Question
Where does risk management sit in the "Knowing vs. Not-Knowing" matrix, and what does it actually cover?
Answer
Risk management handles the known knowns — risks whose cause-and-effect we already understand and deal with daily.
* The four Knowing × Awareness quadrants — risk management owns only the known-knowns; resilience covers the black-swan corner. *
The matrix has four quadrants based on two axes — Wissen/Unwissen (do we know the mechanism?) and Bekannt/Unbekannt (are we aware of the risk at all?):
| Wissen (we understand it) | Unwissen (we don't) | |
|---|---|---|
| Bekannt (we're aware) | Cause-effect, daily handling → Risk Management | Known knowledge gap, dark figure → shrunk by research |
| Unbekannt (we're unaware) | Roughly known statistically but inaccessible per case (taboos, denial) → knowledge sharing | Black-swan territory — unforeseeable even with science → resilience, agility |
Why this matters: Risk management is powerful but limited — it can only manage what you can name and measure. Black swans (the bottom-right quadrant — unforeseeable even with science) live outside its reach, and resilience is the discipline that picks up there.
Tip: Rumsfeld's "known knowns / known unknowns / unknown unknowns" is the same idea: RM covers known-knowns; research shrinks known-unknowns; resilience prepares for unknown-unknowns.
Go deeper:
There are unknown unknowns (Wikipedia) — the known-knowns / known-unknowns / unknown-unknowns framing and its use in risk.
Black swan theory (Wikipedia) — the unpredictable, high-impact events that live in the unknown-unknowns corner.
Note saved — thanks!
Question
How does risk management differ from resilience as a security strategy?
Answer
Risk management = short-term, defends known risks on the existing system. Resilience = long-term survival, evolves the whole organisation to absorb any disruption.
| Risk Management | Resilience | |
|---|---|---|
| Goal | Short-term: avoid losses | Long-term: ensure survival |
| Approach | Management overlay on existing system, annual audit cycle | Continuous, evolutionary, systemic |
| Measures | Reactive, delegated | Anticipating, shaping the future |
| Focus | Limiting damage from known risks | Preparing for any unknown disruption — adapt and learn |
| Responsibility | Assigned risk managers + dedicated risk owners | Embedded in the organisation, part of the culture |
Why both are needed: RM is mechanical and audit-friendly — useful for board reporting, insurance, compliance. But it assumes the threats you'll face look like the ones you've already catalogued. Resilience covers the gap when reality surprises you (NotPetya, COVID, novel zero-days). The WEF's Cyber Resilience Index (CRI) is one published framework for measuring it.
Tip: A ball-in-a-bowl image is often used: RM tries to keep the ball still on a flat surface; resilience builds the bowl so the ball returns to centre after a kick.
Go deeper:
Cyber resilience (Wikipedia) — the discipline of continuing to deliver outcomes despite attacks, contrasted with prevent-and-avoid risk management.
Note saved — thanks!