Risk Has No Department: Building an Enterprise-Wide Risk Ownership Culture Through ESRM

Why security leaders must stop “owning” all organizational risk and start assigning accountability to the people who create, manage, and influence it.

Key Highlights

  • Traditional security models wrongly assumed security 'owned' all risks, leading to accountability gaps and ineffective mitigation.
  • ESRM shifts risk ownership to asset owners, integrating risk management into daily business decisions and fostering a culture of shared responsibility.
  • Creating a risk ownership matrix helps map risks to responsible functions, clarifying roles and decision rights across the organization.
  • Measuring risk management effectiveness through KPIs and KRIs enables organizations to track accountability and improve controls over time.
  • Leadership and board engagement are critical for embedding risk ownership, with top-down modeling and clear governance structures supporting cultural change.

For decades, organizations operated under a flawed but deeply ingrained assumption: security “owns” risk. Whether cyber, physical, personnel or reputational, risks were routinely escalated to security leaders as if they alone were responsible for identifying, managing and mitigating every exposure across the enterprise. Often, security leaders were not properly funded for that responsibility yet were held accountable when something went wrong, even when they lacked control over the underlying decision.

That model is no longer sustainable.

Today's risk landscape, defined by convergence across physical security, cybersecurity, supply chains, regulatory environments and human capital, is too complex and embedded in daily business operations for any single function to control.

Enterprise Security Risk Management (ESRM) provides a corrective lens, reframing risk as a shared, business-owned discipline. The ASIS International ESRM Guideline describes ESRM as an approach that aligns security resources with organizational strategy and calls for security professionals to work with asset owners to identify, prioritize and mitigate risk.

At the heart of ESRM is a transformative idea: risk ownership belongs with the people who create, manage or benefit from the asset at risk—not with the security function advising on it. In the ASIS framework, security professionals partner with asset owners, who retain responsibility for security-risk decisions affecting their assets.

This shift is not merely procedural. It is cultural—and one of the most consequential changes reshaping organizational accountability, resilience and performance.

Why Security Cannot Own Every Risk

The notion that security “owns” risk was understandable when threats were fewer, assets were more centralized, and organizational structures were less complex. Today, risk emerges from nearly every business activity:

  • Marketing launches a data-driven customer campaign.
  • HR implements a hybrid-work policy.
  • Procurement selects a third-party vendor.
  • Operations expands into a new geography.
  • IT deploys a cloud-based platform.

Each decision introduces risk, but each also falls within the domain expertise of non-security leaders.

Security professionals can identify vulnerabilities, assess threats and recommend controls. But they do not control hiring decisions, vendor selections, product strategies or operational processes.

One of the most effective tools in operationalizing ESRM is creating a risk ownership matrix, a structured mapping of risks to their accountable owners across the organization.

When security is treated as the risk owner, two problems emerge:

1. False accountability: Decision-makers defer responsibility, assuming “security will handle it.”

2. Ineffective mitigation: Controls are recommended without the authority or operational insight required to implement them effectively.

The result is a disconnect between risk ownership and risk management that weakens accountability and increases exposure.

ESRM corrects this by redefining security's role: not as the owner of risk, but as the facilitator of informed risk decisions. ASIS International positions security professionals as trusted advisers who guide asset owners through security-risk management decisions.

Defining Risk Ownership in an ESRM Framework

In an ESRM-aligned organization, risk ownership is explicitly assigned to asset owners—individuals or leaders responsible for the value, performance and outcomes of a given asset or function.

These assets include:

  • People: HR, workforce and contractors
  • Physical assets: Facilities, infrastructure and equipment
  • Financial assets: Business objectives and financial outcomes affected by security threats
  • Information: Data, intellectual property and systems
  • Operations: Processes, supply chains and logistics
  • Reputation: Brand, customer trust and stakeholder confidence

Asset owners are accountable for:

  • Understanding the risks associated with their assets
  • Evaluating risk against business objectives
  • Accepting, mitigating, transferring or avoiding risk
  • Ensuring controls align with operational realities

Security provides the structure, methodology and expertise to guide the process; it does not substitute for the asset owner's decision-making authority.

This distinction is critical. It aligns risk authority with operational control, ensuring that those with the greatest influence over outcomes are also accountable for the risks accompanying them.

Building a Formal Risk Ownership Matrix

One of the most effective ways to operationalize ESRM is to create a risk ownership matrix—a structured mapping of risks to accountable owners across the organization, often in conjunction with the Enterprise Risk Management (ERM) team.

