Compliance & frameworks

What is Cyber Risk Management?

A plain-language guide to cyber risk management, covering the main frameworks, real-world breaches and the steps that turn cyber threats into ranked, owned decisions.

Key takeaways
  • Cyber risk management is the ongoing work of finding, ranking and reducing the cyber threats that could harm your organisation.
  • Every framework follows the same four stages, identify, assess, treat and monitor.
  • The NIST Cybersecurity Framework (CSF) and the NIST Risk Management Framework (RMF) are different tools and should not be confused.
  • The four ways to treat a risk are to reduce it, transfer it, accept it or avoid the activity behind it.
  • The average data breach now costs 4.99 million US dollars worldwide, a record, per the IBM Cost of a Data Breach Report 2026.
  • Supplier compromise is the single costliest factor in a breach, per the same report, which puts third-party risk near the centre.
  • NIS2 and Sweden’s Cybersäkerhetslagen make the board, not just IT, accountable, with fines up to 10 million euros or 2% of turnover.
  • The Miljödata attack exposed data on 2.2 million people through one supplier and drew a GDPR fine, showing how concentration and supplier risk compound.
  • A cyber risk assessment produces a ranked risk register with a named owner for each risk.
  • Risk management is a continuous programme, because assets, threats and rules keep changing.

Cyber Risk Management, Defined

Cyber risk management is the ongoing discipline of finding the cyber threats that could harm your organisation working out how likely and how damaging each one is and then reducing each to a level the business is willing to accept. It turns a vague sense of danger into ranked decisions with clear owners.

For most of its history cybersecurity was treated as a technical job for the IT team. That has changed. Under NIS2 and Sweden’s Cybersäkerhetslagen the board itself is now accountable for cyber risk and a serious incident lands as a legal and financial problem, not only an operational one.

The numbers explain the shift. The average data breach now costs 4.99 million US dollars worldwide, a record, according to the IBM Cost of a Data Breach Report 2026. Cybersecurity risk management is how you decide where a finite budget goes so the biggest exposures are covered first. In larger organisations it is also the core of what is called GRC or governance, risk and compliance.

How Cyber Risk Management Works

Every cyber risk management framework, whatever its name, is built on the same four stages. Learn the cycle once and any framework becomes easier to read.

How Cyber Risk Management Works
  • Identify: Map what you have and what could go wrong. List the systems, data and suppliers that matter, then the threats and weaknesses that could hit them.
  • Assess: Work out how likely each risk is and how much damage it would do then score and rank them so the worst rise to the top.
  • Treat: Decide what to do about each risk. The four options are to reduce it, transfer it, accept it or avoid the activity that causes it.
  • Monitor: Keep watching because assets, threats and the business all change. A risk assessment is a living record rather than a one-off report.

The reason this now needs its own discipline is scale. Cloud services, remote work, third-party software and AI have widened the attack surface faster than most teams can track by hand and regulators expect the work to be continuous rather than an annual audit.

Cyber Risk Management Frameworks

You do not have to invent a method. Several established frameworks give you a ready structure and most organisations combine two or three. The trick is knowing what each one is for.

  • NIST Cybersecurity Framework (CSF) 2.0: A voluntary framework of six functions, Govern, Identify, Protect, Detect, Respond and Recover published by NIST in 2024. Its new Govern function puts board-level risk ownership at the heart of security which makes it good for organising a whole programme.
  • NIST Risk Management Framework (RMF): The seven-step process in NIST SP 800-37, Prepare, Categorize, Select, Implement, Assess, Authorize and Monitor. It is more detailed and control-driven than the CSF and common where systems must be formally authorised to operate. This is usually what people mean by the NIST cyber risk management framework and it is not the same thing as the CSF.
  • ISO/IEC 27001 and 27005: ISO 27001 is the certifiable standard for a risk-based information security management system and ISO 27005 is its companion guide for the risk work itself. Useful when you need independent proof for customers or auditors.
  • FAIR: Factor Analysis of Information Risk, a quantitative model that expresses a risk as a probable financial loss rather than a high, medium or low label. Useful for putting a currency figure in front of a board.
  • ISO 31000 and COSO ERM: The broader enterprise risk management frameworks that sit above the cyber-specific ones so cyber risk is reported in the same language as financial and operational risk.

None of these is a checklist you finish. They are structures for the four-stage cycle and the right choice depends on your sector, your size and what your regulators and customers ask you to prove.

