Business Risk Management Overview
Business Risk Management Overview
Business Brief
Risk is part of the equation for any business. There is no way to protect against every risk. However,
there is a way to identify risk, plan for it, manage it, mitigate it, and protect against it to an extent. Risk
management is key to operating any business in a profitable fashion.
Business risks can be broadly classified into seven categories.
Strategic risks arise from the uncertainty surrounding a company's strategic decisions. Examples of
strategic risks include entering a new market, launching a new product, or making a major investment.
These decisions can be risky because they involve uncertain outcomes and can require significant
resources. Strategic risks also include such factors as changes in technology, competitive pressure, shifts
in customer demand
Financial risks refer to the potential for financial loss or instability. Examples of financial risks include
economic downturns, currency fluctuations, and interest rate changes. Financial risks can also arise from
poor financial management or accounting practices, as well as problems with cashflow or credit risks.
Legal risks arise from the potential for legal action against a company. Examples of legal risks include
lawsuits, regulatory fines, and intellectual property disputes. Legal risks can be costly and time-
consuming to manage.
Operational risks refer to the potential for loss or disruption of business operations. Examples of
operational risks include equipment failure, supply chain disruptions, and employee accidents.
Operational risks can have a significant impact on a company's ability to deliver products or services to
customers.
Reputational risks refer to the potential damage to a company's reputation. Examples of reputational
risks include negative publicity, product recalls, and ethical scandals. Reputational risks can have long-
term consequences for a company's brand and customer loyalty.
Natural hazard risks refer to the potential for damage or disruption from natural disasters such as
hurricanes, earthquakes, or floods. Natural hazard risks can impact a company's physical infrastructure
and supply chain.
Cyber-security risks refer to the potential for data breaches (an incident where sensitive or confidential
information is accessed, stolen, or exposed by an unauthorized person or entity) or cyber-attacks.
Examples of cyber-security risks include malware attacks (a type of software designed to harm
computer systems, steal data, or gain unauthorized access to networks, can come in various forms such
as viruses, worms, trojan horses, and spyware), social engineering (a tactic used by cybercriminals to
manipulate people into divulging sensitive information or performing actions that could compromise
security, can be done through phishing scams, pretexting, baiting, or other forms of deception) and
ransomware (a type of malware that encrypts files on a victim's computer system and demands payment
in exchange for the decryption key). Cyber-security risks can compromise sensitive data and damage a
company's reputation.
The 4Ts model of risk management is a framework used to identify and manage risks in various
industries. The model consists of four components: Tolerate, Treat, Transfer, and Terminate. The first
component, Tolerate, involves accepting a risk, taking it on and continuing with normal operations while
monitoring the situation for any changes. Treat involves taking action to reduce or mitigate the risk, such
as implementing safety measures or improving processes. Transfer involves transferring the risk to
another party, such as through insurance or outsourcing. Finally, Terminate involves eliminating the risk
1
ChatGPT assisted
1
altogether by ceasing the activity that poses the risk. By using the 4Ts model, organizations can
effectively manage risks and minimize potential negative impacts on their operations.
Insurance is a type of financial protection that covers individuals or organizations against various risks.
A policy is a contract between an insurer and the insured, providing coverage for specific risks in
exchange for premium payments. The insurer provides indemnity or compensation for losses incurred
by the insured due to events covered by the policy. Risk exposure is the likelihood of experiencing losses
or damages, and insurance is a way to mitigate that risk exposure. Insurance can provide coverage against
various risks, such as accidents, natural disasters, theft, and more.
In conclusion, businesses face a wide range of risks that require careful management and mitigation
strategies. Understanding these risks and taking proactive steps to address them is essential for long-term
success.
I. The verbs in the box are used when talking about risk. Check their meanings and put
them under the appropriate heading in the table below.
1. Many small businesses are __________ risk of closure due to the economic downturn.
2. The company’s reputation is __________ threat after the recent data breach.
3. Investing in volatile markets can pose a significant risk ___________ your financial portfolio.
4. Entrepreneurs often face ____________ risks when launching new products in uncertain markets.
5. Organizations must be prepared to be faced __________ threats from cyberattacks in today’s
digital landscape.
III. Complete the text with the verbs from the box.
The 4Ts model of Risk Management provides a comprehensive framework for managing risks in an
organization.