A well-designed matrix should address four areas:

1. Identify Core Risk Domains

Typical domains include cybersecurity, physical security, supply chain risk, regulatory and compliance risk, insider threat, business continuity and crisis management.

2. Map Risks to Functions

Assign each risk to the function most directly responsible for the associated asset or activity. For example:

  • Cybersecurity risk → CIO/CISO/IT leadership
  • Employee misconduct risk → HR
  • Contractual and liability risk → Legal
  • Facility security risk → Facilities/Operations
  • Vendor risk → Procurement/Supply Chain

3. Define Roles Using RACI Principles

Use the RACI model—Responsible, Accountable, Consulted and Informed—to distinguish execution, ultimate accountability, expert input and communication responsibilities.

  • Responsible: Executes mitigation activities
  • Accountable: Owns the risk decision
  • Consulted: Provides expertise, such as security
  • Informed: Kept aware of outcomes

Security typically falls into the Consulted and sometimes Responsible categories, but rarely the Accountable category.

4. Document Decision Rights

Clearly establish who has authority to accept risk, particularly when exposure exceeds defined thresholds and requires escalation to executive leadership.

A formal matrix eliminates ambiguity. Assign risk ownership rather than assume it.

Assigning Accountability Across the Enterprise

True risk ownership requires breaking down traditional silos and embedding accountability across major functions.

Operations own risks associated with production, logistics and service delivery, including supply-chain disruptions, workplace safety and process vulnerabilities. Security can assess threats, but operational leaders must decide how much risk is acceptable to pursue efficiency and performance.

Human Resources owns workforce behavior, insider threats and organizational culture, including hiring practices, employee conduct and workplace policies. Security supports investigations and awareness, but HR owns the outcomes.

Legal and Compliance owns regulatory and contractual risks, including exposure created through agreements, litigation and compliance posture. Security contributes risk intelligence, but legal defines tolerance within regulatory frameworks.

Information Technology owns risks associated with systems, networks and data. Security may provide governance frameworks, but IT must balance usability, cost and resilience.

Facilities and Real Estate own risks associated with buildings, access control and environmental threats. Security advises on controls, while facilities leaders determine implementation priorities.

Business Units own the risks associated with revenue-generating activities. Whether launching a product or entering a new market, business leaders must weigh risk against opportunity.

 

When accountability is distributed this way, risk management becomes part of everyday decision-making rather than an external requirement imposed by security.

Measuring Risk Ownership Effectiveness

Assigning ownership is only the beginning. Organizations must measure whether risk owners are fulfilling their responsibilities.

Potential KPIs include:

  • Risk Treatment Completion Rates: Are mitigation actions completed on time?
  • Control Effectiveness: Are controls reducing risk as intended?
  • Audit Findings and Remediation: How quickly are issues identified and resolved?
  • Incident Frequency and Impact: Are risk owners reducing the likelihood and severity of incidents?
  • Risk Acceptance Documentation: Are decisions formally recorded and justified?

More mature organizations also use Key Risk Indicators (KRIs) tailored to individual functions, such as vendor-risk scores in procurement, employee misconduct rates in HR, system downtime in IT and safety incidents in operations.

These measures create visibility and accountability while allowing security leaders to shift their focus from directly managing risk to evaluating how effectively the organization manages its own risk.

Linking Risk Ownership to Performance

One of the most powerful ways to reinforce risk ownership is to connect it to leadership performance.

Organizations can:

  • Embed risk-management objectives into annual performance plans
  • Require executives to formally accept risk within defined thresholds
  • Link incentives to appropriate risk-related outcomes, such as incident reduction or compliance adherence
  • Incorporate risk governance into leadership-development programs

COSO's ERM framework integrates risk management with strategy and performance, while the G20/OECD Principles emphasize transparent board and executive accountability. Organizations should tailor performance and incentive mechanisms to their legal, regulatory and operational context.

The message is straightforward: managing risk is a core component of leadership performance.

When leaders are evaluated not only on results but also on how they manage the risks associated with those results, behavior changes. Risk becomes a strategic consideration rather than a compliance exercise.

The Role of Boards and Executive Leadership

Cultural transformation around risk ownership cannot occur without direction from the top. John P. Kotter's Eight-Step Process for Leading Change provides a useful framework for creating the organizational momentum required for this transformation.

Boards of Directors

Boards play a critical role in:

  • Identifying strategic risk
  • Defining organizational risk appetite
  • Ensuring clear accountability structures
  • Holding executives accountable for risk decisions
  • Requiring transparency in risk reporting

Boards increasingly expect evidence that risk ownership is distributed rather than concentrated within security or compliance. This aligns with COSO's emphasis on board and executive oversight and the G20/OECD focus on transparency, accountability and board responsibility.