The Business Impact of Getting It Wrong

Weak cyber risk management does not show up on a balance sheet until something breaks. When it does, the cost arrives on several fronts at once.

  • Direct breach cost: The global average is now 4.99 million US dollars per breach, a record and up 12% in a year, per the IBM Cost of a Data Breach Report 2026. That covers investigation, recovery, lost business and legal work.
  • Regulatory fines: Under NIS2 and Cybersäkerhetslagen, essential entities face fines of up to 10 million euros or 2% of global turnover. GDPR and DORA carry their own penalties on top.
  • Downtime: Breaches now take a mean of 247 days to identify and contain, per the same IBM report, and revenue can stall for the worst of that stretch.
  • Personal liability: NIS2 Article 20 makes the board not just the IT team, accountable for cyber risk.
  • Supply-chain damage: IBM found supplier compromise to be the single costliest factor in a breach so a weak vendor can become your loss.

Risk management is the work that keeps these costs off your books. It will not remove every threat but it makes sure the money and effort you do spend land on the exposures most likely to hurt.

Real-World Cases

Four incidents show what unmanaged risk looks like in practice. Each traces back to a risk that could have been found and treated first.

Equifax and the Patch That Was Never Applied

The 2017 breach of the US credit agency Equifax began with a flaw in Apache Struts, a piece of web software. Apache had released a patch on 7 March that year and Equifax’s own security team had circulated an internal instruction to install it.

The patch was never applied to the online dispute portal. Attackers used the opening and moved through the network undetected for about 76 days, taking the personal data of roughly 147 million people.

The US Government Accountability Office later documented the basic failures behind it and Equifax settled with the FTC, the CFPB and 50 US states and territories for up to 700 million US dollars. The control that would have prevented it was mundane. Patch a known critical vulnerability quickly and confirm the fix is in place. A risk you have already spotted but left untreated is the most dangerous kind.

Change Healthcare and a Missing Second Factor

Change Healthcare processes about one in three medical claims in the United States. In February 2024 attackers logged into a remote-access portal using stolen credentials. The portal had no multi-factor authentication so a single password was enough.

Nine days later the ALPHV/BlackCat group launched ransomware across the systems. The company paid a 22 million US dollar ransom and because so much of US healthcare ran through this one provider, pharmacies and clinics felt the disruption for weeks.

In testimony to the US Congress the chief executive confirmed the missing multi-factor authentication and the US Department of Health and Human Services put the number of people affected at around 190 million. Two lessons stand out. Multi-factor authentication belongs on every external system and a supplier that everyone depends on is a concentration risk that has to be managed as one.

Miljödata and the Risk Inside a Supplier

Cyber risk management _Real-World Cases

In August 2025 Miljödata, a Swedish company whose HR and sick-leave software is used by around 80% of the country’s municipalities was hit by ransomware. The attackers got in through an outdated firewall component whose weaknesses were already public knowledge.

Because so many bodies relied on the same supplier, the incident reached more than 200 municipalities and regions. The Swedish data protection authority, IMY, later put the number of people whose data was exposed at 2.2 million, close to a fifth of Sweden.

In September 2026 IMY fined Miljödata SEK 1.8 million for failing to meet the security duty in GDPR Article 32. For every organisation that used the software, the lesson is that a supplier’s weakness is your risk too and that leaning the whole public sector on one vendor turns a single break-in into a national event.

Maersk and a Network With No Internal Walls

In June 2017 the shipping giant Maersk was caught in NotPetya, destructive malware that governments including the United States and the United Kingdom attributed to the Russian military. It spread across Maersk’s network in hours and wiped most of its computers and servers.

The malware moved so fast because the internal network was flat with few barriers to stop one infected machine reaching thousands. Maersk put the cost at around 250 to 300 million US dollars.

Recovery reportedly came down to a single server in an office in Ghana that had been offline during the attack and so kept a clean copy of key data. That was fortunate rather than planned. The controls that make recovery dependable are network segmentation to contain the spread and tested, isolated backups.

Cyber Risk Management and Compliance

In Europe cyber risk management is no longer only good practice. Several regimes now require it and each expects documented risk work rather than good intentions.

