Skip to main content
Back to Blog
May 13, 2026 by Arthur Mayoux GDPR & conformitate

What is the risk of compliance?

Risk management is essential to ISO27001, SOC2 and GDPR. Most teams treat it as a checkbox.

Open the risk register and you realize that it’s a spreadsheet that someone completed 18 months ago and has never touched it since then.

Sound familiar?

Before you can manage your risks, you need to understand what is actually a risk.

Risk = threat × vulnerability

In information security, a risk is not just “something bad that could happen.”

  • A threat: something dangerous or harmful that may occur (a cyber attack, a data leak, a fire in the server room).
  • A vulnerability: a weakness that could be exploited (no backups, no access control, no encryption).

Remove any of them and the risk disappears.

There is no risk of avalanche in central London.

An attacker without a point of entry is just a person sitting outside a locked building without doors.

This matters because most teams focus on threats without auditing their vulnerabilities or patches vulnerabilities without checking whether there really is a credible threat.

A concrete example

You say that one of your developers is leaving the company. No one revokes their access to GitHub. A potential threat: an unhappy former employee. A vulnerability: active credentials without expiration.

The resulting risk: Your code base is manipulated or shortened.

Component In this scenario
Threat Disgruntled ex-employee
Vulnerability Active credentials post-offboarding
Risk Code leakage or sabotage, reputational and contractual damage

Simple to write, but is it worth repairing?

Probability and Impact: The Two Questions That Really Matter

Let’s put numbers on this:

Each departure without proper take-off involves an estimated exposure of €20,000 (breach investigation, legal fees, customer notification). Probability that it happens badly: once every 4 years.

Annual loss (ALE): €5,000/year.

Cost of an automated identity management platform: €800/month = €9,600/year.

A €9,600/year tool to cover a risk of €5,000/year makes no sense.A better solution: a one-page offboarding checklist and a Slack reminder to IT.

A ransomware attack hits your infrastructure and you don’t have backups offline:

Component In this scenario
Threat Ransomware attack
Vulnerability No immutable backups
Risk Complete data loss, operations shutdown, ransom payment

Probability: Ransomware attacks on SMBs are growing every year.

Impact: The average ransom demand for a small company is around €80,000 – before making a week of interruptions, customer whining and potential GDPR fines.

Cost of a proper immutable backup solution: €200/month = €12,000 over 5 years.

This is a benefit of 488,000 euros over a five-year period.

The Four Ways to Deal with a Risk

Once you have assessed a risk, you have four options:

  1. Reduce it — implement a control (backup system, access policy, encryption).
  2. Transfer it - Get cyber security, use a SaaS that absorbs liability.
  3. Avoid it Stop the activity that creates the risk.
  4. Accept it - the document that you have made a conscious decision to live with it.

Most frameworks (ISO27001,SOC2) require you to choose one of these for each identified risk.

Why Compliance is Important

ISO27001 is built literally around risk management. the entire framework exists to allow you to identify your risks, evaluate them, and treat them systematically.

A compliance audit does not check if you have zero risks, but it checks if you have a rational process to understand and manage them.

This means that a risk register full of “high” ratings and no treatment decisions is worse than useless: it shows the auditor that you have identified problems and ignored them.

A practical starting point

Before the next audit, ask yourself:

  • Do we have a list of assets that matter? (data, systems, people, processes)
  • For each, what is the credible threat and where is the vulnerability?
  • Have we estimated the probability and impact, with real numbers?
  • Have I made an explicit decision on how to deal with each risk?

If the answer to any of these is “no really”, you don’t manage your risk as you should.


Scris de Arthur Mayoux
Arthur Mayoux write about operations, compliance programs and scaling security processes.
Portret Arthur Mayoux
ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert