It's one thing to say 'lessons learnt' in risk management after an event, but do organisations truly analyse and understand what actual action was required and made the necessary process changes or resourcing changes to minimise the risk occurring again? https://t.co/FvcfNS3Mlk
Where do your 'treatments' in your risk register sit and how are they described? #riskmanagement It’s all about the words and how important it is to use the right words https://t.co/jN0HbDju7G
When compiling a risk register, make sure the risks identified are risks that you want to stop from happening and not described as the possible causes or consequences should they occur https://t.co/sZKXLaXAxw
Can we please put risk management at the highest level of the organisation where it belongs - with those who make the decisions relating to the risk controls. Tricky but doable https://t.co/mehTF1khLs
Massive risk: "The attack is troubling not just because of its sheer size, but also the level of detail potentially stolen by the attackers" The Guardian #riskmanagement https://t.co/biRbfT34W5
There is a belief out there that a control in #riskmanagement needs to be applied at the same level across an organisation. Rubbish! Proportionality is the key https://t.co/Tf4fKEb2oU