  • NIS2 and Cybersäkerhetslagen: NIS2 Article 21 requires risk-management measures covering monitoring, incident handling, business continuity, supply-chain security and staff training. Article 20 makes the board personally accountable. Sweden’s version, Cybersäkerhetslagen (SFS 2025:1506), has been in force since 15 January 2026 and is supervised by MCF (formerly MSB) with fines up to 10 million euros or 2% of global turnover.
  • DORA: For financial entities, DORA (Regulation 2022/2554) which applies from 17 January 2025, requires a formal ICT risk-management framework under Articles 5 and 6 with the management body accountable. In Sweden it is supervised by Finansinspektionen.
  • GDPR: GDPR Article 32 requires security measures appropriate to the risk. The Miljödata fine was issued under this article which shows that a regulator can treat weak risk management as a breach in itself.
  • ISO/IEC 27001: ISO 27001 certification is the usual way to prove a working risk-based security programme to customers and auditors and is often a condition of enterprise contracts.

The common thread is that all four ask you to identify your risks, act on them in proportion and be able to show your working. A risk register and a clear owner are the evidence each one wants to see.

How to Run a Cyber Risk Assessment

A cyber risk assessment is the practical heart of the whole discipline. It is how you turn a vague wish to be more secure into a ranked list of specific risks with owners. You can run a first pass in a workshop and refine it over time.

  1. Inventory what matters: List your important systems, data and suppliers. You cannot protect or rank what you have not written down.
  2. Identify the threats: For each asset, ask what could go wrong from ransomware and phishing to a supplier outage or a lost laptop.
  3. Score likelihood and impact: Rate how probable each risk is and how much harm it would do. A simple high, medium and low scale works to start and a quantitative model like FAIR adds a financial figure later.
  4. Rank and record: Put every risk in a register, sorted worst first each with a named owner and a planned response.
  5. Set your risk appetite: Agree with the board how much risk is acceptable so a decision to treat or accept a risk is deliberate.

Two honest warnings. Scoring is partly a judgement call so involve people who know the business, not only the IT team. And an assessment goes stale the moment it is filed because assets and threats keep changing. NIS2 Article 21 expects you to keep checking that your measures still work which is why the monitoring stage of the cycle never really ends.

How to Build a Cyber Risk Management Strategy

A cyber risk management strategy is what keeps the four-stage cycle running instead of stalling after the first assessment. It rests on people, process and technology and none of the three works alone.

How to Build a Cyber Risk Management Strategy
  • Give it an owner at board level: Cyber risk is a board responsibility under NIS2 so name who is accountable and report to them regularly. Where that seniority is missing in-house, a virtual CISO can carry it.
  • Pick a framework and stick to it: Choose the NIST CSF, ISO 27001 or another that fits so your work has a common structure auditors recognise.
  • Prioritise by business impact: Fix the risks that threaten your most important systems and data first not whichever alert is loudest.
  • Manage suppliers as part of your risk: Know which vendors hold your data, track their security and plan for one of them being breached.
  • Treat, transfer, accept or avoid on purpose: For each significant risk make a deliberate choice, whether that is a new control, cyber insurance, documented acceptance or dropping the activity.
  • Monitor continuously and rehearse recovery: Watch for change, run continuous vulnerability management, test your backups and rehearse your incident response before you need it.

Done well, this is a programme, not a project. It will not make you immune but it means that when something does go wrong you have already decided who acts, what matters most and how you recover.

Myths & Facts

Myth

Cyber risk management is just an IT problem.

We are too small to need it.

Buying more security tools manages our risk.

A one-off risk assessment is enough.

The NIST CSF and the NIST RMF are the same thing.

If we get breached, cyber insurance covers it.

Fact

Under NIS2 and Cybersäkerhetslagen the board is personally accountable for cyber risk. It is a governance and business issue, not only a technical one.

Attackers target the weakest link, and many rules catch smaller firms through supply chains. Miljödata's breach spread to hundreds of bodies that were not the original target.

Tools help, but risk management is a process of finding, ranking and treating risks. Most breaches trace back to gaps like a missing patch or absent MFA, not a lack of products.

Assets, threats and rules change constantly, so an assessment goes stale. NIS2 expects continuous monitoring and regular re-assessment, not an annual tick-box.

They are different. The CSF is a voluntary six-function framework for organising a programme, while the RMF is a seven-step process for authorising specific systems.

Insurance can transfer some financial loss, but it does not restore operations, reputation or regulatory standing. Transfer is only one of four ways to treat a risk.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. Your team is told that a critical vulnerability has been found in a piece of software you run, and a patch is already available.

    What do you do first?

    • Schedule the patch for the next quarterly maintenance window
    • Apply the patch to affected systems as a priority and confirm it is done
    • Wait to see if anyone actually exploits it
  2. You discover that one of your external remote-access portals lets staff log in with just a username and password.

