Take a Risk - Ville Rantamäki
Ville Rantamäki (Senior Cyber Consultant · Insta)
Disobey 2026 · Main Stage
Overview
Ville Rantamäki's talk, "Take a Risk," presented at Disobey, offers a critical re-evaluation of information security risk management. While the conference theme, "first principles," might suggest a deep dive into technical vulnerabilities or offensive tactics, Rantamäki instead pivots to the foundational yet often misunderstood discipline of risk management. He argues that effective risk management is the true starting point for any robust security strategy, preceding technical investments and operational plans. This talk is not about specific hacks or zero-days but rather about the strategic and organizational frameworks that enable security professionals to communicate value, secure budget, and align their efforts with overarching business objectives.

Key moments
- 0:00 Introduction and talk disclaimers
- 2:00 Understanding the three levels of risk management
- 2:42 Importance of risk management for budgets and strategy
- 4:08 Standards are not checklists, start risk assessment early
- 5:58 The 'information security is cooking' analogy explained
- 7:59 Is InfoSec an unavoidable expense or business enabler?
- 8:49 Organizational models for effective risk management
Take a Risk
Speakers: Ville Rantamäki, Senior Cyber Consultant, Insta
Conference: Disobey
YouTube: https://www.youtube.com/watch?v=nrq7iQp9Yz8
Overview
Ville Rantamäki's talk, "Take a Risk," presented at Disobey, offers a critical re-evaluation of information security risk management. While the conference theme, "first principles," might suggest a deep dive into technical vulnerabilities or offensive tactics, Rantamäki instead pivots to the foundational yet often misunderstood discipline of risk management. He argues that effective risk management is the true starting point for any robust security strategy, preceding technical investments and operational plans. This talk is not about specific hacks or zero-days but rather about the strategic and organizational frameworks that enable security professionals to communicate value, secure budget, and align their efforts with overarching business objectives.
The presentation challenges common misconceptions and pitfalls in how organizations approach security risks. Rantamäki emphasizes that risk management is frequently overlooked, performed at an ineffective level, or disconnected from business realities. He aims to equip security practitioners with the perspective and tools needed to elevate their risk discussions from technical jargon to tangible business impact, primarily through the lens of financial considerations. This shift in perspective is crucial for bridging the gap between technical security teams and executive management, ensuring that security is perceived not as an unavoidable expense but as a strategic enabler and investment for future resilience and market position.
The talk is particularly relevant for security professionals who struggle to justify budgets, gain executive buy-in, or prioritize their initiatives. Rantamäki posits that by understanding and implementing effective risk management principles, security teams can transform their role from reactive problem-solvers to proactive strategic partners. He advocates for a pragmatic approach that acknowledges the inevitability of some risks and encourages deliberate, informed decision-making rather than an exhaustive, often futile, pursuit of zero risk.
Background
▶ Watch: Introduction and talk disclaimers (0:00)
The landscape of cybersecurity mandates and best practices often leads organizations down a path of checklist compliance rather than genuine risk understanding. Rantamäki highlights that prevalent standards and regulations such as GDPR and ISO 27000 series, while providing frameworks, fundamentally call for "appropriate and proportionate technical measures to manage the risks." This phrasing is key; it doesn't demand a rigid list of controls but rather a thoughtful, context-aware approach to risk. Yet, many organizations default to fulfilling prescriptive lists, often missing the underlying intent of risk-based security.
A significant challenge Rantamäki identifies is the common misconception that risk assessments cannot begin until "every single asset of your organization" is meticulously mapped. He dismisses this as a paralyzing fallacy, advocating for an earlier, more iterative start to risk management. This ties into his analogy of information security as "cooking," where preparing the ground (misan plus) and understanding the "entire recipe" (complete picture of security goals) are paramount before diving into specific tools or controls like a Security Operations Center (SOC) or firewalls. Risk management, he suggests, is the "pulled pork" of information security: low and slow, requiring consistent monitoring and refinement.
Furthermore, the speaker delves into the varying organizational roles and perceptions of information security. Is it merely an "unavoidable expense" or a "business enabler"? This dichotomy profoundly influences how risk management is structured and perceived. Often, security functions operate in isolation, identifying, assessing, and treating risks internally without adequate integration into the organization's centralized risk management function. This disconnect frequently leads to security risks being undervalued or misunderstood by management, who might prioritize financial, health, or safety risks over perceived "technical" security issues. The lack of a shared frame of reference for evaluating diverse risk categories is a root cause of budget shortfalls and misaligned priorities in security investments.
