Residual Risk

Noun · Security & Infosec

Definitions

  1. The risk that remains after security controls, mitigations, or remediation steps have been applied. Residual risk is what decision-makers must consciously accept, transfer, or continue to reduce once perfect elimination of the issue is impractical.

    In plain English: The remaining risk left over after protections and fixes are in place.

    Example: "After segmentation and monitoring were added, the team documented the residual risk of keeping the unsupported device online for one more quarter."

Related Terms