Chapter 12: Risk Management
The purpose of this chapter is not to describe (or even summarize) the entire risk management process in project and portfolio management. This has been done in numerous publications.
Here, we discuss often-neglected aspects of risk management, in particular, risk-adjusted economics and systemic view, and present a new Risk Response Framework.
In this chapter, we deal with three well-known types of uncertainties:
- Variability risks (expected variability)
- Event risks and cumulative risks (known-unknowns)
- “Black swans” and “dark risks” (unknown-unknowns)
What would you prefer: a riskier or a less risky project? Does this question even make sense?
We should not view risk simply as a variable that can lead to a deviation between planned and actual. Rather, proactive risk management and modeling of residual risks provide a basis for decision-making and means for “shaping the future” and achieving the desired reality.
As with other parts of the LeanPM Framework, what is written here should be seen as guidelines to be adapted and, if necessary, simplified depending on the context, and not as a recommended process. This is also why we have tried to avoid algorithmizing the risk management process and to emphasize analytics.
Risks should be managed to the extent that they can affect:
- the benefits and costs
- and, through them, the profit of a project or portfolio.
In other words, risk management should contribute to the improvement of the overall value-creating system and to the increase in the net value it creates.
Find a severe and important risk that has no potential impact on your value-creating system, and here you are—you already have one less risk.
We can view most risks as untested assumptions, and therefore, assumption testing should be considered a fundamental part of risk management.
Let’s first discuss the variability risks that stem from the normal, expected variations of the stochastic parameters of a project or portfolio. "Stochastic parameter" here means a random, probabilistic variable, but within certain limits.
Does this sound complicated? Here's a simple example: when we roll a die, we expect a random number every time, but always a whole number and within the range between 1 and 6.
Typical project examples are the productivity of team members and the delivery time of equipment under normal conditions.
Check the delivery date for your chosen product in an online store. Often, the merchant does not commit to an exact date, but to a period, for example, "FREE delivery 28 January - 2 February". And this is provided that you want to order a gift for a birthday that is on the 1st of February!
As trivial as it may sound, variability risks can be “mitigated” by reducing the variability, e.g., through process improvement. The residual variability can be accounted for by a reserve that serves as a risk “surcharge.”
This type of risk can be modelled by defining the values of the stochastic parameters (e.g., through a three-point estimate) and, through a Monte Carlo simulation [1], their influence is transferred to the probability distribution of the project's or portfolio's profit.
Event risks are related to specific events, and it should be clear which project or portfolio parameters they would affect. These risks are discrete in nature: they either happen or they do not. These are the things we think about:
"What would I do if this suddenly happened?!”
To the extent that these risks affect stochastic parameters on which benefits or costs depend, their impact is modeled by shifting the probability distribution of the parameters.
For example, under normal conditions (temperature and precipitation within the monthly norm), the price of certain imported materials can be expected to vary within certain limits.
An increase in import duties (event risk) means that the impact of this risk must be modeled by shifting to a higher range in which the price of materials will vary.
This is an example of a “conditional distribution”—a probability distribution that shifts when a certain event occurs.
Note: In the Monte Carlo simulation, this is modeled by a binary variable:
- If the event does not happen, the default distribution is used.
- If it does happen, then an alternative distribution is used.
Alas, we are the ones who have to define several input values for each distribution. The simulation model uses them to develop full probability distributions.
When we apply a Monte Carlo simulation, the impact of all modeled event risks is reflected in the probability distribution of the project or portfolio's profit. But this should be done for the residual risks, after we have carried out economically justified elimination and reduction of the probability and impact of inherent risks.
Event risks are known-unknowns. We know what can happen, but to make things more interesting, we do not know if it will happen, when it will happen, or (usually) what exactly the impact will be.
Though event risks can be a serious threat, the Cartel of Known-Unknowns also has another weapon—cumulative risks. As their name suggests, they occur when exposure to negative factors leads to an accumulation with a growing negative impact. When a critical threshold is breached, this can lead to an explosion of negative impact.
For example, prolonged multitasking (risk state) can lead not only to fatigue but also to something more serious, such as burnout.
Preventive actions for this type of risk should be aimed at eliminating the cause, reducing the rate of accumulation (emissions), and interrupting and clearing the accumulation through systemic improvements.
