Risk

An uncertain event or situation that, if it happens, could help or harm one or more project objectives.

Key Points

  • Risks are uncertain; they may be threats (negative) or opportunities (positive).
  • Each risk is characterized by probability, impact, and often timing and urgency.
  • Common responses include avoid, mitigate, transfer, or accept for threats; exploit, enhance, share, or accept for opportunities.
  • Risks are logged in a risk register, assigned to a risk owner, and reviewed throughout the project.

Example

On a software project, a new third-party API may become available mid-project. If it is stable, it could reduce development time by 20% (opportunity). If it is delayed or incompatible, it could require rework and push the schedule (threat). The team records the risk, estimates probability and impact, and plans responses for both outcomes.

PMP Example Question

A project manager notes that a supplier strike might occur next month, which could delay critical hardware delivery, but an early shipment discount could also accelerate the schedule. What is this best described as?

  1. An issue
  2. A risk
  3. An assumption
  4. A constraint

Correct Answer: B — An uncertain event that could either help or hinder project objectives.

Explanation: A risk is uncertain and can have positive (opportunity) or negative (threat) effects; issues are current problems, assumptions are taken as true, and constraints limit choices.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Stop Managing Admin. Start Leading the Future!

HK School of Management helps you learn AI prompt engineering for project work. Move beyond status reports and risk logs with practical prompt frameworks for everyday tasks. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Enroll Now