Guide · Resilience

Cyber risk response, when the risk isn't yours to patch.

Resilience · 8 min read · Updated July 2026

Identifying a cyber risk is the easy part. Cyber risk response is what you do about it — before it materializes, and when it does. This guide covers the four ways to treat any risk, how response differs from incident response, and the case that's becoming the norm: responding when the risk, or the breach itself, sits inside a vendor you don't control.

In one sentence

Cyber risk response is how an organization acts on identified cyber risk — treating it before it materializes (mitigate, transfer, avoid, accept) and reacting when it becomes a live threat, including threats that originate at a third party.

The four ways to treat a risk

Every identified risk resolves to one of four decisions. This is the strategic layer of cyber risk response, and it applies whether the risk is in your own systems or inherited from a vendor:

  • Mitigate. Reduce likelihood or impact with controls — patching, segmentation, contractual security requirements, added monitoring.
  • Transfer. Shift the financial consequence elsewhere, via cyber insurance or contractual indemnities. Note you can transfer cost but rarely accountability — regulators still look to you.
  • Avoid. Stop the activity that creates the risk — decline a vendor, drop a data-sharing arrangement, or choose a different architecture.
  • Accept. Formally acknowledge a residual risk that sits within appetite, document the decision, and monitor it. Acceptance is a legitimate choice — an undocumented one is just an unmanaged risk.

Response vs incident response

It's worth separating two things that share a word. Incident response is the acute reaction to a confirmed security incident — the containment and recovery work covered in our guide to cyber incident management. Cyber risk response is broader: it includes the upfront treatment decisions above, made on risks that haven't materialized yet, as well as the reaction when one does. Incident response is the acute end of cyber risk response; most of the discipline happens before anything goes wrong.

When the risk is a third party's

Here's what has changed the shape of the problem: more and more, the cyber risk you must respond to lives in a vendor, not in your own estate. A large share of breaches now reach organizations through a third party. When that happens, your usual response toolkit is constrained in three ways:

  • Your visibility is second-hand. You learn what happened from the vendor, on their timeline, in their words.
  • Your containment is contractual, not technical. You can't patch their systems. Your levers are the clauses in the contract and the access you can revoke on your side.
  • The clock may still be yours. If your data or your service is affected, your regulatory reporting obligations can run even though the breach happened somewhere else.

All three are decided long before the incident, by preparation. If you already know exactly what each vendor holds of yours — and you've written notification and audit rights into the contract — you can respond in hours. If you don't, you spend the first day just working out whether you're even affected. That preparation is the whole point of sound third-party risk management, and specifically of classifying vendors by what they hold of yours rather than by an external score.

A third-party response playbook

  1. Confirm exposure. Establish precisely what of yours the vendor holds or can reach — which is a lookup, not an investigation, if you classified them properly upfront.
  2. Invoke the contract. Trigger breach-notification clauses, request the vendor's incident details, and hold them to their obligations.
  3. Assess your reporting duty. Determine whether DORA, NIS2, or GDPR deadlines now apply to you, and start those clocks.
  4. Contain your side. Rotate shared credentials, revoke or restrict the vendor's access, and watch for lateral movement into your environment.
  5. Communicate. Inform affected internal stakeholders, customers, and — where required — data subjects and regulators.
  6. Reassess. After the dust settles, re-tier the vendor and feed the event into your monitoring. A breached vendor is new evidence, not a closed case.
Signal in, verdict yours
Outside-in as evidence. Inside-out as verdict.

Polestead attaches external breach and exposure signals to the resolved vendor as evidence that feeds review and reassessment — scoped to the vendors that actually hold something of yours, never turned into a public grade a vendor must dispute.

How external signals work →

Signals that trigger reassessment

Response isn't only reactive. Between formal reviews, certain signals should pull a vendor back onto your desk: a disclosed breach or ransomware event, a change of ownership, financial distress, a lapsed certification, or new external exposure attached to their resolved identity. The discipline is to treat these as evidence feeding a decision — mitigate, transfer, avoid, or accept — rather than as an automatic alarm. Signals inform the verdict; your own exposure context determines it. That is cyber risk response working as intended: continuous, proportionate, and grounded in what a vendor actually holds of yours.

FAQ

Common questions.

What is cyber risk response?+

How an organization acts on identified cyber risk — treating it before it materializes (mitigate, transfer, avoid, accept) and reacting when it becomes a live threat, including threats originating at a third party.

What are the four risk treatment options?+

Mitigate, transfer, avoid, and accept. Reduce it with controls, shift its cost, stop the activity, or formally acknowledge and monitor a residual risk within appetite. Every identified risk resolves to one of these.

How do we respond to a third-party incident?+

Confirm what of yours is exposed, invoke breach-notification clauses, assess your own reporting obligations, contain your side by rotating credentials and revoking access, communicate with affected parties, and reassess the vendor afterward. Preparation decides how fast you can move.

How is it different from incident response?+

Incident response is the reaction to a confirmed incident. Cyber risk response is broader — it includes treating risks that haven't materialized yet, and the response when they do. Incident response is the acute end of it.

Keep reading
Cyber incident management
The lifecycle and the clocks.
Third-party risk management
The preparation that makes response fast.
CIIC →
Regulatory incident response.