Nassim Taleb’s "black swans" (rare "birds" with extreme unpredictability and impact and low probability, but explainable ex post facto) and "dark risks" (unpredictable and unknown in nature, and unexplainable ex post facto, like vague bad dreams) are "unknown-unknowns."
"Black" and "dark" go well with events of unknown nature and indefinite probability, for which we have no historical data, yet which can have a potentially huge impact. For such risks, we can set aside reserves of time and budget (not to be confused with off-the-books funds!) and make decisions based on the organization's ability to withstand a shock. These reserves also represent a risk “surcharge.”
The impact of a risk should be considered systemically—in terms of the impact on the whole value-creating system and the flow of value. The focus should be on proactive system design and redesign, not on eliminating the consequences.
Risk Management ⊃ Value-Generation Management
High exposure to residual risks can be a symptom of a weak assumption testing process. In this sense, assumption testing is a risk management tool, as it accelerates validated learning and reduces uncertainty. Risk management becomes a means of system evolution through PDCA (Plan–Do–Check–Act) cycles.
In conclusion to the basic principles, let’s clarify the relationship between constraint (see Constraint Management) and risk. The constraint exists objectively, and risk can affect its capacity or change it. Risk can manifest itself in a change in the capacity of the constraint or in the emergence of a new constraint.
Let’s consider the general model for the occurrence and impact of a risk. It can be represented as a causal relationship between a cause, a risk event or state, and an effect. Yes, risks also start with a compelling cause!
The event risk model is Cause -> Risk Event -> Impact. The cumulative risk model is Cause -> Risk State -> Threshold Breach -> Impact.
In summary, the model looks like this:
In practice, the immediate causes and effects can be more than one each, and causes also have causes (and so on), but this does not change the essence of the model.
The causes of risks stem from requirements, restrictions, situations (facts), errors or flaws, for example:
- The project team is multitasking (situation/fact) --->>> Burnout and project delays are possible.
- A project to build a new bridge must be completed by April 30 (restriction) --->>> Additional costs may be required to meet the deadline.
- There is only one heavy-duty crane in the project area (fact, restriction) --->>> The crane may not be available when needed. (We may not need the crane, but if we have budgeted for it, we should at least try to spend the budget.)
- For safety reasons, the work on the site may only be performed during daylight hours, and only when visibility is good (requirement, restriction) --->>> Project may be delayed.
- Error in the technical specification of equipment to be delivered (error) --->>> Necessitates rework.
- Compliance flaw --->>> Risk of sanctions by regulatory agencies.
The expected value of a risk is its statistically expected impact on the profitability of a project or portfolio. According to the standard practice, the expected value of a risk is the product of its probability and impact (severity of consequences).
Of course, when a risk occurs, we bear the entire impact, not the product of probability and impact. However, when we consider a pool of multiple risks, we expect the total expected value of all risks (for a sufficiently diversified pool) to cover the impact of those risks that will actually occur.
The pool acts as a damper, absorbing individual risks.
We should not assume the probability and impact to be deterministic by default. In some cases, the impact can be precisely defined, such as a fixed fine or penalty. Negotiated or legally defined sanctions provide us with this convenience. But in the general case, the probability and impact should be defined stochastically.Individual perspective
Suppose we have defined the following optimistic, most likely, and pessimistic values for a risk: probability of 10%, 15%, 21%, and impact of $21K, $35K, $62K.
The Triad of Three-Point Estimation confronts the Cartel of Known-Unknowns in a battle with a stochastically defined outcome. Nothing is certain, and no action is safe.
If we use the most likely values, the expected value would be $5.25K.
But using a Monte Carlo simulation (applying a beta distribution to both parameters), we find the following distribution of impact:- Mean: $6.45K
- Median: $6.01K
- 85th percentile: $9.89K
- 95th percentile: $11.82K
Expected value is also stochastic. Mean represents the “statistical average result.” This is actually the expected value, the weighted average of all possible outcomes of the simulation.
The percentile indicates the probability that the actual impact is below a specific value, e.g., the Median corresponds to the 50th percentile and means that there is a 50% chance that the actual impact will be up to $6.01K. (If 50% doesn't suit you, and you want to know something with 100% certainty, here it is: there is a 100% probability that the actual impact will either be up to $6.01K or exceed it.)
The Mean is higher than the deterministic value and the Median because the probability distribution of the impact is asymmetrically shifted towards the pessimistic value ($62K).
