Most Organizations Can Produce a Risk Assessment. Fewer Can Defend One.

by | May 31, 2026

Introduction

Recently wrapping up our latest Healthcare Enterprise Cyber Risk Management course at The University of Texas at Austin, I have been thinking and writing about a problem I now call Defensible Risk Assessment.

Our Capstone Project requires students to critically evaluate whether an actual risk assessment (i.e., risk analysis in HIPAA parlance) is defensible vis-à-vis the requirements set forth by the Office for Civil Rights. As you may be aware, HIPAA-regulated healthcare entities have a dismal track record of conducting OCR-acceptable risk analyses.

I believe risk assessment failure is a cross-industry, global problem, and it has piqued my interest.

All Kinds of Work Products

Most organizations can produce something they call a risk assessment. 

Far fewer can explain why anyone should rely on it.

That is the problem.

A risk assessment may exist. The meeting may have been held. The spreadsheet may have been updated. The heat map may have been presented. The consultant may have delivered the report. The risk register may have a fresh date on it.

Everyone can point to something.

But the existence of a risk assessment does not prove its quality. It does not prove that the right things were assessed. It does not prove that the right evidence was considered. It does not prove that likelihood and impact were evaluated in a disciplined way. It does not prove that leaders understood the assumptions, limitations, uncertainty, or residual risk.

It proves only that something was produced.

That is no longer good enough.

Risk Activity Is Not Risk Understanding

One of the most common mistakes in risk management is confusing risk activity with risk understanding.

Risk activity is visible. People hold meetings. They complete questionnaires. They map controls. They update dashboards. They fill in spreadsheets. They assign red, yellow, and green ratings. They brief management. They send materials to the board portal.

Risk understanding is different.

Risk understanding exists when an organization can explain what was assessed, why it was assessed that way, what evidence was considered, what assumptions were made, what uncertainty remains, and why the resulting decision was reasonable.

That distinction matters because leaders rarely rely on risk activity itself. They rely on the conclusions that come out of it.

They rely on the statement that a risk is high, moderate, or low. They rely on the assertion that a control is effective enough. They rely on the recommendation to accept, mitigate, transfer, or avoid risk. They rely on the claim that one risk deserves capital before another.

If the assessment cannot explain the reasoning behind those conclusions, the organization may have a document. It may not have a defensible risk assessment.

The Governance Problem

Members of the board and senior executives do not need to perform every risk assessment personally.

They also do not personally prepare every financial statement.

But they do need to know when something is good enough to rely on.

A chief executive officer may rely on a risk assessment to approve a strategy. A chief financial officer may rely on it to allocate capital. A general counsel may rely on it to evaluate legal exposure. A chief risk officer may rely on it to compare risks across the enterprise. A chief information security officer may rely on it to prioritize action. Members of the board may rely on it to oversee management.

The risk assessment becomes the foundation for many other decisions.

If the foundation is weak, the structure above it is unstable.

That is why the central question should not be, “Did we do a risk assessment?”

The better question is, “Can we defend the risk assessment we are relying on?”

The Evidence Problem

The practical question is simple:

Where is the evidence?

Where is the evidence that the scope was appropriate? Where is the evidence that material assets, systems, processes, data, business capabilities, and third parties were considered? Where is the evidence that reasonably anticipated threats and vulnerabilities were identified? Where is the evidence that existing controls were evaluated rather than merely listed? Where is the evidence behind likelihood and impact? Where is the evidence supporting residual risk? Where is the evidence that leaders understood and accepted the risk they were carrying?

These questions are not about creating bureaucracy for its own sake.

They are about improving decision quality.

Evidence does not eliminate judgment. It disciplines judgment.

A defensible risk assessment does not pretend that uncertainty disappears. Risk assessment is not prophecy. It is a structured way to make reasoned decisions under uncertainty.

The more important the decision, the more important the record.

The Heat Map Is Not the Assessment

A heat map can be useful. It can help leaders see relative priority. It can make a meeting more efficient. It can convert a large body of analysis into something easier to discuss.

