home  /  standard of care  /  risk proportionality
the standard · cybersecurity incidents

Risk proportionality.

The same control set can be reasonable for one organization and indefensible for another. Proportionality is what separates them.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to risk proportionality. Pick a starting point, or describe the incident directly.

Incident Conciergerisk proportionality · orientation, not a security opinion
Tell me what data the organization held, roughly how much, and what sector it is in. Proportionality starts with the risk profile rather than the control list, and that is usually the more productive starting point.

Proportionality is the clause in the reasonable-security standard that actually decides cases, and it is the one least amenable to a checklist. It asks whether the safeguards an organization maintained were commensurate with what it held and what it faced — the sensitivity and volume of its data, the regulatory regime over it, the threat environment for its sector, its resources, and the harm a compromise would cause. The analysis is genuinely two-directional, which practitioners on both sides tend to forget: a small organization holding trivial data is not required to run an enterprise program, and an organization holding millions of sensitive records does not discharge its duty by pointing at a modest budget. Getting this right is what stops the standard collapsing into either perfection or excuse.

mechanisms

What proportionality weighs.

Each factor pushes the expected standard up or down, and they are assessed together.

Data sensitivity and volume

Health, financial and biometric data raise the standard sharply. So does sheer scale.

Regulatory regime

Where a sector rule applies it usually sets a floor beneath the proportionality analysis.

Threat environment

Whether the sector was known to be actively targeted, and whether the organization knew.

Resources

Real and relevant, and not a defense for omitting basic controls that cost little.

Foreseeable harm

What a compromise would do to the people whose data it is. Raises the expected standard.

Prior warnings

Earlier incidents, audit findings or intelligence. Knowledge of a risk raises what is expected in response.

methodology

What the evidence shows — and what we examine.

How proportionality is assessed.

Profile the risk firstData held, regime, sector threat and foreseeable harm — before looking at any control.
Compare like with likePeer organizations of similar size, sector and data profile, not an industry average.
Read the organization’s own assessmentsWhat it said about its own risk beforehand is the most powerful evidence either way.
Test both directionsWhether the program was under-built for the risk, and whether the claim demands more than proportion allows.
what's at stake

What proportionality decides.

Where the line sits between an unfortunate breach and a negligent one.

whether the duty was breached how far the expected standard rises whether budget is a credible answer which internal documents matter most what peer evidence is needed board and officer exposure

Knowing about a risk raises the standard for it.

An organization that suffered a similar incident, received an audit finding, or was warned about a threat and did not respond proportionately is in a materially weaker position than one that never knew. Prior warnings are the first thing a competent plaintiff looks for.

common questions

Proportionality — practical questions.

Is a limited budget a defense?

Partially, and it is weaker than defendants expect. Resources are a legitimate factor and no one is required to spend without limit — a small organization is genuinely not held to a bank's program. But budget does not excuse controls that are basic and inexpensive, and multi-factor authentication, tested backups, and a patching process now fall on the wrong side of that line for almost anyone. Budget is also considerably less persuasive where the organization chose to hold large volumes of sensitive data: the proportionality argument runs on what you held, not only on what you could afford.

How is the peer comparison established?

With evidence rather than assertion, which is harder than it sounds and often decides which expert is believed. Credible peer evidence comes from published sector surveys, regulatory guidance aimed at organizations of that size, framework tiering, and the expert's own documented experience across comparable environments. What does not travel well is an expert generalising from enterprise practice to a mid-market defendant, and a competent cross-examination will find that gap quickly.

Does holding more data automatically raise the standard?

Yes, in both sensitivity and volume, and this is one of the more settled parts of the analysis. An organization that chose to collect and retain millions of sensitive records has assumed a correspondingly higher obligation to protect them. It also raises a question defendants frequently have no good answer to: why was that data still being held at all? Retention beyond any business need is a recurring and avoidable aggravating fact, because the cheapest control is not holding the data.

Can proportionality cut in the defendant’s favor?

Regularly, and it is under-used. Where a plaintiff's expert argues for controls that would be disproportionate for an organization of that size and risk profile — enterprise-grade monitoring for a small operation, say — proportionality is the direct answer, and it is more persuasive than disputing the control's value. The defense is strongest where the organization can show it actually performed a risk assessment, reached a reasoned conclusion, and documented it at the time.

related

Related specialization areas & resources.

Profile the risk before the controls.

Describe what the organization held and faced. The Institute will help you frame the proportionality question.

incident conciergeorientation · not a security opinion
Tell me what data the organization held, roughly how much, and what sector it is in. Proportionality starts with the risk profile rather than the control list, and that is usually the more productive starting point.