Key Findings
▶ Watch: Importance of risk management for budgets and strategy (2:42)
Rantamäki's core findings revolve around the systemic issues plaguing contemporary information security risk management and offering clear pathways for improvement. He identifies that risk management is often either overlooked or performed at a level that fails to provide useful insights for either management or effective security work. This deficiency directly impacts budget allocation, as the ability to secure funding for security initiatives is intrinsically linked to how risks are presented and understood.
A critical finding is the pervasive disconnect between technical vulnerabilities and actual business impact. Security professionals frequently focus on highly technical issues, using metrics like CVSS scores, which, while valuable for technical prioritization, often fail to translate into meaningful business language for executives. A CVSS score of 10, indicating a severe technical vulnerability, does not automatically equate to a "catastrophic" business risk. The actual impact depends heavily on the criticality of the affected system to the business operations, revenue, or reputation. This leads to a common scenario where security teams present extensive lists of vulnerabilities, only to be met with confusion or indifference by management who cannot discern the true organizational risk.
Rantamäki introduces a crucial pyramid model for understanding risk at different organizational levels:
- Organization Level Risks: Strategic risks affecting the entire entity.
- Mission or Business Process Level Risks: Risks impacting specific business functions or services.
- Information System Level Risks: Technical risks related to specific systems or data, which is where most security professionals typically operate.
The speaker emphasizes that while most security professionals are adept at the third level, the critical insights and budget decisions are made at the first and second levels. Effective risk management, therefore, requires elevating discussions to these higher tiers, synchronizing security risk assessments with the organization's general risk management framework. This synchronization ensures that security risks are assessed on similar terms as other business risks, allowing for comparable evaluation of probability and impact.
Finally, a significant finding is the need for a pragmatic approach to risk treatment, including the often-overlooked strategy of risk acceptance. Many organizations and security professionals are conditioned to believe that every identified risk must be "fixed" or "reduced." However, Rantamäki argues that knowingly accepting certain risks, after a thorough cost-benefit analysis, is a legitimate and often necessary business decision. This acceptance must be informed, monitored, and supported by defined acceptance criteria and appropriate risk owners.
Technical Deep Dive
▶ Watch: Standards are not checklists, start risk assessment early (4:08)
The technical deep dive in Rantamäki's talk focuses not on code or exploits, but on the architecture and methodology of effective information security risk management within an organizational context. He meticulously breaks down how risk management functions are typically structured and the implications of these structures.
Rantamäki outlines three common organizational models for risk management:
- Option Good: This model features a centralized risk management function that encompasses various risk categories—security, personnel, business, compliance, etc.—all on equal footing. Information security risks are integrated into this central function, assessed using similar criteria as other risks, and reported directly to management. This structure ensures high management visibility and a holistic view of organizational risks, facilitating informed decision-making and resource allocation.
- Option Not That Great: This common model involves a separate information security risk management team that reports to a centralized risk management team at agreed intervals (e.g., quarterly). While there might be direct reporting to management, it's often limited (e.g., "top 10" risks). This structure can lead to reduced visibility and a potential disconnect if the reporting is not robust or if the centralized team doesn't fully understand the nuances of security risks.
- Option Bad: This highly problematic structure places information security as a subcategory of IT risk management, which itself is a subcategory of the overall risk management function. In this hierarchy, security risks are diluted and filtered multiple times. Information security reports its top risks to IT risk management, which then compiles its own top risks (potentially including only one or two from security) to the centralized function. Management, in this scenario, has severely limited insight into the actual information security posture.
Rantamäki stresses that even with separate information security or IT risk management functions, they can be effective internal planning tools. However, for achieving broader organizational impact, these identified risks must be escalated and rephrased using the organization's general risk criteria. This often means adjusting probability and impact scores, as a technical severity (like CVSS 9.8) might translate to a lower business impact if the affected system isn't critical.
