Risk Management’s cover photo
Risk Management

Risk Management

Professional Services

Melbourne, Victoria 27,822 followers

Making decisions concerning risks and their subsequent implementation and flows from risk estimation and risk evaluation

About us

Risk evaluation is the complex process of determining the significance or value of identified hazards and estimated risks to those concerned with or affected by the decision. It, therefore, includes trade-off between perceived risks and perceived benefits. Risk management is making of decisions concerning risks and their subsequent implementation, and flows from risk estimation and risk evaluation

Website
https://www.patreon.com/riskmanagement
Industry
Professional Services
Company size
2-10 employees
Headquarters
Melbourne, Victoria
Founded
2011
Specialties
Risk, Risk Management, Risk Analysis, Risk Assessment, Risk Management Framework, Risk Estimation, Risk Science, Enterprise Risk Management, Operational Risk, Organisational Risk, Climate Risk, Uncertainty, Resilience, Systemic Risk, and Emerging Risk

Updates

  • In 1948, Coch and French ran the experiment that most risk transformations still get wrong. Harwood pyjama factory. Same change, same workforce, same factory. One variable: how the change was introduced. Announcement and explanation. Output collapsed, grievances rose, people quit. Full participation in designing the change. Output recovered rapidly, then exceeded the previous benchmark. Explanation was the losing condition in 1948. Town halls, leader-led videos and email campaigns are explanation. 75 years on, the average risk transformation still buys the losing condition at scale, and names a workstream after it. Full piece linked in the first comment. #RiskManagement #ChangeManagement #RiskCulture

    • Why Your Risk Transformation Is Failing (And Why the "Resistors" Are Right): Risk Culture
https://www.linkedin.com/pulse/why-your-risk-transformation-failing-resistors-right-tony-0fxte/
  • How do you protect your mobile workforce when the risk map stays the same, but the ground beneath it shifts? The latest Global Executive Travel Risk Briefing (Week 36, 2026) highlights a critical challenge for corporate security, travel, and operations leaders: traditional country-level risk ratings are no longer enough to drive daily decision-making. From the sudden end of the US-Iran war pause in the Middle East and a devastating landslide on the Nepal-China border, to a tropical system making landfall on the US Gulf Coast, this week’s major crises occurred entirely within unchanged national risk bands. To meet modern duty of care, risk leaders must shift their focus from broad national categories to precise sub-national exclusions and a rapidly moving calendar of hard regulatory deadlines. 🚨 Key Observations & Operational Takeaways Resumed Kinetic Activity in the Middle East: The month-long US-Iran pause has ended with a US strike on Larak Island and eight missiles intercepted over Jordan. Despite these events, the European aviation regulator (EASA) relaxed its Jordan airspace bulletin hours later. Practical Recommendation: Treat Jordanian overflight as unresolved; do not rely on a single regional regulator's view and obtain the operating carrier's written compliance position before booking. Trans-Boundary Footprint of Natural Disasters: A massive landslide on the Nepal-China border killed 939 and left 3,925 missing. Notably, only 24 deaths occurred where the slide began—creating a massive 240 km transboundary casualty footprint into India. Practical Recommendation: Implement strict sub-national corridor exclusions (such as the Trishuli corridor) rather than blanket countrywide suspensions, which overstate the risk and unnecessarily strand travellers. Immediate Weather & Infrastructure Disruptions: Tropical Storm Edouard is making landfall near the Texas/Louisiana border, while the Panama Canal reduces daily booking slots to 32/day. Practical Recommendation: Suspend non-essential ground movement between Houston and Beaumont for 48 hours and immediately re-cost September canal-dependent freight charters. 📅 Four Critical Compliance Deadlines (The "Hidden" Risk Layer) None of these highly disruptive regulatory shifts is visible on traditional government travel advisories, yet they impact global operations this fortnight: Schengen Biometrics (Sept 6): The Entry/Exit System flexibility mechanism ends, meaning first-time biometric registration delays must be factored into all European arrivals. Canadian Counter-Tariffs (Sept 8): Retaliatory tariffs of 15%, 25%, and 50% take effect on C$27.6B of US goods. US Ebola Entry Order (Sept 11): Travel restrictions for travellers transiting the DRC, Uganda, and South Sudan lapse unless extended. Tony Ridley, MSc CSyP FSyI SRMCP

