Where does risk management fit in, and why does its importance vary so much between companies?
It is the function that looks at all of a company's risks — cyber being one kind among many — so the quality of the cyber security architecture feeds directly into its picture; how central it is depends on the industry.
Risk management does not specialise in IT. It aggregates everything that could damage the company — market, credit, legal, operational, supply-chain, reputational — and puts it in front of the board in a comparable form. Cyber risks, meaning the risks arising from IT systems, OT plants and everything else digital, are one input to that consolidated view.
Its weight is industry-dependent for structural reasons. Banks, insurers, energy utilities, healthcare and critical-infrastructure operators are supervised, and formal risk management is a regulatory obligation with dedicated staff and reporting lines. A mid-sized manufacturer may run the same function as a quarterly workshop.
Why the architect should care either way:
- Risk management is often the channel through which cyber risk reaches the people who allocate money. A risk that is not in the register does not exist at budget time.
- The quality of the architecture changes the numbers. Segmentation and containment reduce the impact half of the risk calculation; documentation and transparency change the confidence with which any of it can be assessed at all.
- It supplies the second half of the pair of governing questions: information security asks what must be protected, risk management asks how much risk is bearable — and that answer is what makes a control "appropriate" rather than arbitrary.
Go deeper:
Wikipedia — ISO 31000 — the enterprise-wide risk framework cyber risk has to be reported into, alongside every other kind.