A significant portion of the deep dive addresses the common pitfalls of risk registries. Rantamäki notes that registries often contain either "very little" (e.g., 5 risks) or "a huge amount" (e.g., 1521 risks). A small number usually indicates superficial compliance, while an excessively large list is often a compilation of technical vulnerabilities or threats disconnected from business context. To rectify this, he defines what a true risk is: "potential for loss or disruption caused by an incident," leading to "physical, material or non-material damage and cause harm to an organization." He highlights that many "risks" listed in registries are merely "events" or "vulnerabilities" without articulated business consequences.
He provides examples of "bad" risks and demonstrates how to transform them into actionable, business-centric risks:
- Too Vague/Broad: "A malicious actor wants to affect our company's systems by breaking in, phishing for credentials, DDOSing, or installing malware." This is useless because it averages impacts and probabilities of vastly different scenarios. Rantamäki suggests splitting it into multiple specific risks, each with a clear risk source, impact (e.g., "severe reputational damage and a service disruption for at least eight hours"), a specific control (e.g., "fix the known authentication vulnerability"), and a clear risk owner (e.g., "lead developer").
- Too Specific/Hyper-technical: An example involving "speculative processing" and "inferring memory values" is cited as a risk that is often assessed as high due to technical severity (like a CVSS 9.8) but lacks inherent business relevance. The speaker demonstrates how to reframe this by focusing on the business effect (e.g., "catastrophic" if highly confidential data is extracted) and then proposing a more feasible control (e.g., "stop storing highly sensitive data on these systems") rather than an unwieldy technical fix.
Crucially, Rantamäki emphasizes the importance of quantifying financial damage (direct: service disruption, contractual claims; indirect: reputational damage) and assigning a risk owner who is responsible for monitoring the risk and ensuring control effectiveness. He introduces a critical cost-benefit principle: if implementing a control costs significantly more than the potential annual financial impact of the risk realizing, it makes no business sense to implement it. This underpins the "forget cyber, think business" philosophy.
Finally, he details the four pillars of risk treatment:
- Avoid: Eliminate the activity causing the risk (e.g., decommissioning a legacy system, stopping the use of an unauthorized AI tool). This is often challenging due to organizational inertia or resistance.
- Transfer: Shift the risk to a third party, typically through insurance or contractual agreements with service providers. This is a legitimate strategy, often underutilized due to a perception of "dodging responsibility."
- Reduce: Implement controls or change configurations to lower the probability or impact of the risk. This is the most common and intuitive approach, often aligning with security best practices and compliance checklists.
- Accept: Acknowledge the risk and its potential consequences without implementing further controls. This is a deliberate business decision, not a passive oversight. Accepted risks must still be monitored, reassessed periodically, and be within defined acceptance criteria set by appropriate management levels (e.g., security manager, CIO, CEO). Rantamäki warns against "going full donkey hardy" – blindly accepting risks without proper consideration or simply fighting unwinnable battles against organizational realities. He highlights that achieving 100% risk elimination is impossible and prohibitively expensive.
Demo / Proof of Concept
▶ Watch: Is InfoSec an unavoidable expense or business enabler? (7:59)
The talk "Take a Risk" by Ville Rantamäki focuses on strategic and organizational aspects of information security risk management rather than technical exploits or tool demonstrations. As such, the presentation did not include any live demo or proof of concept of a specific vulnerability, tool, or attack. The speaker primarily utilized conceptual models, organizational diagrams, and illustrative examples to convey his points on effective risk assessment and treatment.
Defensive Implications
▶ Watch: Organizational models for effective risk management (8:49)
Rantamäki's talk provides crucial defensive implications for information security professionals seeking to enhance their organization's security posture and influence. The primary takeaway for defenders is to fundamentally shift their perspective from a purely technical, vulnerability-centric view to a business-centric, impact-driven approach to risk management.
- Translate Technical to Business Impact: Defenders must learn to articulate risks not in terms of CVSS scores or specific vulnerabilities (e.g., "speculative processing might infer memory values") but in terms of tangible business consequences (e.g., "severe reputational damage," "service disruption for eight hours," "catastrophic financial loss"). This means understanding the critical business processes, assets, and data that, if compromised, would cause direct or indirect financial, operational, or reputational harm.