    • Travel Safety, Security & Risk Briefing as of 1 Sep 26
https://www.linkedin.com/pulse/travel-safety-security-risk-briefing-1-sep-26-tony-ed9ve
  • Risk-informed decision-making is a scientific endeavour, not a destination. It rests on three properties, none of which a risk matrix provides. Provisional status. Information, perspectives and views on risk are transient and change as knowledge arrives. Scientific rigour. The model assumes constant change and requires continuous revision, rather than issuing definitive prophecies. Inclusive critique. It evaluates all the factors informing a risk choice and its operational trade-offs, not only those that fit the scale. The practical test is simple. Does your process expect to be revised, or does it defend what it has already published? Original article linked in the first comment. #RiskManagement #RiskInformed #ISO31000

    • Beyond the Matrix: Why "Risk-Based" Decisions are Failing and What to Do Instead
https://www.linkedin.com/pulse/beyond-matrix-why-risk-based-decisions-failing-what-tony-wnhpe/
  • Agentic #AIrisk is not an emerging issue. It is a binding regulatory obligation. Critical infrastructure. CIRMP Rules 2023, rr 6, 8 and 10. Minimise the risk of privileged access misuse by third-party providers in the supply chain. Prudential. APRA CPS 230 and CPS 234. Control testing and material service provider risk management commensurate with asset sensitivity. Due diligence. WHS Act s27 and Corporations Act s180. Officers must actively acquire knowledge, resource appropriately, and verify control effectiveness. A crowdsourced MCP server is a third-party provider holding privileged access. Every one of those clauses already reaches it. The original article is linked in the first comment. #CIRMP #APRA #RiskGovernance

    • The Mesh Beneath the Perimeter: Why Your AI Security Strategy Is Already Obsolete
https://www.linkedin.com/pulse/mesh-beneath-perimeter-why-your-ai-security-strategy-tony-slofe/
  • #RiskManagement #AI "The principal finding of this paper is that crowdsourced MCP tooling has formed an unverified supply chain mesh inside organisations. Tens of thousands of community-published servers, installed with minimal vetting and running with a user’s own credentials, are now embedded in mainstream operating systems and business applications. The threat is not a single malicious link. It is a mesh: one or more servers, singly or in combination, penetrating an organisation surreptitiously or by design, carrying prompts and data in tokens that a conventional firewall passes as ordinary encrypted traffic. The vectors are demonstrated, not hypothetical. Poisoned tool descriptions, a prompt injection that exfiltrated private repositories through the official GitHub server, a critical remote code execution flaw affecting several hundred thousand installations, a cross-tenant data exposure at Asana, the first backdoored server found stealing email in the wild, and a trojanised server clone that harvested developer credentials from thousands of machines, all occurred between April 2025 and February 2026" Ridley, T. (2026). The Unverified Mesh: How the Model Context Protocol (MCP) turned crowdsourced AI tooling into an unverified supply chain that penetrates organisations beneath the security perimeter, ResearchGate, DOI: 10.13140/RG.2.2.21227.50728, ResearchGate, Available at: https://lnkd.in/e7Aaz2GC

