A risk practitioner is selecting a control for a low-likelihood but high-impact risk to a customer database. The proposed safeguard costs more each year than the largest single loss the database could plausibly cause. What should the practitioner recommend?
- AImplement the proposed safeguard regardless of cost, because protecting customer data is a non-negotiable priority for the organisation
- BAccept the risk outright and document the decision, since any control costing more than a single loss is automatically unjustified
- CDefer the decision until the database is re-rated, because the current exposure figure is clearly too low to be trusted here
- DSelect a less costly control or treatment whose expected benefit is proportionate to the assessed exposure of the database Correct
Why A is wrong: Treating data protection as cost-blind feels principled, but spending more than the exposure each year destroys value and ignores the cost-benefit test that control selection requires.
Why B is wrong: Acceptance can be valid, but jumping to it ignores that a cheaper proportionate control may exist; the absolute rule stated here is not how cost-benefit selection works.
Why C is wrong: Deferring to re-rate seems cautious, but nothing suggests the assessment is wrong; delay leaves the risk untreated when a proportionate control could be selected now.
Why D is correct: A control should reduce risk at a cost that does not exceed the exposure it removes, so a proportionate, cheaper option preserves value while still treating the risk.