Again, as we explained above, it is about the contribution of this risk to the total expected impact of all risks, not its individual impact.Aggregate perspective
In practice, to assess the impact of all risks, we need to analyze them simultaneously, as in the following example for three independent risks with corresponding optimistic, most likely, and pessimistic values.
Risk A
- Probability: 10%, 15%, 21%
- Impact: $21K, $35K, $62K
Risk B
- Probability: 15%, 22%, 25%
- Impact: $35K, $55K, $165K
Risk C
- Probability: 20%, 25%, 40%
- Impact: $45K, $55K, $155K
The individual 95th percentile values are $11.86K, $38.65K, and $56.53K. Their arithmetic sum is $107.04K. This is the scenario in which all three risks occur simultaneously at their pessimistic values, i.e., when we consider the 95th percentile as a “pessimistic” level. (The probability of the 95th percentile occurring is 0.0125% = 0.05 × 0.05 × 0.05)
If we model reality in a better way and analyze the three risks simultaneously, we get an aggregate 95th percentile value of $90.02K. This is a 5% probability scenario, and this percentage may seem small. Actually, it means that we can be 95% confident that the total impact will not exceed $90.02K. We’ll need $17K less in reserve funds than in the individual estimates’ scenario (naturally, we can claim part of this amount as a bonus for the savings we have secured).
The difference represents the effect of risk diversification. This example is for independent risks; Monte Carlo simulation also works with correlations between the risks.
The arithmetic sum of the individual values may be close to the aggregate value, but this is not guaranteed. Even when the individual risks are highly asymmetric, when aggregated, their distribution tends to a normal distribution, that is, to perfect central symmetry of the distribution.
This is a nice reward that we get without any effort.
The probability that all risks will materialize simultaneously in their pessimistic scenario is very small. We need a smaller overall reserve (“surcharge”) to achieve a certain level of confidence in the aggregated risk impact than the sum of the impacts for individual pessimistic scenarios.
Why does the individual perspective also matter
Are the individual expected values of risks useless? Not really, and definitely not if we want to impress stakeholders. We can use the expected value of a risk to assess the economic justification of the mitigating actions for that risk.
Risk analysis involves two parts:
- Analyzing individual risks to decide how and to what extent to mitigate them.
- An aggregate analysis of residual risks to assess their combined impact.
A budget with risk reserves
Variability risks require a reserve for estimation uncertainty. We start modestly by preparing a baseline budget using average, deterministic values. The estimate uncertainty reserve represents the difference from the budget at a chosen confidence level, e.g., 85%. Planned (proactive) risk response actions are also budgeted in the baseline budget, and the variability of their costs is accounted for in the estimate uncertainty reserve.
For all residual known-unknowns, which the Cartel insists on, we determine the aggregate impact value at the chosen confidence level (e.g., 85%) and set it as a contingency reserve. (Yes, the Cartel will insist on 100% confidence and will expect to receive a very high price for it.)
We can account for the costs of contingent (reactive) response in the impact of the risks, that is, the impact is the sum of the damage plus the cost of contingent response.
A separate management reserve for unknown-unknowns can be provided.
Therefore, the project or portfolio budget may have the following components:
- Base budget with average, deterministic values
- Estimate uncertainty reserve
- Contingency reserve (for event and cumulative risks)
- Management reserve (for unknown-unknowns at the portfolio level and a proportional share for individual projects)
This is how you can get a bigger budget, fully justified.
Risk analysis is not only used to reduce risk exposure (the expected value of profit loss) and determine reserves. It should serve as a ground for making management decisions. The variability of benefits and operating costs over the entire life cycle of the project or portfolio is also subject to analysis.
Ideally, the assessment of the necessary reserves should be carried out simultaneously through a Monte Carlo simulation (except the management reserve, which is determined by management), integrating the benefits and costs for the entire life cycle of the project or portfolio.
Risk and project/portfolio goal
The aim is to obtain a probability distribution of profit (or other measure of the goal), which can serve as a basis for making decisions about the "fate" of the project or portfolio. It might be better for us to decide what fate will be than for fate to decide for us. Through risk analysis, we not only determine the project costs, but also its risk-adjusted profitability, expressed as, e.g., Expected Net Present Value (eNPV).