The first stage, _______________(1), involves identifying risks that are too significant to be managed
and deciding to ________________(2) them altogether.
The second stage, _______________(3), involves implementing measures to_________________ (4) the
impact of risks that cannot be eliminated.
The third stage, _________________(5), involves accepting some level of risk as unavoidable and
focusing on managing the potential consequences.
The fourth stage, _________________(6), involves passing the risk to a third party through contracts or
insurance.
2
IV. What type of cybercrime is this?
1. Between 2013 and 2015, Google was tricked out of $100 million. The attacker took advantage of the
fact that the company used Quanta, a Taiwan-based company, as a vendor. The attacker sent a series
of fake invoices to the company that impersonated Quanta, which Google paid.
2. Professional networking giant LinkedIn saw data associated with 700 million of its users posted on a
dark web forum in June 2021, impacting more than 90% of its user base.
3. Emotet is a sophisticated banking trojan that has been around since 2014. It is hard to fight Emotet
because it evades signature-based detection, is persistent, and includes spreader modules that help it
propagate. The trojan is so widespread that it is the subject of a US Department of Homeland
Security alert, which notes that Emotet has cost state, local, tribal and territorial governments up to
$1 million per incident to remediate.
4. In March 2019, the CEO of a UK energy provider received a phone call from someone who sounded
exactly like his boss. The call was so convincing that the CEO ended up transferring $243,000 to a
“Hungarian supplier” — a bank account that actually belonged to a scammer.
5. In its early forms, TeslaCrypt searched for 185 file extensions related to 40 different games including
Call of Duty, World of Warcraft, Minecraft and World of Tanks and encrypted the files. Newer
variants of TeslaCrypt also encrypted Word, PDF, JPEG and other file extensions, prompting the
victim to pay a ransom of $500 in Bitcoin to decrypt the files.
1. __________________: The state of being unsure or not having complete knowledge or information
about a particular situation or event.
2. __________________: A legal action brought by one party against another in a court of law, seeking
a remedy or compensation for some harm or injury suffered.
3. __________________: Any formal legal proceeding initiated by one party against another, usually
seeking redress or compensation for some harm or injury suffered.
4. __________________: The attention given to something by the media or the public, especially in a
positive or favorable way that promotes or enhances its image or reputation.
5. __________________: The process of removing a defective or unsafe product from the market and
notifying customers who have purchased it to return it for a refund or replacement.
6. __________________: A written agreement between an insurer and an insured that outlines the
terms and conditions of the insurance coverage provided.
7. __________________: The scope and extent of protection provided by an insurance policy,
including the types of losses or damages covered and the amount of compensation available.
8. __________________: The payment made by an insurer to an insured to compensate for losses or
damages covered under an insurance policy.
VI. Complete the sentences with the right form of the word in brackets.
1. Being _____________________ (active) in your approach to health and wellness can help you avoid
costly medical bills down the line.
2. Failure to identify and mitigate risks can result in costly claims and damage to the
__________________'s (insure) reputation.
3. It's essential to have adequate _______________ (cover) for unexpected events, such as natural
disasters or accidents.
4. Negative ___________________ (public) can harm a company's image and drive away potential
customers.
5. _____________________ (reputation) risk can lead to loss of business and damage to a company's
brand.
6. A robust risk management culture is the basis for minimizing risk ___________________(expose).
3
Lead-In Business Risk Taker Aptitude
A. If courage and risk-taking are traits necessary for success, how much of a business risk
taker are you? Take this 10-question quiz to find out.
1. When considering starting a new venture, you:
a) Fear that it will be unsuccessful making you reluctant to step out.
b) Weigh the pros and cons beforehand and consult with other business owners and financial
advisors.
c) Are confident of that you will be successful and able to overcome any obstacles.
4
B. Assessing the degree of risk that you are exposed to is the starting point for risk management.
The following list of statements is designed to help employees evaluate the risk of being made
redundant. Put them into two groups according to whether they increase or decrease the risk.
✓ Your company would have to use a headhunter to find someone to replace you.
✓ You have no direct dealings with customers.
✓ The department you work in is well staffed.
✓ Your company is currently restructuring.
✓ You are approaching retirement age.
