{"id":148135,"date":"2023-02-08T12:59:35","date_gmt":"2023-02-08T15:59:35","guid":{"rendered":"https:\/\/www.pmgacademy.com\/itsm\/risk-management-how-not-to-do-it\/"},"modified":"2025-12-16T14:55:44","modified_gmt":"2025-12-16T17:55:44","slug":"risk-management-how-not-to-do-it","status":"publish","type":"post","link":"https:\/\/sandbox2.institutopmg.com\/en\/articles\/risk-management-how-not-to-do-it\/","title":{"rendered":"Risk management: how NOT to do it"},"content":{"rendered":"\r\n<p>If you work with information technology, you know how important risk management is. After all, we&#8217;re dealing with confidential information, complex systems, and a host of other factors that can put the security of your business at risk. Unfortunately, many companies still make crucial mistakes when it comes to <a href=\"https:\/\/itsmhouse.com\/how-to-manage-risks\/\">managing risks<\/a>.<\/p>\r\n<p>So, let&#8217;s get to it. Here are some of the main ways NOT to do risk management:<\/p>\r\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Navegue por t\u00f3picos de interesse:<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/sandbox2.institutopmg.com\/en\/articles\/risk-management-how-not-to-do-it\/#Ignoring_the_importance_of_risk_management\" >Ignoring the importance of risk management<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/sandbox2.institutopmg.com\/en\/articles\/risk-management-how-not-to-do-it\/#Not_having_a_contingency_plan\" >Not having a contingency plan<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/sandbox2.institutopmg.com\/en\/articles\/risk-management-how-not-to-do-it\/#Not_training_employees\" >Not training employees<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/sandbox2.institutopmg.com\/en\/articles\/risk-management-how-not-to-do-it\/#Not_updating_systems_and_software\" >Not updating systems and software<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/sandbox2.institutopmg.com\/en\/articles\/risk-management-how-not-to-do-it\/#Not_monitoring_suspicious_activities\" >Not monitoring suspicious activities<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Ignoring_the_importance_of_risk_management\"><\/span>Ignoring the importance of risk management<span class=\"ez-toc-section-end\"><\/span><\/h2>\r\n<p>One of the biggest mistakes companies make is simply ignoring the importance of risk management. This can happen for various reasons: perhaps the IT team is too busy with other tasks, perhaps the company doesn&#8217;t have a sufficient budget to invest in security, or perhaps the team is simply not aware of the risks involved.<\/p>\r\n<p>Whatever the reason, the truth is that ignoring the importance of risk management can be disastrous. You&#8217;re basically leaving the security of your business to chance, which can lead to serious problems.<\/p>\r\n<h2><span class=\"ez-toc-section\" id=\"Not_having_a_contingency_plan\"><\/span>Not having a contingency plan<span class=\"ez-toc-section-end\"><\/span><\/h2>\r\n<p>Another common mistake is not having a contingency plan in case of failures or security breaches. When a vulnerability is detected or an attack occurs, it&#8217;s important to have a plan ready to act quickly and minimize the damage. Otherwise, the team may end up lost and unsure of how to handle the situation.<\/p>\r\n<h2><span class=\"ez-toc-section\" id=\"Not_training_employees\"><\/span>Not training employees<span class=\"ez-toc-section-end\"><\/span><\/h2>\r\n<p>Employees are the first line of defense for any company when it comes to security. However, many companies do not invest time or resources in <a href=\"https:\/\/www.axelos.com\/certifications\/propath\/mor-risk-management\/\">training their employees<\/a> in good information security practices. As a result, they may end up making mistakes that put the security of the company at risk.<\/p>\r\n<h2><span class=\"ez-toc-section\" id=\"Not_updating_systems_and_software\"><\/span>Not updating systems and software<span class=\"ez-toc-section-end\"><\/span><\/h2>\r\n<p>The systems and software your company uses are constantly updated to fix security flaws and vulnerabilities. However, many companies fail to update them regularly, which means they are leaving doors open to invasions.<\/p>\r\n<h2><span class=\"ez-toc-section\" id=\"Not_monitoring_suspicious_activities\"><\/span>Not monitoring suspicious activities<span class=\"ez-toc-section-end\"><\/span><\/h2>\r\n<p>Finally, many companies do not monitor their network activities to detect possible threats. This means they may be under attack for months or even years without knowing it. Monitoring network activities is an important way to identify potential threats and act before it&#8217;s too late.<\/p>\r\n<p>So, folks, these are some of the main ways NOT to do risk management. If you want to ensure the security of your business, it&#8217;s important to avoid these mistakes and invest in good information security practices. Remember: the cost of a security breach can be much higher than the cost of preventing it.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>If you work with information technology, you know how important risk management is. After all, we&#8217;re dealing with confidential information, complex systems, and a host of other factors that can put the security of your business at risk. Unfortunately, many companies still make crucial mistakes when it comes to managing risks. So, let&#8217;s get to [&hellip;]<\/p>\n","protected":false},"author":85233,"featured_media":148136,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[8044],"tags":[10109,9571,9704,10110,9451,9502,9503,9452,10111,9493,10112,10113,10114],"class_list":["post-148135","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","tag-gerenciamento-de-riscos-2","tag-gerenciamento-de-servicos-de-ti-2","tag-gsti-2","tag-how-to-manage-risks","tag-it-service-management-2","tag-itil-2","tag-itil-4-2","tag-itsm-2","tag-riscos","tag-risk-management","tag-risk-security-it","tag-risks","tag-security-breach"],"acf":[],"_links":{"self":[{"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/posts\/148135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/users\/85233"}],"replies":[{"embeddable":true,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/comments?post=148135"}],"version-history":[{"count":1,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/posts\/148135\/revisions"}],"predecessor-version":[{"id":149133,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/posts\/148135\/revisions\/149133"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/media\/148136"}],"wp:attachment":[{"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/media?parent=148135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/categories?post=148135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sandbox2.institutopmg.com\/en\/wp-json\/wp\/v2\/tags?post=148135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}