- Definition
- Systematically identifying, assessing, treating and monitoring risks
- Process steps
- Identify → Assess → Treat → Monitor
- Role under NIS2
- Express core duty
- Related approach
- All-hazards approach
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is risk management?
Risk management describes the structured, continuous process through which an organisation identifies, assesses and deliberately steers the hazards to its systems, data and processes. Instead of only reacting to incidents, risks are identified in advance and reduced to a level at which the remaining residual risk is carried consciously and traceably. While Governance sets the frame and the responsibilities, risk management is the operational heart: this is where individual threats are assessed concretely and matched with measures. It is therefore the second building block of GRC and the professional foundation of every ISMS.
The risk management process
- Identify: Which threats and vulnerabilities are there? Which values (Assets) are affected?
- Assess: How likely is a risk and how large would the damage be? Those two factors give you the priority.
- Treat: Avoid risks, reduce them (with Controls), transfer them (through insurance, for example) or accept them consciously.
- Monitor: Check that measures work and adjust them when new threats appear – then the cycle starts again.
The risk management cycle at a glance
- 1 Identify: Threats, vulnerabilities and the assets concerned are collected together.
- 2 Assess: Every risk is prioritised by how likely it is and how much damage it would cause.
- 3 Treat: The risk is avoided, reduced, transferred or consciously accepted.
- 4 Monitor: Effectiveness is checked continuously, then the cycle starts again.
The all-hazards approach
NIS2 requires an All-hazards approach: it is not only cyberattacks that are considered, but all relevant hazards – power cuts, human error, outages at service providers in the supply chain or physical events such as fire and water damage. Risk management therefore has to think beyond IT alone and take in organisational and physical risks that could endanger the availability of the services.
Risk management and NIS2
Under NIS2 risk management is the central duty. Article 21 calls for appropriate and proportionate technical and organisational measures that reflect the state of the art, are approved by the leadership and are evidenced by a maintained risk register – because entities in scope have to assess their cyber risks not once but continuously, and have to be able to show their competent authority at any time that the measures taken fit the actual risk. The directive has applied since 18 October 2024, and each Member State turns it into national law on its own timetable, so registration channels and deadlines differ from country to country. If risk management does not hold and a significant incident occurs, the reporting chain applies as well: an early warning within 24 hours, an incident notification after 72 hours and a final report after one month. Article 34 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
An example from a hospital: The head of IT keeps a risk register in which every asset – from the patient records system to the emergency power supply – is assessed with its likelihood, the damage it would cause and the measure assigned to it. It is reviewed once a year and after every significant incident. That keeps it provable at any time why a residual risk is being carried.
What do you need to do?
- Record all assets worth protecting and assign an owner to each one.
- Build a risk register with likelihood, damage and a measure for every risk.
- Document the treatment decision (avoid, reduce, transfer, accept) for every risk and have the leadership approve it.
- Set fixed review dates – annually and after every significant incident.
- If you have not done so yet: check the registration rules of the authority responsible for you and settle the 24-hour and 72-hour reporting routes in advance.
Further reading: EUR-Lex – NIS2 Directive (EU) 2022/2555
Frequently asked questions
What is risk management, explained simply?
Risk management is the systematic, continuous handling of risks in four steps: risks are identified, assessed by how likely they are and how much damage they would cause, treated, and then monitored on an ongoing basis. The aim is to avoid or limit damage to the organisation and to carry the remaining residual risk consciously and traceably. Risk management is the second building block of GRC and the professional foundation of every ISMS.
Why does risk management matter under NIS2?
Article 21 of NIS2 makes risk management an express core duty: entities in scope have to assess cyber risks systematically, take appropriate measures and anchor those measures at leadership level. The evidence has to be available to the competent authority at any time, which means the risk register has to be kept current. Article 34 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
What is the all-hazards approach?
Under the all-hazards approach, risk management looks not only at cyberattacks but at every relevant hazard to the availability of the services. That includes technical failures such as power cuts, human error, outages at service providers in the supply chain and physical events such as fire or water damage. NIS2 requires this approach expressly, so risk management has to reach beyond IT alone and take in organisational and physical risks as well.