Residual Risk
Residual risk is the level of risk that remains after all applied controls, mitigations, and treatments have been accounted for, representing the actual exposure an organization carries after its risk management program takes effect.
Why Residual Risk Is the Number That Matters
Boards, CFOs, regulators, and cyber insurers all care about residual risk. It is what the organization is actually exposed to, not what it would be exposed to hypothetically without controls. Investment decisions, risk transfer decisions, and reporting decisions all reference residual risk.
Comparing residual to inherent risk is what makes the control program's value visible. The reduction from inherent to residual, expressed in dollar terms, is the measured return on control investment.
Residual Risk vs. Risk Tolerance
Residual risk is the actual exposure. Risk tolerance is the acceptable exposure. The two need to be compared against each other. When residual exceeds tolerance, additional treatment is required. When residual is well below tolerance, additional investment may not be justified.
This is the mechanism boards use to govern the cyber program. Residual risk reports against tolerance thresholds, with escalation triggered when the gap closes.
Residual Risk in CRQ
Quantified programs report residual exposure as the primary financial figure. AAL, 1:100, and other outputs from CRQ are all residual measures, calculated with the organization's actual control posture reflected in the modeling.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