But a heat map is not the assessment.

A red box does not explain the asset or process at risk. A yellow box does not document the vulnerability. A green box does not prove the control works. A plotted point does not show the evidence behind likelihood or impact.

A dashboard can summarize risk. It does not prove that risk was understood.

The same is true for checklists, maturity scores, risk registers, and consultant reports. They can all help. They can all support the process. But none of them should be confused with the reasoning itself.

The artifact starts the conversation. It does not end it.

Cybersecurity Is the Urgent Proving Ground

The problem is not limited to cybersecurity. It appears in privacy, artificial intelligence, third-party risk, operational risk, safety risk, financial risk, and other high-stakes domains.

But cybersecurity is the urgent proving ground.

The consequences are visible. The incidents are expensive. The dependencies are complex. The threat environment changes quickly. Regulators are active. Insurers care. Customers ask questions. Investors want disclosure. Members of the board are being told to pay attention.

In cybersecurity, weak risk assessments do not stay buried forever. After a serious incident, the organization may be asked what it knew, what it considered, what it ignored, and how it decided.

At that point, the risk assessment is no longer merely an internal management artifact. It becomes evidence.

Healthcare Is the Warning Sign

Healthcare provides one of the clearest public warning signs.

For years, the HIPAA Security Rule has required regulated entities to conduct a risk analysis related to electronic protected health information. Enforcement history has repeatedly shown that many organizations struggle to demonstrate an accurate, thorough, enterprisewide analysis.

Healthcare is not the whole story. It is the warning sign.

The lesson for other sectors is straightforward: when the duty to assess risk becomes visible, enforceable, and documented, weak assessments become difficult to defend.

Leaders in other industries should not dismiss this as a healthcare-only problem. They should view it as an early signal of where risk governance is heading.

Artificial Intelligence Will Raise the Stakes

Artificial intelligence will change risk assessment work.

It can help collect evidence, compare documents, identify inconsistencies, draft summaries, analyze control mappings, and test whether conclusions follow from the available record.

But artificial intelligence will not eliminate judgment. It will not eliminate accountability. It will not make a weak assessment defensible simply because the language sounds polished.

In fact, artificial intelligence may make weak risk assessments easier to write and harder to excuse.

A polished assessment generated or improved by artificial intelligence may look more professional. But if the scope is wrong, the evidence is thin, the scoring is unexplained, or the conclusions do not follow from the facts, the assessment is still weak.

Used poorly, artificial intelligence may simply help organizations pave the same old risk assessment cow path faster and make it look slightly prettier.

The Shift From Performance to Reliance

The next stage of risk management is not merely performing risk assessments.

It is producing risk assessments that leaders can rely on.

That requires more than a template. It requires clear scope. It requires a rational unit of analysis. It requires evidence connecting the thing at risk, the threat, the vulnerability, and the existing control environment. It requires explanation of likelihood and impact. It requires documentation of assumptions, exclusions, and uncertainty. It requires conclusions that follow from the record.

A defensible risk assessment does not need to be perfect. It does need to be complete enough, evidence-based enough, methodologically sound enough, and decision-useful enough to support responsible action.

That is the standard leaders should begin demanding.

The Question Leaders Should Ask

The first question is not whether the organization did a risk assessment. The better question is whether the organization can defend the risk assessment it is using to make decisions.

  1. Can management explain what was assessed?

  1. Can it explain what was out of scope?

  1. Can it explain the evidence behind the conclusions?

  1. Can it explain why the assessment is good enough to support the decision being made?

  1. Can it show the record after an incident, an audit, an enforcement action, an insurance claim, a customer inquiry, an investor question, or a board challenge?

  1. Most of all: Where is the evidence?

That question is where defensible risk assessment begins.

#riskmanagement #CISO #riskassessment #defensibleriskassessment #DRA #enterprisecyberriskmanagement #cyberriskilliteracy  #boardcyberoversight #boardofdirectors