Transfer
Shifting risk to a third party — typically via insurance or outsourcing.
Transfer shifts a risk’s financial impact to a third party, usually through cyber insurance or by outsourcing the risky function. The crucial caveat: you can transfer the monetary loss but never the accountability — reputational damage and regulatory responsibility stay with you. Cyber insurers increasingly require evidence of baseline controls (MFA, EDR, backups) before they’ll write or pay on a policy.
Advertisement