Risk Sharing

A positive risk response in which the project assigns ownership of an opportunity to an external party that is best positioned to realize and capture its benefits.

Key Points

  • Used for opportunities (positive risks), not threats.
  • Ownership and accountability to pursue the upside are shifted to a third party more capable of delivering the benefit.
  • Common mechanisms include partnerships, joint ventures, licensing, and incentive-based contracts.
  • Requires clear agreements on roles, benefit sharing, success criteria, and ongoing monitoring.

Example

The project team develops a new analytics feature but lacks market access. They form a joint venture with a major vendor that takes the lead on commercialization in exchange for a revenue share. The vendor owns the opportunity and is best placed to capture the upside.

PMP Example Question

A software project identifies a significant growth opportunity if a global reseller launches the product in new markets. The team signs a partnership granting the reseller the lead role and a share of profits to pursue this upside. Which risk response strategy is being used?

  1. Exploit
  2. Share
  3. Enhance
  4. Accept

Correct Answer: B - Risk sharing (giving opportunity ownership to a partner best able to realize it)

Explanation: The team transfers ownership of the opportunity to a third party that can best capture the benefit, which is the essence of risk sharing.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Launch your career!

HK School of Management offers training in project management, job-search strategies, and career growth. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More