Black Kite is a finalist in the 2026 SC Awards for continued innovation and leadership in third-party cyber risk intelligence.Learn more
BlackKite: Home
Menu
Back to Glossary

Risk Mitigation

Risk mitigation is the process of taking actions to reduce the likelihood or impact of an identified risk. In third-party cyber risk management, risk mitigation strategies include requiring vendors to remediate specific vulnerabilities, implementing compensating controls at the first-party level, adjusting the scope of a vendor's access to sensitive systems, or in some cases terminating the vendor relationship. Risk mitigation decisions are typically made in the context of a vendor's inherent risk, residual risk, and the first party's risk appetite.