    What is the priority fix?

    • Enforce multi-factor authentication on the portal
    • Ask staff to choose longer passwords
    • Note it in the risk register and move on
  3. A supplier that stores your employee data has just announced a ransomware breach.

    What should your risk management plan already have prepared?

    • Nothing, because their breach is their responsibility
    • A record of what data they hold and a response plan for a supplier breach
    • A request for them to pay any fines you receive
  4. Ransomware has started spreading from one infected laptop across your office network.

    Which earlier decision limits the damage most?

    • Having a flat network so everything can reach everything
    • Segmenting the network and keeping tested, isolated backups
    • Hoping a backup server happens to be switched off

Knowledge Test

  1. What are the four stages of the cyber risk management cycle?

    • Buy, install, update, replace
    • Identify, assess, treat, monitor
    • Detect, alert, report, close
    • Plan, build, launch, review

    Every framework is a version of identify, assess, treat and monitor.

  2. How many core functions does the NIST Cybersecurity Framework 2.0 have?

    • Four
    • Five
    • Six
    • Seven

    CSF 2.0 has six functions, adding Govern to Identify, Protect, Detect, Respond and Recover.

  3. Which of these is a recognised way to treat a cyber risk?

    • Ignore it
    • Transfer it
    • Hide it
    • Duplicate it

    The four options are to reduce, transfer, accept or avoid a risk.

  4. Under NIS2 and Cybersäkerhetslagen, who is accountable for cyber risk?

    • The IT department alone
    • The management body or board
    • The external auditor
    • The software supplier

    NIS2 Article 20 places responsibility and personal accountability on the board.

  5. What is the main purpose of a risk register?

    • To store passwords
    • To rank risks and assign owners
    • To log completed patches
    • To replace insurance

    A risk register ranks risks worst first and gives each a named owner and planned response.

  6. Roughly what is the global average cost of a data breach in 2026?

    • Half a million US dollars
    • About 5 million US dollars
    • About 50 million US dollars
    • It cannot be measured

    The IBM Cost of a Data Breach Report 2026 put the global average at 4.99 million US dollars.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

People are part of every one of these frameworks for a reason. Phishing and stolen credentials remain among the most common ways attackers get in, and the Change Healthcare and Equifax cases both turned on ordinary lapses rather than exotic techniques.

NIS2 Article 21 explicitly lists security awareness training as a required measure. Treating your staff as a control, and giving them regular, realistic security awareness training, closes gaps that no tool can reach. It is one of the cheapest risk reductions available and one of the easiest to evidence for an auditor.

Frequently Asked Questions

What is cyber risk management?

Cyber risk management is the ongoing process of identifying the cyber threats to an organisation, assessing how likely and how damaging each is and then treating them to a level the business will accept. It covers people, process and technology, and it turns security from guesswork into ranked, documented decisions with clear owners.

What is the difference between the NIST Cybersecurity Framework and the NIST Risk Management Framework?

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary structure of six functions, Govern, Identify, Protect, Detect, Respond and Recover, for organising a whole security programme. The NIST Risk Management Framework (RMF), from SP 800-37, is a detailed seven-step process for selecting controls and formally authorising a system. They complement each other but are not the same.

Which cyber risk management framework should we use?

There is no single right answer, and most organisations combine a few. Use the NIST CSF or ISO 27001 to structure an overall programme, add FAIR when you need to express risk as a financial figure and let your sector, size and regulators guide the choice. ISO 27001 also gives you a certificate auditors and customers recognise.

How do you do a cyber risk assessment?

Start by listing the systems, data and suppliers that matter, then identify what could threaten each one. Score every risk for likelihood and impact, rank them worst first in a risk register and give each a named owner and a planned response. Agree a risk appetite with leadership, then review the assessment regularly because it dates quickly.

What are the four ways to treat a cyber risk?

There are four options. You can reduce the risk with new controls, transfer it to another party through insurance or a contract, accept it with documented sign-off when it is small enough or avoid it by stopping the activity that causes it. Every significant risk deserves a deliberate, recorded choice rather than a default.

Is cyber risk management a legal requirement in Sweden?

For many organisations, yes. NIS2, implemented in Sweden as Cybersäkerhetslagen since January 2026, requires risk-management measures and makes the board accountable. GDPR Article 32 demands security appropriate to the risk, and DORA sets ICT risk rules for financial firms. Even where no law names you directly, customer and insurer requirements often make it unavoidable.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.