You know, I used to want to fight that fight, but there really are up to 12 different definitions of risk in the dictionary (depending on which one you use).

These days, I try not to say risk, period. I qualify it with descriptors (frequency, dollar losses, a specific threat action, etc).


Yes, absolutely and positively. This was the point of my "BeFUDdled by Risk" post last month, in fact, and exactly the reason I took issue with a certain analyst's desire to dismiss Mac malware as being (universally) a "low risk". Context is everything.

Robert David Graham

And while we are at it, let's stop using "security" with no context.


Security and Risk are tools to confuse management.

