Skip to main content

Residual risk: cybersecurity’s silent passenger

Published on August 30, 2018   26 min
0:00
Hello, everyone. Welcome to the next in the HS Talk series on cybersecurity. My name is Don Johnston. I'm a lawyer in Toronto, with the firm of Aird and Berlis, and I'm going to be speaking to you about residual risk in cybersecurity.
0:19
What is residual risk? Well, risk generally as we know is a fact of life and we all have to accept it in business. We really can't make money without assuming some risks. What residual risk is in a general sense is the risk that remains after you've taken steps to reduce, manage, or control your risk. You might, while traveling, reduce the risk of losing your personal belongings by simply not bringing them with you, but that doesn't mean that they're safe. Someone could break into your house at home and of course where else would your house be and take your stuff. You haven't eliminated your risk, you simply reduced it in some way or another.
0:60
In information technology, residual risk is the remaining risk after you've done your best to protect your system and your data from attacks, leaks, and losses of all kinds. You know that there is remaining risk. Indeed, when I draft agreements pertaining to information technology services, I'm always very careful to make sure that there is no guarantee in there that everything will be completely safe. It's just not possible.
Hide

Residual risk: cybersecurity’s silent passenger

Embed in course/own notes