Blog
Blog

Risk management in the company – top or flop?

CISO 30 October 2025 By fortControl Editorial Team

Risk is part of doing business. The decisive question is therefore not whether a company has risks, but how deliberately and systematically it deals with them.

Financial risks, staffing bottlenecks, supply failures or regulatory change have long been part of classic risk management for many companies. But increasing digitalisation adds another dimension: IT and cyber risks can today have just as great an impact on business operations as traditional corporate risks.

Contemporary risk management must therefore consider the company as a whole – including its digital dependencies.

Risk management – desirable, but not mandatory?

It is not quite that simple.

Swiss contract law does not prescribe a specific formal risk management system for every company. Dealing with material corporate risks is, however, part of responsible corporate governance.

In a Swiss public limited company, the board of directors is required under Art. 716a of the Swiss Code of Obligations to ensure, among other things, the ultimate direction of the company, the definition of its organisation, the structuring of financial control and the ultimate supervision of management.

Anyone who runs and oversees a company must therefore also know which material risks could jeopardise its objectives, its business activity or its existence.

For companies required to prepare a management report under Art. 961c of the Swiss Code of Obligations, the risk assessment is even mentioned explicitly: the report must, among other things, state that such an assessment has been carried out.

Risk management is therefore far more than an annual list of possible problems. It is a management instrument.

At its core, it comes down to four questions:

  • Which risks exist?
  • How relevant are they for the company?
  • What are we doing about them?
  • Who is responsible?

The Swiss federal SME portal describes a comparable process: risks are identified, assessed and prioritised, then analysed and treated with suitable measures.

Risks can, for example, be accepted, reduced, avoided or transferred.

The goal: to act before you have to react.

What makes risk management good

Effective risk management does not have to be complicated. It does, however, need a clear structure.

This includes in particular:

Identifying risks systematically
Not every conceivable scenario has to be analysed down to the last detail. What matters is knowing the risks that are material for the company.

Assessing risks transparently
How likely is an event? And what impact would it have on finances, operations, reputation, compliance or customers?

Defining responsibilities
A risk without a responsible person often remains nothing more than an entry in a list.

Defining and tracking measures
What is to be done? By when? By whom? And has the measure actually been implemented?

Reviewing risks regularly
Companies change – and so do their risks. A risk assessment is therefore not a one-off exercise.

It is precisely this last point that usually reveals whether risk management is truly practised in a company – or only exists on paper.

All well and good – but without the cyber stuff, please?

Finances? Of course. Staff? Naturally. Supply chains? Obviously.

But cyber risks?

In some companies, IT and cyber topics are still seen primarily as a task for the IT department. Yet this separation works less and less well.

Business processes today are digitally interconnected. Data sits in cloud services, employees access systems on the move, suppliers are technically integrated, web shops generate revenue and central applications are operated by external service providers.

An IT outage is therefore often no longer a purely IT problem.

It can mean that:

  • employees can no longer work
  • orders cannot be processed
  • production or logistics come to a standstill
  • customer data is affected
  • services are unavailable
  • contractual obligations cannot be met
  • revenue and reputation suffer

A cyber risk thus very quickly becomes a corporate risk.

Cyber risks belong in the overall picture

Modern risk management should therefore not consider IT and cyber risks in isolation. What matters is that they become comparable with other corporate risks.

What, for example, does a multi-day outage of a central ERP system mean compared to a supply failure? What impact would the loss of important data have? How critical is the dependency on a single cloud provider?

Only when such risks are considered together can management prioritise sensibly.

IT and cyber risks can either be integrated directly into company-wide risk management or handled in more detail within an information security management system – ISMS for short.

What matters less is where a risk is managed. What matters is that it is visible, that it is assessed and that it has a responsible person.

The Swiss ICT minimum standard as a guide

For a structured assessment of their own cyber resilience, companies can draw on the Swiss ICT minimum standard, for example.

It offers companies a systematic framework for assessing their ICT security and cyber resilience and for making potential improvements visible.

For most industries it serves as a recommendation and a point of orientation. For certain areas of critical infrastructure, binding sector-specific requirements apply instead.

The approach can also be helpful for ordinary SMEs: not because every company has to implement every single measure identically, but because a standardised procedure helps to identify blind spots and to assess one’s own security maturity in a structured way.

A risk management tool? But I have Excel.

Of course risks can be managed in Excel. For a small risk catalogue with few responsible people, that may even be entirely sufficient.

It becomes more difficult as soon as risk management grows: who is working with which version? When was an assessment changed? Why was a risk accepted? Which measure belongs to which risk? Who has to implement it? Which deadlines have been missed? And how has the risk situation changed since the last management meeting?

At that point at the latest, a simple spreadsheet quickly turns into an administrative construct.

The problem is not Excel. The problem arises when a spreadsheet is expected to replace a process.

From risk register to manageable process

Professional risk management therefore needs more than a list of probabilities and impact figures. It needs an end-to-end process:

  1. 1 Identify
  2. 2 Assess
  3. 3 Decide
  4. 4 Act
  5. 5 Monitor

Monitoring leads back to identification: risks change, and the process starts again.

Risk management as an end-to-end cycle rather than an annual list.

Risks have to be assigned to responsible people. Measures need deadlines and owners. Changes should be traceable. And management needs an overview that shows where action is actually required.

This is exactly where fortControl comes in.

Risk management with fortControl

fortControl helps companies to record and assess risks in a structured way and to link them to concrete measures.

Instead of spreading information across various Excel files, documents and emails, a central and traceable view of risks and their treatment emerges.

With fortControl, risk management becomes:

Traceable
Assessments, changes, decisions and measures remain documented and can be reconstructed later.

Accountable
Risks and measures are assigned to specific owners. This makes it visible who has to act.

Collaborative
Internal teams and, where needed, external partners or consultants can work on the same topics in a structured way.

Manageable
Measures can be scheduled, prioritised and tracked.

Clear
Filters, reports and dashboards show which risks are particularly relevant and where action is required.

Connected
Risks can be linked to assessments, measures and requirements from information security frameworks.

This turns a static risk register into a management instrument.

And what does an ISMS have to do with it?

An information security management system applies exactly this basic idea to information security.

Here, too, the point is not to implement as many security measures as possible. The point is to define the right measures for the relevant risks.

An ISMS creates a structured framework for this: risks are recorded and assessed, responsibilities defined, measures implemented and their effectiveness reviewed regularly.

This makes it possible to place cyber risks in a broader corporate context – instead of treating them independently of the rest of risk management.

This is particularly important for SMEs. Resources are limited. Investment should therefore not be spread evenly, but concentrated where risks are genuinely relevant for the company.

Top or flop?

Risk management is top when it supports decisions.

When management knows which risks are truly relevant. When responsibilities are clear. When measures are implemented and reviewed. And when changes become visible before they turn into a problem.

Risk management becomes a flop when an Excel list is updated once a year and nobody actively manages the risks it contains.

Because in the end it is not about having as many risk entries as possible. It is about asking the right questions in good time:

What could jeopardise our objectives? How great is the risk? What are we doing about it? And who is taking care of it?

With fortControl, companies create a structured basis for assessing risks transparently, managing measures consistently and treating information security as part of overall corporate risk.

Because risks do not disappear simply because they are not on a list.

Loslegen

Risiken im Blick. Sicherheit im Griff.

Lernen Sie fortControl in einer persönlichen Demo kennen.

fortControl – Risikomanagement und Informationssicherheit einfach steuern.