What is the simplest useful definition of cyber risk?
The possibility that digital systems, data, suppliers or technology-dependent processes could create a consequence for an organizational objective or obligation.
Is cyber risk the same as cybersecurity?
No. Cybersecurity operates safeguards. Cyber-risk management uses evidence about exposure and safeguards to make ownership, priority, treatment and acceptance decisions.
Who owns cyber risk?
The accountable business or service leader owns the consequence and treatment decision. Technical and specialist teams provide evidence and operate controls.
What should a risk statement include?
A cause or initiating event, the affected service or objective, and a meaningful business consequence.
Does every vulnerability belong in the risk register?
No. Vulnerabilities may support a material risk scenario or remain in an operational issue process. A risk register should focus on decision-relevant exposure.
What is residual risk?
The exposure that remains after safeguards and treatment are considered, including uncertainty about how well they work.
How often should risk be reviewed?
At a scheduled interval proportionate to importance, and earlier after material change, incidents, supplier changes, failed controls or expired decisions.
Can the toolkit be used as a compliance program?
No. The toolkit is educational and generic. Specific legal, contractual, regulatory and framework obligations require tailored analysis.
Does the site provide incident response?
No. Use authorized organizational and professional resources for active incidents.
Where is scenario-planner data stored?
The planner runs in the browser and does not submit fields to this website or create a server-side backup.