Residual Risk
Noun · Security & Infosec
Definitions
The risk that remains after security controls, mitigations, or remediation steps have been applied. Residual risk is what decision-makers must consciously accept, transfer, or continue to reduce once perfect elimination of the issue is impractical.
In plain English: The remaining risk left over after protections and fixes are in place.
Example: "After segmentation and monitoring were added, the team documented the residual risk of keeping the unsupported device online for one more quarter."