- Align with Organizational Risk Management: Security teams should actively seek to integrate their information security risk management processes with the broader centralized risk management function of the organization. This involves understanding and adopting the organization's existing risk criteria, reporting structures, and terminology. Risks identified at the information system level must be rephrased and re-evaluated to fit the mission/business process level and organization level risks, ensuring they are comparable with other organizational risks like financial or safety risks.
- Focus on "What's the Harm?": When identifying risks, the emphasis should be on the potential "loss or disruption caused by an incident" that leads to "damage and harm." This moves beyond merely listing "events" (like a phishing click) to detailing the cascading effects on the business (e.g., "attacker reads and edits confidential data, leading to regulatory fines and customer churn").
- Identify and Empower Risk Owners: It's critical to assign specific risk owners (e.g., lead developer, business unit head) who are accountable for monitoring risks and ensuring the effectiveness of risk controls. The "lonely infosec specialist" should not be the default owner for all risks, as this dilutes accountability and expertise.
- Embrace All Four Risk Treatment Strategies: Defenders should be prepared to utilize avoidance, transfer, reduction, and acceptance as valid risk treatment options. While "reduction" is the natural instinct, "avoidance" (e.g., decommissioning unnecessary legacy systems) and "transfer" (e.g., insurance, contractual SLAs) are powerful tools. Crucially, "acceptance" should be a deliberate, informed business decision, not a failure. This requires defining clear risk acceptance criteria and ensuring that accepted risks are regularly monitored and reassessed.
- Conduct Cost-Benefit Analysis for Controls: Before advocating for a new security control, defenders should perform a realistic cost-benefit analysis. If the cost of implementing and maintaining a control significantly outweighs the potential financial impact of the risk, it may not be a justifiable investment. This pragmatic approach helps secure budget for truly impactful controls and avoids wasteful spending.
- Continuous Improvement: Risk management is not a one-time activity but an ongoing process ("pulled pork"). Defenders should continuously monitor identified risks, reassess their probability and impact as organizational contexts change, and refine their risk treatment strategies.
By adopting these principles, security professionals can transform their role from technical gatekeepers to strategic business partners, effectively communicating the value of security, securing necessary resources, and contributing to the overall resilience and success of the organization.
Key Takeaways
- Define Impact, Not Vulnerabilities: Focus on the potential business loss, disruption, damage, or harm caused by an incident, rather than just listing technical vulnerabilities or threats.
- Think Business, Not Just Cyber: Elevate security discussions to the organizational and business process levels, translating technical risks into financial and operational impacts that resonate with management.
- Organizational Structure Matters: Integrate information security risk management into the organization's centralized risk management function for greater visibility, comparable assessment, and effective budget allocation.
- Embrace Risk Acceptance: Deliberately accepting certain risks, after a thorough cost-benefit analysis and with defined acceptance criteria and owners, is a legitimate and often necessary business decision.
- Risk Management is a Continuous Process: Treat risk management as an ongoing, iterative activity ("pulled pork"), requiring constant monitoring, reassessment, and refinement of strategies.
- Utilize All Four Treatment Options: Be prepared to employ avoidance, transfer, reduction, and acceptance as appropriate strategies for managing risks, rather than solely relying on reduction.
About the Speaker(s)
Ville Rantamäki is a Senior Cyber Consultant at Insta. With a background as an ex-military professional specializing in air defense and cyber, Rantamäki brings a practical and disciplined approach to cybersecurity. Currently based in Mikkeli due to prior engagements, he balances his professional life with his role as a somewhat fresh father, which he humorously notes leaves him "perpetually tired." Beyond his consultancy work, Rantamäki is actively involved in the cybersecurity community, volunteering with both SIMAK and Women for Cyber Finland, demonstrating his commitment to advancing the field and fostering diversity within it. His talk reflects his extensive experience in navigating the complexities of organizational security and advocating for more effective, business-aligned risk management practices.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent, well-structured walkthrough of risk management fundamentals aimed at practitioners who struggle to speak management's language. Nothing here will surprise anyone who's read FAIR, NIST RMF, or spent time in a GRC role, but it's delivered clearly and without vendor noise — which, at Disobey, is worth something.
Heather Calloway (CISO) — SOLID
Rantamäki is making the right argument — risk management is upstream of every security decision, and most security teams are operating two levels too low in the organizational hierarchy. The content is sound and the framing is practical, but it doesn't go far enough to be transformative for anyone who has sat in a CISO seat.