Risk Seeking

A utility-function stance where a stakeholder favors higher-risk choices, even when they offer only a small potential increase in project value or benefits.

Key Points

  • Reflects a convex utility curve: uncertain outcomes with potential upside are preferred over safer options of similar expected value.
  • Leads to selecting high-variance strategies and more aggressive opportunity responses (exploit, enhance).
  • Must align with organizational risk appetite and tolerances and be recorded in the risk management plan.
  • Impacts reserve planning and decision techniques (e.g., EMV adjusted by utility) and requires clear stakeholder communication.

Example

A product sponsor chooses an unproven cloud service that might cut costs by 3% but carries notable integration risk, preferring the uncertain upside over a stable vendor with nearly the same expected benefit.

PMP Example Question

During release planning, the sponsor consistently selects options with higher uncertainty for only a minor potential gain in benefits compared to safer alternatives. Which utility-function category best describes the sponsor?

  1. Risk-averse
  2. Risk-neutral
  3. Risk-seeking
  4. High risk appetite but risk-averse utility

Correct Answer: C — Risk-seeking

Explanation: Choosing greater uncertainty for a small possible increase in benefit indicates a risk-seeking utility preference.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build complete project plans in minutes with AI

Learn how to use AI to create charters, WBSs, schedules, risk registers, and executive reports while staying in control. This course gives you prompt templates and practical workflows based on real project work. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More