✓ Your boss resigned but you were not offered the position.
✓ Your salary is at the high end of the scale for your profession.
✓ The work you do is not very demanding.
C. Look at the following situations. How would you weigh the risks in each case? What
decision would you make?
1) You have been given the chance to manage an overseas subsidiary that has been underperforming.
The previous manager was transferred after antagonising the unions with a plan to reorganise work
procedures. If you succeed in this assignment, your long-term career prospects will be very
promising. Would you accept the post or not?
2) Your company has recently patented a new technology. However, developing the technology would
be extremely expensive and there are concerns that it could produce negative health impacts on
users. Would you go ahead or not?
3) You have been contacted by your HR director, who is offering you a one year overseas assignment
in a developing country. You would have to move to the country with your spouse and children.
Would you accept or not?
5
The business of insuring intangible risks is still in its infancy
Companies’ value lies mainly in assets that are tricky to insure
1 THE development, hundreds of years attack last year, is likely to have cost such policies is that they can provide cash
ago, of ship and cargo insurance was companies more than $3bn. One of the quickly, meeting an immediate need after
revolutionary. It marked the start of first events to awaken corporate America misfortune strikes. The downside is that
commercial insurance; protection against to intangible risks, a hack in 2013 of these products tend to cover only a share
loss from looting, fire and the perils of the Target, a retailer, resulted in the theft of of damages.
high seas fostered global trade. But in the data on 70m customers, falling sales and
8 Some once-uninsurable risks can now be
21st century the value of companies profits, and litigation costing millions.
at least partly insured thanks to advances
consists less of solid objects, such as
5 Companies are not oblivious. in modelling, indemnity structures and
boats and buildings, than of weightless, Respondents to a survey last year by Aon, other areas, says Thomas Holzheu of
intangible elements, such as intellectual an insurance broker, ranked reputation as Swiss Re, a reinsurer. Examples include
property (IP), data and reputation. “Today
their top risk (up from fourth in 2013) and business interruption, cyber-risks,
the most valuable assets are more likely
cyber-risk as their fifth (from 18th). But product recalls, damage to reputation and
to be stored in the cloud than in a
there is a big difference between how risk energy prices. A study by Swiss Re points
warehouse,” says Inga Beale, chief
managers perceive such risks and how to cover for hoteliers against a drop in
executive of Lloyd’s of London. boards do. And if firms do seek insurance occupation after widespread travel
2 As Western economies have shifted from against some of these risks, insurers have disruption or a pandemic, and a flight-
making things to providing information not exactly been inundating them with cancellation policy for airlines triggered
and services, the composition of novel products. “Even when policies are by severe events which do no harm to
companies’ assets has shifted too. labelled ‘innovative’ it’s usually to insure airports or aircraft but stop air traffic.
Intangible assets can be hard to define, let physical assets in the sharing economy 9 Most of the action has been in cyber-
alone translate into dollars (under rather than intangibles,” says Magda
insurance. Early policies dealt merely
international accounting standards they Ramada of Willis Towers Watson,
with the immediate costs of an attack—
are defined as “identifiable non-monetary another broker. But in a world where
paying to restore a data centre or for crisis
asset[s] without physical substance”). Yet Airbnb, in effect the world’s largest hotel
management—but insurers now also
their growth has been undeniable. In chain, owns no hotels and Uber, its largest offer “holistic” cover, which includes
2015, estimates Ocean Tomo, a merchant taxi firm, owns no cabs, such policies are knock-ons such as physical damage, loss
bank, they accounted for 84% of the value of limited use. Those that do protect
of revenue and litigation costs. But at the
of S&P 500 firms, up from just 17% in assets such as data, IP and reputation are
same time, insurers have become more
1975 (see chart). This does not merely often expensive and bespoke, and include
aware of their “silent” exposure to cyber-
reflect the rise of technology giants built strict exclusions and limits. risks under existing policies. Increasingly
on algorithms; manufacturers have 6 Insurers’ caution is understandable. they are excluding them from
evolved too, selling services alongside jet
Intangible risks are not only new and conventional policies, such as property
engines and power drills, and crunching
complex. “They’re a bit like not-yet-set cover, or selling cyber bolt-ons. A huge
data collected by smart sensors.
