Browse Definitions :
Definition

business risk

A risk, in a business context, is anything that threatens an organization's ability to generate profits at its target levels; in the long term, risks can threaten an organization's sustainability.

Business risks are broadly categorized as pure risks, which are negative events over which the organization has no control, and speculative risks, which are potential effects of actions taken and choices made that may have positive and/or negative effects. Another model categorizes business risks as internal (resulting from events with the organization) and external (resulting from events occurring outside the organization).

According to security expert Shon Harris, once a business risk has been identified, an organization has four options: transfer it, avoid it, reduce it or accept it.

Risk analysis programs are designed to help an organization deal as effectively as possible with existing or potential threats. The four main elements of risk analysis are:

  • Identifying corporate assets and assessing their value.
  • Identifying vulnerabilities and threats to the security of those assets.
  • Quantifying the probability of those threats and their potential impact on the business.
  • Compare the potential economic impact of the threat versus the cost of the countermeasures required to protect the organization from it.

See also: Types of enterprise risk

 

This was last updated in October 2014

Continue Reading About business risk

Networking
  • voice over LTE (VoLTE)

    Voice over LTE (VoLTE) is a digital packet technology that uses 4G LTE networks to route voice traffic and transmit data.

  • ONOS (Open Network Operating System)

    Open Network Operating System (ONOS) is an OS designed to help network service providers build carrier-grade software-defined ...

  • telematics

    Telematics is a term that combines the words telecommunications and informatics to describe the use of communications and IT to ...

Security
  • three-factor authentication (3FA)

    Three-factor authentication (3FA) is the use of identity-confirming credentials from three separate categories of authentication ...

  • cyber espionage

    Cyber espionage (cyberespionage) is a type of cyber attack that malicious hackers carry out against a business or government ...

  • role-based access control (RBAC)

    Role-based access control (RBAC) is a method of restricting network access based on the roles of individual users within an ...

CIO
  • project charter

    A project charter is a formal short document that states a project exists and provides project managers with written authority to...

  • leadership

    Leadership is the ability of an individual or a group of people to influence and guide followers or members of an organization, ...

  • transaction

    In computing, a transaction is a set of related tasks treated as a single action.

HRSoftware
  • employee engagement

    Employee engagement is the emotional and professional connection an employee feels toward their organization, colleagues and work.

  • talent pool

    A talent pool is a database of job candidates who have the potential to meet an organization's immediate and long-term needs.

  • diversity, equity and inclusion (DEI)

    Diversity, equity and inclusion is a term used to describe policies and programs that promote the representation and ...

Customer Experience
  • sales development representative (SDR)

    A sales development representative (SDR) is an individual who focuses on prospecting, moving and qualifying leads through the ...

  • service level indicator

    A service level indicator (SLI) is a metric that indicates what measure of performance a customer is receiving at a given time.

  • customer data platform (CDP)

    A customer data platform (CDP) is a type of software application that provides a unified platform of customer information that ...

Close