends brings
us to a 3-Second Challenge.

156
00:07:23,370 --> 00:07:25,470
Five challenge questions,
three seconds each.

157
00:07:25,470 --> 00:07:26,303
Let's do it.

158
00:07:28,140 --> 00:07:32,163
The probability that an event
will occur. One, two, three.

159
00:07:33,450 --> 00:07:35,640
That's the likelihood, and
that's gonna be important

160
00:07:35,640 --> 00:07:38,700
when we start doing our risk assessments.

161
00:07:38,700 --> 00:07:41,250
Number two, uncertainty of outcome.

162
00:07:41,250 --> 00:07:43,533
What is that? One, two, three.

163
00:07:44,850 --> 00:07:46,980
And that is risk.

164
00:07:46,980 --> 00:07:50,730
Number three, measuring
the magnitude of harm.

165
00:07:50,730 --> 00:07:53,973
One, two, three. That's impact.

166
00:07:55,530 --> 00:07:57,930
Number four, how fast an exposure

167
00:07:57,930 --> 00:08:00,300
can impact an organization.

168
00:08:00,300 --> 00:08:04,623
One, two, three. That's gonna be velocity.

169
00:08:05,550 --> 00:08:08,850
I always think a roadrunner
going through velocity.

170
00:08:08,850 --> 00:08:11,730
And number five, risk appetite approach

171
00:08:11,730 --> 00:08:15,570
that indicates a preference
for low-risk activities.

172
00:08:15,570 --> 00:08:17,520
One, two, three.

173
00:08:17,520 --> 00:08:19,773
And that's gonna be a
conservative approach.

174
00:08:21,240 --> 00:08:23,340
Let's do a Security-in-Action.

175
00:08:23,340 --> 00:08:26,730
Put our knowledge into use
about a risk appetite statement.

176
00:08:26,730 --> 00:08:29,880
You recently learned that
the non-profit you work for

177
00:08:29,880 --> 00:08:32,220
doesn't have a risk appetite statement.

178
00:08:32,220 --> 00:08:34,830
Now you'd like to approach management

179
00:08:34,830 --> 00:08:36,483
and explain the benefits.

180
00:08:37,590 --> 00:08:39,150
So what might you tell them?

181
00:08:39,150 --> 00:08:41,553
Okay, so you're working for a non-profit,

182
00:08:42,480 --> 00:08:44,850
doesn't have a risk appetite statement,

183
00:08:44,850 --> 00:08:45,870
you'd love the guidance

184
00:08:45,870 --> 00:08:48,240
that a risk appetite
statement could provide.

185
00:08:48,240 --> 00:08:52,230
So you wanna approach management
and explain the benefits.

186
00:08:52,230 --> 00:08:54,750
And my question to you is,
what might you tell them

187
00:08:54,750 --> 00:08:56,490
about a a risk appetite statement?

188
00:08:56,490 --> 00:08:57,510
Go ahead and put me on pause

189
00:08:57,510 --> 00:08:59,823
and jot down some notes
about the benefits.

190
00:09:02,730 --> 00:09:05,580
Well, a risk appetite
statement provides a framework

191
00:09:05,580 --> 00:09:08,760
for decision-making and
risk management strategies.

192
00:09:08,760 --> 00:09:11,160
And some of the benefits include,

193
00:09:11,160 --> 00:09:13,323
it provides clarity and direction,

194
00:09:14,190 --> 00:09:16,140
it supports our risk
management activities,

195
00:09:16,140 --> 00:09:18,450
so we can say, okay, "We can do X, Y, Z,"

196
00:09:18,450 --> 00:09:22,413
because this is the risk
appetite in a particular level.

197
00:09:23,760 --> 00:09:27,240
And it demonstrates
transparency from the top down

198
00:09:27,240 --> 00:09:29,310
and says, "This is what
we're willing to do,"

199
00:09:29,310 --> 00:09:31,080
and it builds trust, right?

200
00:09:31,080 --> 00:09:33,247
Because at the top we've said,

201
00:09:33,247 --> 00:09:34,350
"This is what we're willing to do,

202
00:09:34,350 --> 00:09:37,050
and we're gonna allow you to implement

203
00:09:37,050 --> 00:09:39,930
to these various risk appetite levels."

204
00:09:39,930 --> 00:09:41,610
It's great having a
risk appetite statement.

205
00:09:41,610 --> 00:09:43,500
A lot of organizations don't.

206
00:09:43,500 --> 00:09:46,230
If yours doesn't, you may
wanna follow up on this.

207
00:09:46,230 --> 00:09:49,980
Doing so would be Security-in-Action.

208
00:09:49,980 --> 00:09:51,180
There's your word cloud.

209
00:09:51,180 --> 00:09:54,510
Make sure you've got these
really foundational concepts down

210
00:09:54,510 --> 00:09:55,830
before moving on.

211
00:09:55,830 --> 00:09:58,223
But when you're ready, I'll
see you the next lesson.
