Risk Avoidance

A risk response in which the team removes the threat or alters the plan so the project is not exposed to its effects.

Key Points

  • Eliminates the risk source or changes scope, approach, or schedule to avoid exposure.
  • Best used for high-impact threats when a feasible alternative exists.
  • Often requires change requests and sponsor or stakeholder approval.
  • Aims to drive the probability to zero or block any potential impact.

Example

A project faces regulatory uncertainty if hosting data in Country X. To avoid the threat, the team selects a compliant hosting region with clear regulations, removing the risky location from the plan.

PMP Example Question

During planning, a custom cryptography component is identified as technically uncertain and could cause major delays. Which action best represents risk avoidance?

  1. Replace the custom component with a certified commercial library and remove the custom build from scope.
  2. Purchase insurance to cover potential rework costs.
  3. Add additional testing and quality checks to reduce defects.
  4. Accept the risk and add schedule reserve.

Correct Answer: A — Avoid the risk by changing scope to remove the risky work

Explanation: Avoidance eliminates the threat by altering the plan so the project is no longer exposed, such as removing the risky custom development.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build complete project plans in minutes with AI

Learn how to use AI to create charters, WBSs, schedules, risk registers, and executive reports while staying in control. This course gives you prompt templates and practical workflows based on real project work. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More