Executive Leadership

C-suite leaders must:

  • Model risk-ownership behavior
  • Reinforce accountability across their functions
  • Support security in its advisory role
  • Align risk management with strategic objectives

The CEO sets the tone. When leadership treats risk as a shared responsibility, the organization follows.

Convergence and Real-World Use Cases

Enterprise-wide risk ownership becomes particularly important where risks cross traditional boundaries.

Hybrid Work Environments

A global organization transitioning to hybrid work may face cybersecurity risks from remote access, physical-security risks from changing facility utilization and HR risks involving employee well-being and policy enforcement.

Under ESRM:

  • IT owns system-security decisions
  • Facilities manages physical adaptations
  • HR addresses workforce policies
  • Security coordinates risk assessment and guidance

No single function owns the entire risk, but each is accountable for its component.

Third-Party Vendor Risk

A company onboarding a critical supplier may face cyber risk from data access, legal risk from contracts and liability, and operational risk from supply-chain dependency.

Ownership is distributed among procurement, IT and legal, with security providing risk assessment and due-diligence support.

Expansion into High-Risk Markets

Entering a new geographic region can introduce geopolitical, regulatory and physical-security threats. Business leaders own the expansion decision, informed by security intelligence, legal analysis and compliance considerations.

These examples illustrate a core ESRM principle: risk is interconnected, but ownership remains specific and accountable.

Emerging Best Practices

Organizations implementing enterprise-wide risk ownership through ESRM commonly employ practices consistent with ASIS ESRM, COSO ERM and broader corporate-governance guidance:

  1. Executive-Endorsed Risk Governance: Clear policies defining roles, responsibilities and decision rights.
  2. Standardized Risk Assessments: Consistent methodologies that enable comparison and an enterprise view of risk.
  3. Integrated Risk Registers: Centralized visibility into risks, owners and mitigation status.
  4. Continuous Education: Training that ensures leaders understand their risk-management responsibilities.
  5. Technology Enablement: Platforms that track ownership, metrics and reporting.
  6. Regular Cross-Functional Reviews: Forums that align stakeholders on priorities and dependencies.

These practices reinforce an important point: risk ownership is not a one-time assignment. It is an ongoing discipline.

Conclusion: From Ownership to Accountability

The central message of ESRM is simple but transformative:

Security does not own risk; leaders do.

Security's value lies not in absorbing accountability, but in enabling better risk decisions across the enterprise. By shifting ownership to those who create and manage risk, organizations can achieve:

  • Stronger accountability
  • Better-informed decisions
  • Greater alignment between risk and strategy
  • Enhanced resilience against evolving threats

In today's complex, converged risk environment, no department can—and should—carry the burden alone.

Risk has no department. But with ESRM, it finally has owners.

References

ASIS International. (2019). Enterprise Security Risk Management Guideline (ASIS ESRM-2019).

California State University Channel Islands, Organizational Effectiveness Unit. (n.d.). Responsible, Accountable, Consulted, and Informed (RACI) Matrix.

Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2017). Enterprise Risk Management—Integrating with Strategy and Performance.

Kotter, J. P. (1996). Leading Change. Harvard Business School Press.

Kotter. (n.d.). The 8-Step Process for Leading Change.

Organization for Economic Co-operation and Development (OECD). (2023). G20/OECD Principles of Corporate Governance 2023. OECD Publishing.

 

About the Author

Jeffrey A. Slotnick CPP, PSP

Jeffrey A. Slotnick CPP, PSP

President of Setracon ESRMS

Jeffrey A. Slotnick, CPP, PSP, President, Setracon ESRMS

Jeffrey A. Slotnick, CPP, PSP, is an internationally known Enterprise Security Risk Consultant with over 28 years of experience. Jeff is peer-recognized as a “Thought Leader and Change Agent. He focuses on all Enterprise Security Risk Management facets, including quality management programs, risk, vulnerability, threat assessments, Emergency Response Planning, Business Continuity Planning, and Physical Security System Master Planning, Design, and Integration. As a curriculum developer and master trainer, Jeff advocates for quality professional development and training of security, law enforcement, and military personnel. He is a former member of the North American Board. He is a Community Vice President for ASIS International and a Faculty Advisor for the University of Phoenix Bachelor of Science in Cyber Security and Security Management Degree Program.

Jeff is a regular contributor to Security Executive Magazine and SecurityInfoWatch.com 

[email protected]  

Sign up for our eNewsletters
Get the latest news and updates