Even when we perform an integrated analysis of the project or portfolio, taking into account residual risks, the analysis of individual inherent event and cumulative risks still makes sense to determine economically justified response actions.
By risk response, we mean reducing the risk's expected value by taking actions to reduce its probability or impact. This is one of the most exciting aspects of risk management —to undertake something uncertain to influence something uncertain.
Standards and other risk management publications typically recommend several types of risk response strategies, such as avoidance, mitigation, transfer, and acceptance [2].
Although useful, these strategies are very general. Also, they do not distinguish well between preventive and corrective aspects of risk management. In this classification, "mitigation" is almost a universal medicine but is understood primarily as a reactive limitation of damage.
Therefore, below we will present a more comprehensive framework for risk responses and provide ideas to support brainstorming specific solutions.
Naturally, there are two directions for risk mitigation: reducing the probability and reducing the impact. Both directly affect the expected value of the risk. From this, two groups of risk response actions arise: preventive and corrective.
We use "response actions" instead of "response measures" to emphasize proactivity in risk management.Preventive Actions
Preventive action is an action taken to reduce the probability of a risk by either eliminating or influencing its root cause, or weakening the causal link between the risk's cause and the risk event, or the threshold breach, or by interrupting and clearing the accumulation related to cumulative risks.
Risk prevention can be achieved through four distinct approaches:
- Eliminating the root cause
- Influencing the root cause
- Weakening the causal link
- Interrupting and clearing the accumulation
More details follow:
1) The first option to consider is eliminating the root cause of the risk (Category 1 Preventive Actions). If we can do this with reasonable effort, the risk simply disappears.
2) Our next option is influencing the root cause by changing the conditions so that the risk occurs less frequently (Category 2 Preventive Actions).
3) So far, we have worked on the cause and may have weakened it, but it is still active. Therefore, we can consider isolating it: weakening the causal link by placing a barrier between the cause and the event or the threshold breach (Category 3 Preventive Actions).
4) For cumulative risks, we also have the opportunity to interrupt and clear accumulation (Category 4 Preventive Actions) through system improvements. For example, interrupting the accumulation and clearing of technical debt through refactoring can reduce the probability of increasing maintenance costs for a software system.
Influencing the root cause and weakening the causal link can complement each other. For cumulative risks, these actions can be complemented by interrupting and clearing the accumulation.
Here, unlike standard frameworks that focus generally on reducing probability, we introduce specific categories of actions intervening in different parts of the causal chain.

Here is an illustration of this approach. Suppose that a loud noise from a machine poses a health risk to operators. Here are the options we have:
1) Eliminating the root cause could involve redesigning the production process to eliminate the noisy machine. If this is feasible and the costs are reasonable, the issue will be resolved completely.
2) Our next option is to influence the root cause, which could involve altering the machine's design to reduce noise emissions.
3) Even if we have managed to reduce noise emissions, we can consider weakening the causal link. This might entail soundproofing the machine and providing operators with noise-cancelling headphones. With this category of actions, the cause is not affected, but a barrier is placed between it and the risk event or the threshold breach.
4) If there is still a residual risk, the accumulation can be interrupted by rotating machine operators so that individual noise exposure does not reach a critical level. With rotation, the accumulation will also be naturally cleared, as operators will have a break from the noise, and their organisms will recover.
Though this is an example of a cumulative risk, the first three categories of actions also apply to event risks. In this example, they eliminate the cause or reduce the intensity of accumulation. The fourth category of action reduces the probability of the residual risk, if it's present.
This is a list of possible types of preventive actions that can enable creative thinking when looking for solutions to specific risks. Write them on separate cards, shuffle them, and pull them out one by one to get ideas when considering a specific risk—and you will have… more risk management cards.
These actions are applicable in a variety of contexts and should therefore be interpreted in the broadest sense. For brevity, not all actions are explicitly defined as such, but they all inherently involve taking actions.
