Skip to main content
Informationssicherheit / NIS2

Residual risk

Residual risk is the risk that remains once all agreed security controls have been implemented, and which must be consciously and verifiably accepted by the risk owners or top management.

Residual risk is the exposure that is left after an identified information security risk has been treated. It exists because security controls usually reduce a risk rather than eliminate it: technical measures have limits, organisational rules depend on how people actually behave, and driving a risk to zero would often be disproportionately expensive. Practitioners distinguish the inherent or gross risk – the level of exposure before effective controls are taken into account – from the net or residual risk, which reflects the controls already in place plus those newly decided upon. A residual risk is therefore not a failing but the normal, expected outcome of rational risk management.

What matters is how residual risk is handled formally. Clause 6.1.3 of ISO/IEC 27001:2022 requires the organisation to obtain the risk owners' approval of the risk treatment plan and their explicit acceptance of the residual information security risks. The yardstick is the risk acceptance criteria defined in advance: if the residual risk falls below the agreed threshold it can be accepted; if it exceeds the threshold, either another round of treatment is needed or a deliberate, reasoned exception has to be decided at the appropriate management level. The acceptance must be documented in an auditable way – with a date, a named decision-maker, a rationale, a validity period and a reference to the specific risk. Germany's BSI Standard 200-3 makes the same point, stressing that residual risks have to be presented transparently to top management because that is where accountability sits.

Accepting a residual risk is not a permanent sign-off. Residual risks should carry an expiry date, be reviewed regularly and be reported in the management review under clause 9.3 of ISO/IEC 27001, because the threat landscape, business processes and control effectiveness all change over time. The topic has gained further weight through the NIS2 Directive (EU) 2022/2555 and its German implementation: under Articles 20 and 21, the management bodies of essential and important entities must approve the cybersecurity risk management measures, oversee their implementation and can be held personally liable for breaches. An undocumented or unconsidered acceptance of residual risk is therefore not merely an audit finding inside the ISMS but a potential supervisory issue. It should be noted that Germany transposed the NIS2 Directive well after the EU deadline of 17 October 2024, and that individual details and transition arrangements are still being fleshed out through statutory instruments and regulatory guidance.

Legal Basis

ISO/IEC 27001:2022 (clauses 6.1.2, 6.1.3, 8.2, 8.3, 9.3), ISO/IEC 27005, ISO 31000; BSI Standard 200-3 (risk analysis); Articles 20 and 21 of the NIS2 Directive (EU) 2022/2555

Practical Example

An information security officer assesses the risk that an ageing production control system is compromised, given that its vendor no longer ships security updates. As treatment, she implements strict network segmentation, removes direct internet access, enables full access logging and tightens the authorisation concept. That brings the risk down from "high" to "medium" – yet the remaining attack path via external technicians' maintenance laptops cannot be reduced further without replacing the machine itself. She records this residual risk in the risk register together with its rating, the remaining scenario and a reference to the implemented controls, and presents it to the plant manager as risk owner. He accepts the residual risk in writing, limited to twelve months and on condition that the replacement is budgeted in the next investment cycle. The acceptance is revisited in the annual management review and reported to the executive board.

FAQ

Under ISO/IEC 27001 the risk owners accept the remaining information security risks and approve the risk treatment plan. The risk owner is the manager accountable for the process or asset concerned. Where a residual risk exceeds the defined acceptance criteria, the decision belongs at top management level, which carries overall accountability for the ISMS.
Inherent or gross risk describes the level of exposure without taking effective security controls into account. Residual risk is what remains once the implemented and agreed controls are working. The gap between the two shows how much risk reduction the controls actually deliver and makes their value visible to management.
The standard sets no fixed interval, but it does require risk assessments to be repeated at planned intervals and whenever significant changes occur, with the results fed into the management review. In practice an annual review works well, supplemented by ad-hoc reassessments after new threats, system changes or security incidents. Acceptances should therefore always be granted for a limited period.

How preeco supports you

Learn how our software supports you with this topic.

Learn more