Risk transfer
Also known as: risk sharing
Moving the financial cost of a risk to another party, usually through insurance or a contract with a supplier.
Draft - this entry has not been reviewed yet.
Formal
The risk treatment option in which some or all of the consequences of a risk are shared with or passed to a third party - for example through cyber insurance or contract terms with a supplier - while accountability for the risk stays with the organisation.
In plain English
Like hiring a removal firm that pays if it drops your piano - you get the money back, but you still have no piano for the party on Saturday.
In practice
A Danish online furniture shop takes out cyber insurance that pays for outside experts and lost income after an attack, and its contract makes the hosting provider cover losses from the provider's own outages.
Why it matters
Money can be moved, but the lost trust, the lost data and the legal duties cannot - an insured organisation must still report breaches and answer to its customers.
Technical deep dive
ISO 31000:2018 and ISO/IEC 27005 call this option risk sharing, and the choice of word is deliberate: what moves is part of the financial consequence, while the likelihood of the event and the accountability for it stay where they were. The two main instruments are insurance and contract. Neither changes the probability of a breach; both change who pays for some of its consequences, and only up to the limits written into the policy or agreement.
Cyber insurance typically combines first-party cover (incident response and forensics, data restoration, business interruption after a waiting period, extortion costs where lawful) with third-party cover (liability to customers and data subjects, defence costs, sometimes regulatory proceedings). The details decide how much risk is really transferred: sublimits for particular loss types, retentions, waiting periods of several hours before business interruption applies, requirements to use the insurer's panel of breach coaches and forensic firms, and exclusions. War and state-backed attacks are the most debated exclusion. In Merck v. ACE American, a dispute over roughly 1.4 billion dollars of NotPetya losses claimed under all-risk property policies, New Jersey's Appellate Division held in May 2023 that a traditional hostile or warlike action exclusion did not apply, and the case settled in January 2024; in parallel, Lloyd's Market Bulletin Y5381 required state-backed cyber-attack exclusions in stand-alone cyber policies incepting or renewing from 31 March 2023. Underwriters also make controls such as MFA, EDR and offline backups conditions of cover, so an inaccurate application can jeopardise the claim when it matters. The insurability of regulatory fines is limited and depends on national law.
Contractual transfer uses indemnities, liability clauses and service credits with suppliers. In practice liability caps, often tied to a year's fees, and exclusions of indirect or consequential loss mean the transferred amount is usually small compared with the actual business impact of a major outage. Regulation limits what can be shifted: under GDPR Art. 82(4), where several controllers or processors are involved in the same damaging processing, each can be held liable for the entire damage towards the data subject, with recourse among them under Art. 82(5); DORA Art. 28(1) keeps financial entities fully responsible for compliance when they use ICT third-party providers; and NIS2 Art. 21(2)(d) makes supply chain security part of the entity's own obligations.
Transfer therefore complements mitigation rather than replacing it. It is best suited to low-likelihood, high-impact residual risk that remains after reasonable controls, and quantitative analysis of the loss tail is what makes it possible to choose sensible limits and retentions.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk transfer
Relationships
- A kind of
- Risk treatment
- Don't confuse with
- Risk mitigation
Sources & further reading
Standards & official texts
- ISO/IEC 27005:2022 (8.2 - Risk treatment options)
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 5 og Ordliste (Risikohåndtering - overføre)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…