01. Adding (activities, resources)
02. Alternative Routes
03. Avoiding
04. Buffers
05. Clearing
06. Change (of criteria)
07. Change (of period, place)
08. Change (of process, technology)
09. Change (of roles, responsibilities)10. Change (of scope, plan)
11. Decentralization
12. Design Enhancements
13. Directing, Guiding, Supervising
14. Exclusion
15. Feedback, Control Loop
16. Filling a Gap
17. Interruption
18. Isolation
19. Phased Implementation / Incremental Delivery
20. Poka-Yoke
21. Precautions
22. Preservation
23. Preventive Maintenance
24. Procedures and Policies
25. Process Enhancements
26. Protection
27. Proven Practices
28. Reallocation
29. Refactoring
30. Rehearsals, Exercises
31. Repetition
32. Replacement
33. Safety Measures
34. Simplification
35. Skills Building
36. Spare Capacity
37. Testing
38. Warnings, Reminders
Corrective Actions
Corrective action is an action that reduces the negative impact of a risk event or a threshold breach after it has materialized by weakening the causal link between the risk event or threshold breach and its negative consequences.
Corrective action is not simply something that follows from the occurrence of the risk. Getting the soccer ball out of the goal is important, but it is not exactly a correction.

We must not define corrective actions by their timing, but by their function. They are not undertaken by default after the risk has occurred. This is true for reactive corrective actions (Category 2 Corrective Actions), which seek to limit damage after the fact, but not for proactive corrective actions.
Proactive corrective actions (Category 1 Corrective Actions) are preparatory actions to reduce damage by increasing system resilience, like putting on warm clothes before going outside in the cold. These actions are taken before a risk event or threshold breach occurs. For example, training on how to respond to a cyberattack can be conducted in advance. Training does not reduce the probability of a cyberattack, but it can mitigate its negative consequences. Similarly, installing a fire suppression system does not reduce the probability of a fire, but it can limit its consequences.
We need to keep in mind that relying extensively on reactive risk treatment (reactive corrective actions) can be a symptom of waste. Proactive system redesign removes the structural prerequisites for risk, thereby enabling the avoidance of waste. This is another example of applying the concept of Most Responsible Moment to decision-making and action-taking (see Most Responsible Moment).
Here is a list of examples of possible types of corrective actions (put them on cards, and you will have fortune-telling cards). As with the actions from the previous list, they should also be interpreted in the broadest sense to be applicable across different contexts. Some corrective actions are also included in the list of preventive actions. Depending on the context, a specific “type” of action can be preventive or corrective in nature.
01. Alternative Routes
02. Cleanup and Restoration
03. Collaboration, Negotiations
04. Change (of place, period)
05. Change (of technology, process)
06. Change (of plan, scope)
07. Compensation, Offset 08. Containment
09. Contingency Plans
10. Corrective Design Changes
11. Counteraction
12. Crisis Management
13. Damage Control
14. Exercise, Rehearsal
15. Incident Handling
16. Legal Actions
17. Process Redesign
18. Reassignment
19. Recovery Plans
20. Remediation
21. Reparation
22. Replacement, Repair
23. Reputation Management
24. Resource Reallocation
25. Risk Transfer
26. Stakeholder Communication
27. Termination
The figure below summarizes the LeanPM Risk Response Ready (RRR) Framework in terms of the response action types and their timing.
Figure 12.1: LeanPM Risk Response Ready (RRR) Framework: Action Types and Timing

ROI logic
Mitigating individual risks makes sense as long as the benefits of mitigation exceed the cost. Some foods require more energy to digest than they provide the body and are therefore not suitable for a staple food.
In other words, the Return on Investment (ROI) of taking a risk response action should be positive. In this way, we reduce the overall risk exposure (the expected value of profit reduction) of the project or portfolio.ROI calculation
The ROI of taking a risk response action can be calculated by using the following conventional formula:
ROI = (Net Benefit of Action / Cost of Action) * 100
"Benefit of Action" represents the gain from taking the risk response action, expressed as a reduction in the expected value of the risk. In the example below, "Benefit" is calculated as the profit loss reduction due to taking the action. (A side benefit is that in this way, a loss can be presented as a gain.)
"Cost of Action" refers to the expense associated with implementing the risk response action.
"Net Benefit of Action" is the Benefit of Action minus the Cost of Action.
Let's illustrate the ROI calculation with an example in which the probability and impact are defined deterministically—boldly and decisively. This is a simplified example for demonstration purposes only. In reality, greater reliability of the outcome can be achieved with stochastic values and Monte Carlo simulation.
Numeric example
Let's consider the following two scenarios for a risk:
- Without a risk response action, the probability of occurrence is 60%, and the potential loss of profit is $1.2M.
- With a risk response action, we take a preventive action that costs us $0.2M, and we reduce the probability to 40% (the impact remains the same).
