Risk Exposure

The overall level of possible effect from the complete set of risks, evaluated at a specific moment in a project, program, or portfolio.

Key Points

  • Represents the combined effect of all risks at a point in time; it changes as risks evolve.
  • Often estimated by summing probability-weighted impacts (e.g., EMV) or using risk scoring/heat maps.
  • Guides decisions on risk response priorities, contingency reserves, and escalation.
  • Can be assessed at project, program, and portfolio levels and rolled up for governance.

Example

An IT project tracks three risks: R1 (30% chance of a USD 200,000 cost hit), R2 (10% chance of a USD 1,000,000 delay cost), and R3 (50% chance of a USD 50,000 rework). The exposure at this time is 0.30*200,000 + 0.10*1,000,000 + 0.50*50,000 = USD 185,000. As risks are mitigated or new risks emerge, this total will rise or fall.

PMP Example Question

A project manager wants a single metric that reflects how severe the overall risk is right now so leadership can set an appropriate contingency reserve. What should the manager use?

  1. Risk appetite
  2. Risk threshold
  3. Risk register
  4. Risk exposure

Correct Answer: D — Risk exposure

Explanation: Risk exposure consolidates the potential effect of all risks at a specific time, providing a basis for reserves and priority setting.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Launch your career!

HK School of Management delivers top-tier training in Project Management, Job Search Strategies, and Career Growth. For the price of a lunch, you’ll gain expert insights into landing your dream PM role, mastering interviews, and negotiating like a pro. With a 30-day money-back guarantee, there’s zero risk—just a clear path to success!

Learn More