jelly,” says Julia Graham of Airmic, a gap in coverage remains. Cybercrime
3 As the importance of intangibles has trade body. “Their shape constantly caused around $550bn in losses last year,
grown, so has companies’ need to protect changes.” Underwriters like to look at according to Aon. Companies are covered
themselves against “intangible risks” of past data on events’ frequency as well as for only 15% of potential cyber-risk
two types: damage to intangible assets clients’ current exposure—which may be losses, against 59% for property, plant
(eg, reputational harm caused by a tweet next to impossible when assessing the and equipment losses.
or computer hack); or posed by them (say, risk and impact of a cyberattack, a sexual- 10 Companies also have to do more
physical damage or theft resulting from a harassment scandal, which would have to protect themselves. Just as insurance
cyberattack). However, insurance against been very differently priced even a couple
was only part of the answer to fire and
such risks has lagged behind their rise. of years ago, or a celebrity’s throwaway
maritime risk, it is only part of the answer
“The shift is tremendous and the exposure tweet. (Snap’s share price has fallen by
to modern perils. “Instead of buying
huge,” says Christian Reber of the Boston more than one-third in six months,
insurance against a damaged reputation,
Consulting Group, “but the insurance suggesting deeper troubles than Ms firms should be looking at preventing it in
industry is only at the early stage of Jenner’s disapproval.) “The problem with the first place,” says Richard Wergan of
finding solutions to close the gap.” intangible assets is that they have fuzzy
Edelman, a communications-marketing
boundaries, and for insurance to work you
4 Examples of potential damage are not firm. Plenty of cyber-breaches could
want crispness,” says David Teece, of the
hard to find. In February a tweet by Kylie doubtless have been avoided if software
Jenner, a celebrity with over 25m University of California. had simply been kept up to date. Insurers
followers, rhetorically asking whether 7 But some underwriters are starting to need to catch up with the intangible age;
anyone still used Snapchat, coincided come up with more suitable policies. One but so do their clients.
with a drop of 6% in the share price of is parametric cover, which pays a fixed
Snap, the messaging app’s owner. amount automatically after a defined
NotPetya, a widespread ransomware event, such as a hack. The advantage of
6
Speaking
Discuss these questions. (ChatGPT generated)
1. In addition to IP, data and reputation, what are some examples of intangible risks that businesses face?
How are these risks different from tangible risks?
2. Why do you think the insurance industry has been slow to develop products that address intangible
risks? What are some challenges that insurers face in this area?
3. What role do you think governments and regulators should play in promoting the development of
insurance products for intangible risks? Should they provide incentives for insurers to invest in this
area?
Vocabulary
A. Find the words or expressions in the text that correspond to the following definitions.
1. (para 1) the act of stealing goods, often by force or during a time of chaos or unrest -
_________________
2. (para 1) something that cannot be physically touched or seen, such as intellectual property, brand
reputation, or goodwill - _______________________
3. (para 1) a large building used for storing goods, typically on a commercial or industrial scale -
____________________
4. (para 2) any resource owned by a company or individual that has economic value and can be used to
generate income, such as property, equipment, or cash - ____________________
5. (para 2) a set of guidelines and principles used to ensure consistency and transparency in financial
reporting across different countries and jurisdictions - ____________________
6. (para 2) the process of analyzing and manipulating large amounts of data to extract insights or
patterns, often done using software or algorithms to automate the process - _______________
7. (para 4) to become aware of something - ___________________
8. (para 4) the process of taking legal action, such as filing a lawsuit or going to court, to resolve a
dispute between two parties - ____________________
9. (para 5) unaware or not paying attention to what is happening around you - ______________
10. (para 5) an economic system in which individuals share resources, such as cars or homes, with others
in exchange for payment, typically by means of the internet - ________________
11. (para 5) custom-made or tailored to a specific individual or purpose - ___________________
12. (para 6) careful consideration and attention to potential risks or dangers - ________________
13. (para 6) extremely difficult or unlikely to happen - ___________________
14. (para 6) a casual or insignificant message posted on social media that is not intended to be taken
seriously - ____________________
15. (para 6) unclear or indistinct, lacking in detail or precision - __________________
16. (para 6) clarity and sharpness in appearance, sound, or taste - __________________
17. (para 8) cause something to happen or set off a reaction - __________________
18. (para 9) taking a comprehensive and integrated approach that considers all aspects of a situation or
problem - ___________________
19. (para 9) being exposed to risks without being aware of them or without any visible signs or
symptoms - _________________
20. (para 9) additional features or components that can be added to a digital device or system to enhance