  • Two of the four available AI adoption postures are active decay states. Validated and Reinvesting. Displaces throughput, retains judgement, converts released capacity into output. Capability compounds. Validated and Harvesting. Retains the ability to judge, then removes it to bank the saving. Output holds, then degrades several turnover cycles later. Unvalidated and Reinvesting. Scales output with zero capacity to adjudicate it. Highest output per head. Fails catastrophically on defensibility. Unvalidated and Harvesting. Neither retains nor builds the capacity to judge. Decline with no internal detection and no route back. Only the first is a stable resting place. The other three are transitional, and two of them are terminal. Most boards have not chosen a position. They have arrived at one by omission. A posture arrived at by default is still a posture, and it is still the board's. The question for the next risk committee: has this been minuted, or assumed? Full breakdown in Risk + Safety + Security + Sciences. Source in the first comment. #RiskManagement #AIGovernance #BoardGovernance

    • The AI Productivity Paradox: Why Your Best Metrics Might Be Your Biggest Liars
https://www.linkedin.com/pulse/ai-productivity-paradox-why-your-best-metrics-might-tony-nyf9e/
  • #RiskManagement "The principal finding of this paper is that organisations are managing the wrong constraint. The constraint that binds in expertise-dependent work is not headcount, licence spend, adoption rate or output per head. It is validation capacity: the retained organisational ability to detect that a machine-assisted output is wrong, held by a named person with the competence to see the error and the standing to stop the work. Validation capacity is almost never defined, rarely measured, and effectively never reported to a board. What is not measured is not governed, and what is not governed is not defended. " Ridley, T. (2026). The Validation Question: Artificial intelligence, deskilling, and the erosion of organisational error detection in expertise-dependent organisations. ResearchGate, https://lnkd.in/ewpeTE6a

  • Thank you to all of my supporters, promoters, consumers, peers, and fellow researchers who have contributed to my growth on ResearchGate and spread the word, as well as those who have provided feedback, critique, and engagement over the years. Greatly appreciated. 40,000 and going strong. ResearchGate: https://lnkd.in/efeFa_fh #riskmanagement #crisismanagement #travelriskmanagement #securitymanagement #risk #safety #security #riskanalysis #phd

    • ResearchGate:  https://www.researchgate.net/profile/Tony-Ridley
  • Is your travel risk program built on actual ground truth, or an "illusion of clearance"?⚠️ During Week 35 of 2026, we witnessed official government advisories drop weeks—and in some cases, days—before major security escalations in Thailand and the Gulf. Meanwhile, transit blockages at Narita and refuelling crises at Nadi proved that an "open" airport is not always a usable one. Relying on lagging bureaucratic updates leaves your travellers exposed. To align with ISO 31030 guidance, organisations must transition from passive tier-following to direction-aware, event-driven travel controls. We’ve broken down the exact mechanics of this shift in our latest operational briefing. 👉 Read the full analysis here: The Great Disconnect: 5 Surprising Realities of Global Risk the Official Advisories Are Missing Right Now https://lnkd.in/efYNPWr7 #RiskManagement #DutyOfCare #ISO31030 #GSOC #SecurityOperations

    • The Great Disconnect: 5 Surprising Realities of Global Risk the Official Advisories Are Missing Right Now 
https://www.linkedin.com/pulse/great-disconnect-5-surprising-realities-global-risk-tony-t49we/
  • A 1 to 5 maturity score is an accounting output. It is not a #risk measurement. Bell-curve grading tells you where you sit against a cohort. It tells you nothing about the specific adversary, tactic or vector you are exposed to right now. These scales exclude the three things that decide outcomes: specific threats, specific tactics, and adversarial efficiency. That is not a minor omission. That is the entire risk picture. Ordinal self-grading fails a basic test. The values are subjective; they are not calibrated between organisations, and aggregating them produces a number that describes nothing real. Substitute one word, and the problem surfaces immediately. Replace "mature" with "ready". Ready against what, assessed when, and on what evidence? The original article is linked in the first comment. #RiskManagement #RiskGovernance #ThreatAssessment

    • Why Your "Security Maturity" is a Dangerous Illusion (and What Actually Keeps You Safe)
https://www.linkedin.com/pulse/why-your-security-maturity-dangerous-illusion-what-tony-aem9e/

Affiliated pages

Similar pages