Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
10 / 34

Chapter 8

08Advanced Risk Management for Creative Assets

3 min read10 of 34Read it in the book · page 50

“No control without a risk to justify it, and no risk without an owner to decide its fate.”

Where innovation is the currency of success and assets are digital and intellectual, risk management becomes the heart of the whole system. This chapter delves into identifying, analysing and treating risks under ISO 27001:2022, with a focus on creative and software contexts. Effective risk management not only prevents loss; it lays a secure foundation for growth and innovation.

Understanding Risk in Creative Contexts

Risk management under the standard is a systematic, iterative process that requires a deep understanding of the nature of information risks, their sources and their impact on the business. In the creative industries, this means going beyond traditional IT risks to the entire project life cycle: from ideation to delivery.

The risk management process: identify, analyse, treatThe risk management process: identify, analyse, treat
The risk management process: identify, analyse, treat
Text in this figure

Identify · What could happen? · Assets · Threats · Vulnerabilities · Analyse · How big is it? · Likelihood · Impact · Scenarios · Treat · What do we do? · Mitigate · Transfer · Avoid · Accept · Decisions are recorded in the risk treatment plan and the Statement of Applicability · Figure 9

Stage One: Risk Identification

  • Asset identification: An inventory of everything operations rely on: tangible assets such as servers and laptops, and intangible ones such as digital files, client databases, proprietary software and brand reputation. Completeness is essential here.
  • Threat assessment: Internal or external, intentional or accidental: malware, ransomware and phishing, physical theft, accidental data loss, system failure and natural disasters. In the creative sector, also: intellectual property theft, plagiarism and reputational damage.
  • Vulnerability assessment: The weaknesses threats exploit: technical, such as weak passwords and outdated software, or procedural, such as no clear access policy or inadequate staff training.

Stage Two: Risk Analysis

After identification comes analysis to estimate potential impact and likelihood, so priorities can be set and the most appropriate action chosen.

  • Likelihood and impact: For each risk: how likely is it? And what is its financial, reputational, legal or operational impact? The assessment can be qualitative (high, medium, low) or quantitative on a numerical scale.
  • Risk scenarios: A short story explaining how a risk turns into an incident. Especially useful in creative environments, where new projects and technologies bring unexpected risks, so consequences become clearer and treatment strategies improve.
Likelihood and impact matrix with creative-industry examplesLikelihood and impact matrix with creative-industry examples
Likelihood and impact matrix with creative-industry examples
Text in this figure

Spam · Phishing · Ransomware · Public share link · Footage leak · Screen fault · Encrypted disk theft? · High · Medium · Low · Low · Medium · High · Likelihood · Impact → · High: treat now · Medium: scheduled plan · Low: monitor · Risk acceptance criteria set the line between acceptable and unacceptable · Figure 10

Stage Three: Risk Treatment

After analysis, a treatment plan is developed and implemented. There are four main options:

  • Mitigate: Apply controls that reduce likelihood or impact; the most common approach.
  • Transfer: Shift the risk to a third party through an insurance policy or by outsourcing a function to a specialist provider.
  • Avoid: Refrain from the activity or project that generates the risk.
  • Accept: Accept the risk and its consequences, usually when the cost of treatment exceeds its potential impact, by a documented decision of the risk owner.

For each risk, the most appropriate treatment option is chosen and documented in the risk treatment plan, with the specific actions, resources required and implementation timeline. The register is then reviewed periodically, because the risks themselves change.

From the Field

A register with two hundred risks all rated the same helps no one. Start with ten real risks with real owners, and add to them with every review.

2026 Update

Add to the asset inventory what has become an asset since 2023: approved prompt libraries, AI API keys, custom models, and AI agents connected to your systems. And add to the threats: prompt injection, data leakage through public tools, and AI-generated fake content.

Risk management is not a table filled in once; it is a constant dialogue between what we protect and what threatens it.

Lessons Learned

  1. 1Risk management has three stages: identification, analysis and treatment.
  2. 2Assets are tangible and intangible, and reputation is an asset too.
  3. 3There are four treatment options, and every decision is documented and assigned to an owner.
  4. 4Models, prompts and API keys are new assets in the register.

Tip: use ← → to move between sections.