its functionality or security - ____________________
7
B. Who do these companies and professionals do? Match the terms with definitions.
4. underwriter
5. insurance broker
6. reinsurer A. I help individuals or businesses find
insurance coverage. I work with multiple
insurance companies to find the best
coverage at the best price for my clients
A B
1. peril a. statistical analysis 1. foster a. provoke
2. looting b. progress 2. evolve b. promote
3. data crunching c. hazard 3. inundate with c. develop
4. downside d. stealing 4. trigger d. flood
5. advances e. drawback 5. abide
(Reading 2)
6. cripple e. stem
7. impinge on f. obey
C
8. roil g. impede, hamper
1. bespoke a. vague
9. contain h. affect
2. crisp b. innovative
10. abide i. disturb
3. tricky c. customized
4. in one’s infancy d. precise
5. fuzzy e. at an early stage
6. novel f. challenging
8
D. Complete each set of sentences with the same word.
Complete the sentences below with the appropriate form of either luck or chance.
There are many expressions where two words are combined with and. However, such expressions are
used in different ways depending on whether they are adjectives, adverbs, nouns or verbs.
Choose words from the list to complete the expressions with ‘and’.
1. When you start a new business you don’t always have a precise business model, which means that
very often you have to learn by ______________________ .
2. Small businesses can learn from experienced entrepreneurs who know ______________________ of
obtaining finance.
3. Any new venture is bound to go through difficult moments, so being able to handle the _________
_____________ of starting your own business is critical.
4. The company's financial situation was ______________________ for a while and the prospects
seemed vague.
5. After the system update, the website was ______________________ smoothly.
6. The startup was considered an ______________________ player in the industry.
7. Any successful negotiation involves some ______________________.
8. The consultant offered some general recommendations – some _____________________ for cyber
security awareness.
10
Listening 1 Beyond ChatGPT: what chatbots mean for the future
Look at how ChatGPT answers the question about the potential risks and benefits of the
technology.
Speaking
In your opinion, what are the potential risks and benefits of the developments in the sphere of AI?
Can you think of any possible implications for education, business, everyday life?
11
Reading 2 Cyber-Risks
Read the text and make a list of
• cyber-security risks and threats mentioned in the text
• possible responses to these threats
• words that refer to negative trends and/or events
Speaking
Discuss these questions. (ChatGPT generated)
1. What are some of the basic steps that individuals and organizations can take to protect themselves
from cyber-attacks?
2. How do cyber-attacks impact the broader economy, and what steps can be taken to mitigate these
effects?
3. What are some of the latest trends and developments in the cyber-security landscape, and how are
attackers adapting to new security measures?
4. What role do government agencies and law enforcement officials play in combatting the
ransomware threat, and what challenges do they face in doing so?
5. What legal and ethical considerations arise in the event of a successful ransomware attack, and how
should organizations respond to such incidents?
6. How does the global nature of the threats to cyber-security impact international cooperation and
collaboration among law enforcement agencies and governments?
7. What are the potential long-term consequences of cyber-attacks on society, and how can we work
to prevent them?
13
Glossary
Business Brief
protect against
identify/manage / mitigate risks
risk management
strategic / financial / legal / operational / reputational / cyber-security risks
uncertainty
risky
risks arise from
legal action against
lawsuit
negative publicity
product recall
natural hazard
data breaches
malware attacks
social engineering
ransomware
compromise sensitive data
tolerate / treat / transfer /terminate a risk
take on a risk
eliminate a risk
pose a risk
insurance
covers sb against a risks
policy
insurer
the insured
coverage for specific risks
premium payment
indemnity
incur losses
risk exposure
proactive
Reading 1
intangible assets/risks
international accounting standards
litigation
caution
holistic cover/approach
Listening 1
generative AI/chatbot
copyright/trademark infringement
sue
14
plagiarism
Reading 2
cripple
hamper
impede
at stake
vulnerable
take precautions
ransom payment
abide by standards
contain risks
15