After phishing controls and a cyber policy are in place, leaders accept a small documented residual cyber exposure and attach an incident playbook with an owner. Which path does this follow?
Select an answer to reveal the explanation.
Short Explanation
Do the sensible hardening, buy the sensible cover, then own the leftover nibble with a playbook and a name on it. That's the full treat-then-accept path — not "accept" as code for doing nothing.
Full Explanation
A complete treatment path often combines reduction (controls), transfer (insurance), and conscious acceptance of residual risk that remains within appetite. Documenting that residual with ownership and a playbook ensures the organization can respond if the residual materializes. Skipping controls or documentation breaks the sequence.