Risk Mitigation
Pronunciation: RISK mih-tih-GAY-shun
Definition
Risk Mitigation is a measurable uncertainty or exposure that applies controls or changes that reduce the likelihood, impact, duration, or detectability of an adverse risk scenario. Risk Mitigation must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Risk Mitigation to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.
Overview
Risk mitigation changes exposure while allowing the underlying activity to continue. Measures may prevent events, limit damage, improve detection, shorten recovery, reduce concentration, or create barriers that make exploitation more difficult.
A control can reduce one dimension while increasing cost, complexity, privacy impact, latency, or dependency risk. Claimed mitigation should be based on evidence of design, coverage, and operating effectiveness rather than the existence of a policy or tool.
Treatment plans should identify the scenario, control owner, target residual risk, resources, deadline, dependencies, and validation method. After implementation, organizations should test effectiveness, monitor exceptions, reassess introduced risks, and update acceptance decisions when evidence differs from expectations.
Risk Mitigation is a measurable uncertainty or exposure that applies controls or changes that reduce the likelihood, impact, duration, or detectability of an adverse risk scenario. Risk mitigation is successful only when implemented controls demonstrably reduce defined exposure without creating unmanaged secondary risk.
For Risk Mitigation, the assessment should evaluate a measurable uncertainty or exposure that applies controls or changes that reduce the likelihood, impact, duration, or detectability of an adverse risk scenario. The assessment record should separate observed evidence supporting a measurable uncertainty or exposure that applies controls or changes that reduce the likelihood, impact, duration, or detectability of an adverse risk scenario from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in a measurable uncertainty or exposure that applies controls or changes that reduce the likelihood, impact, duration, or detectability of an adverse risk scenario have changed enough to require a new rating, treatment, or approval.
Key Takeaway
Risk mitigation is successful only when implemented controls demonstrably reduce defined exposure without creating unmanaged secondary risk.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)