Mitigated Risks

Risks that the Scrum Team has reduced to an acceptable level by executing planned responses during the project.

Key Points

  • Mitigation lowers a risk's probability, impact, or both to an agreed acceptable level.
  • Actions are planned, implemented, and tracked by the Scrum Team as part of ongoing risk management.
  • Residual risk may remain and should be monitored and reassessed regularly.
  • Common tactics include design changes, tests, controls, spikes, buffers, and process improvements.

Example

During Sprint 3, the team identifies a risk that a third-party API might throttle requests, slowing user logins. They implement caching, retries with backoff, and a circuit breaker. After testing, the likelihood and impact are both reduced, and the risk is marked as mitigated and monitored for residual effects.

PMP Example Question

In an agile project, the team adds rate limiting and a circuit breaker to handle potential API throttling. The risk's probability and impact are now low and recorded as such. What best describes this risk?

  1. Accepted risk
  2. Mitigated risk
  3. Transferred risk
  4. Issue

Correct Answer: B — Mitigated risk

Explanation: The team implemented actions that reduced the likelihood and/or impact to an acceptable level, which is mitigation.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Lead with clarity, influence, and outcomes.

HK School of Management offers a practical Leadership for Project Managers course for real projects, tight deadlines, and cross-functional teams. Learn to set direction, align stakeholders, and drive commitment without relying on title. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More