LOGBOOK

HELP

1 / 35
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

Where does risk management sit in the "Knowing vs. Not-Knowing" matrix, and what does it actually cover?

Answer

Risk management handles the known knowns — risks whose cause-and-effect we already understand and deal with daily.

The four Knowing × Awareness quadrants — risk management owns only the known-knowns; resilience covers the black-swan corner

* The four Knowing × Awareness quadrants — risk management owns only the known-knowns; resilience covers the black-swan corner. *

The matrix has four quadrants based on two axes — Wissen/Unwissen (do we know the mechanism?) and Bekannt/Unbekannt (are we aware of the risk at all?):

Wissen (we understand it) Unwissen (we don't)
Bekannt (we're aware) Cause-effect, daily handling → Risk Management Known knowledge gap, dark figure → shrunk by research
Unbekannt (we're unaware) Roughly known statistically but inaccessible per case (taboos, denial) → knowledge sharing Black-swan territory — unforeseeable even with science → resilience, agility

Why this matters: Risk management is powerful but limited — it can only manage what you can name and measure. Black swans (the bottom-right quadrant — unforeseeable even with science) live outside its reach, and resilience is the discipline that picks up there.

Tip: Rumsfeld's "known knowns / known unknowns / unknown unknowns" is the same idea: RM covers known-knowns; research shrinks known-unknowns; resilience prepares for unknown-unknowns.

Go deeper:

A black swan (Cygnus atratus) in Tasmania, Australia
A black swan (Cygnus atratus) in Tasmania, Australia
Charles J. Sharp · CC BY-SA 4.0 · Wikimedia Commons
or press any other key

Question

How does risk management differ from resilience as a security strategy?

Answer

Risk management = short-term, defends known risks on the existing system. Resilience = long-term survival, evolves the whole organisation to absorb any disruption.

Risk Management Resilience
Goal Short-term: avoid losses Long-term: ensure survival
Approach Management overlay on existing system, annual audit cycle Continuous, evolutionary, systemic
Measures Reactive, delegated Anticipating, shaping the future
Focus Limiting damage from known risks Preparing for any unknown disruption — adapt and learn
Responsibility Assigned risk managers + dedicated risk owners Embedded in the organisation, part of the culture

Why both are needed: RM is mechanical and audit-friendly — useful for board reporting, insurance, compliance. But it assumes the threats you'll face look like the ones you've already catalogued. Resilience covers the gap when reality surprises you (NotPetya, COVID, novel zero-days). The WEF's Cyber Resilience Index (CRI) is one published framework for measuring it.

Tip: A ball-in-a-bowl image is often used: RM tries to keep the ball still on a flat surface; resilience builds the bowl so the ball returns to centre after a kick.

Go deeper:

  • doc Cyber resilience (Wikipedia) — the discipline of continuing to deliver outcomes despite attacks, contrasted with prevent-and-avoid risk management.
or press any other key