What is the risk of compliance?
Risk management is essential to ISO27001, SOC2 and GDPR. Most teams treat it as a checkbox.
Open the risk register and you realize that it’s a spreadsheet that someone completed 18 months ago and has never touched it since then.
Sound familiar?
Before you can manage your risks, you need to understand what is actually a risk.
Risk = threat × vulnerability
In information security, a risk is not just “something bad that could happen.”
- A threat: something dangerous or harmful that may occur (a cyber attack, a data leak, a fire in the server room).
- A vulnerability: a weakness that could be exploited (no backups, no access control, no encryption).
Remove any of them and the risk disappears.
There is no risk of avalanche in central London.
An attacker without a point of entry is just a person sitting outside a locked building without doors.
This matters because most teams focus on threats without auditing their vulnerabilities or patches vulnerabilities without checking whether there really is a credible threat.
A concrete example
You say that one of your developers is leaving the company. No one revokes their access to GitHub. A potential threat: an unhappy former employee. A vulnerability: active credentials without expiration.
The resulting risk: Your code base is manipulated or shortened.
| Component | In this scenario |
|---|---|
| Threat | Disgruntled ex-employee |
| Vulnerability | Active credentials post-offboarding |
| Risk | Code leakage or sabotage, reputational and contractual damage |
Simple to write, but is it worth repairing?
Probability and Impact: The Two Questions That Really Matter
Let’s put numbers on this:
Each departure without proper take-off involves an estimated exposure of €20,000 (breach investigation, legal fees, customer notification). Probability that it happens badly: once every 4 years.
Annual loss (ALE): €5,000/year.
Cost of an automated identity management platform: €800/month = €9,600/year.
A €9,600/year tool to cover a risk of €5,000/year makes no sense.A better solution: a one-page offboarding checklist and a Slack reminder to IT.
A ransomware attack hits your infrastructure and you don’t have backups offline:
| Component | In this scenario |
|---|---|
| Threat | Ransomware attack |
| Vulnerability | No immutable backups |
| Risk | Complete data loss, operations shutdown, ransom payment |
Probability: Ransomware attacks on SMBs are growing every year.
Impact: The average ransom demand for a small company is around €80,000 – before making a week of interruptions, customer whining and potential GDPR fines.
Cost of a proper immutable backup solution: €200/month = €12,000 over 5 years.
This is a benefit of 488,000 euros over a five-year period.
The Four Ways to Deal with a Risk
Once you have assessed a risk, you have four options:
- Reduce it — implement a control (backup system, access policy, encryption).
- Transfer it - Get cyber security, use a SaaS that absorbs liability.
- Avoid it Stop the activity that creates the risk.
- Accept it - the document that you have made a conscious decision to live with it.
Most frameworks (ISO27001,SOC2) require you to choose one of these for each identified risk.
Why Compliance is Important
ISO27001 is built literally around risk management. the entire framework exists to allow you to identify your risks, evaluate them, and treat them systematically.
A compliance audit does not check if you have zero risks, but it checks if you have a rational process to understand and manage them.
This means that a risk register full of “high” ratings and no treatment decisions is worse than useless: it shows the auditor that you have identified problems and ignored them.
A practical starting point
Before the next audit, ask yourself:
- Do we have a list of assets that matter? (data, systems, people, processes)
- For each, what is the credible threat and where is the vulnerability?
- Have we estimated the probability and impact, with real numbers?
- Have I made an explicit decision on how to deal with each risk?
If the answer to any of these is “no really”, you don’t manage your risk as you should.