Let's first calculate the expected value for each scenario:
- Expected loss without action = 0.6 * $1.2M = $0.72M
- Expected loss with action = 0.4 * $1.2M = $0.48M
Comparing the two values, we determine that the Benefit of Action is $0.24M. The effect is positive, but we should also consider the cost incurred:
- Cost of Action = $0.2M
- Net Benefit of Action = $0.04M
- ROI = ($.04M / $0.2M) * 100 = 20%
The conclusion is that the action brings a good, positive return.
This is expected ROI, as it is a probabilistic, not a guaranteed result, that can be used for analysis and planning purposes. The expected return of 20% indicates that, on average, this investment is justified.
More about ROI
Despite this simplified example, we suggest that the ROI of response actions be considered as a variable within a specific range, as both the benefit and the cost of action vary within certain ranges.
We should treat the risk response costs determined in this way as the upper reasonable bound.
To understand which key risks mostly contribute to uncertainty, we can “gamble” with a Monte Carlo simulation that integrates all inherent event and cumulative risks (the Tornado Chart can help with this). We can then focus our efforts on them.
Are you in the upper, wide part of the tornado? Well, we will have to deal with you and reduce you to a residue!
For the residual risks, we can assess whether planning and executing response actions would require excessive, unjustified efforts and whether they can be absorbed through the contingency reserve.
We should view and use project and portfolio risk management as a tool for improving the value-creating system.
Most of risk management boils down to prevention and economic rationality. The majority of risk management activities need to be carried out before implementing the project or portfolio. This means that the appetite for prevention is healthier than the appetite for reaction. And that we need to judge what price we are willing to pay for risk insurance and whether the project or portfolio can absorb the residual risks.
In summary, here is how we can deal with different types of project and portfolio risks:
TYPES OF RISKS | HOW WE DEAL WITH THEM | ANALYTICAL TOOLS |
|---|---|---|
Variability risks | Reducing variability (process improvement, negotiations with suppliers), estimate uncertainty reserve | Monte Carlo Simulation |
Event risks | Assumption testing, ROI-based responses, contingency reserve | Cause-Effect Analysis, Monte Carlo Simulation |
Cumulative risks | System improvement, ROI-based responses, contingency reserve | Cause-Effect Analysis, Trend Analysis, Monte Carlo Simulation |
“Black swans”, “dark risks” | Management reserve based on absorptive capacity/risk appetite | Stress Testing |
Risk management should not be performed in isolation. Risk analysis should be integrated into the overall benefit, cost, and profit model of the project or portfolio (which requires a value-creating system view).
The profit of a project or portfolio can be calculated using Expected Net Present Value (eNPV). Standard NPV works with deterministic (exact) input and output values; eNPV, the better imitation of reality, works with stochastic input and output values.
We first model the standard NPV based on the discounted benefit and cost flows over the entire project or portfolio life cycle, using the average, deterministic values under normal conditions. We also integrate unknown-unknowns through a fixed management reserve for the portfolio, or its proportional part for an individual project.
We then integrate variability risks through the probability distribution of the stochastic parameters and event risks through conditional distributions of the stochastic parameters. The discount rate (this rate by which you hope the value of your investments will grow each year) can also be defined stochastically. Cumulative risks are modeled by gradually changing the stochastic parameters, such as decreasing benefits or increasing costs. Thresholds can also be defined, the crossing of which triggers “penalties” on the flow of net benefits.
In the final push, the Monte Carlo simulation calculates the probability distribution of NPV. The statistical expected value (Mean) of this distribution is the Expected Net Present Value.
The simulation outcome also presents the NPV at the desired confidence (or overconfidence) level. For example, we can conclude that there is an 85% probability that the project profit will reach at least Y million dollars.
In this way, we model uncertainty and turn it from a problem into a manageable factor. NPV becomes a risk-adjusted estimate (eNPV), which is a much better ground for management decisions. This is where the “management” in “risk management” comes from.
We'd love to hear from you.
Share your thoughts in the comments below!
_______________
[1] Monte Carlo simulation is a standard risk analysis tool.
[2] For instance, ISO 31000:2009(E) Risk management — Principles and guidelines defines the following risk treatment options for threats: avoiding, removing the risk source, changing the likelihood, changing the consequences, sharing, and retaining.

