Risk transfer is a risk response strategy that shifts the financial impact of a risk onto another party. The most familiar example is cyber liability insurance: the organization pays premiums, and the insurer agrees to cover losses from qualifying incidents up to the policy limit. Contracts can transfer risk too, through indemnification clauses or by assigning responsibility to a vendor.
What transfers is money, not the event itself, and this is the distinction people blur. A policy does not stop a breach from happening. The organization still faces operational disruption, regulatory scrutiny, customer anger, and reputational harm, and insurers increasingly deny claims when required controls were not actually in place. Treating insurance as a substitute for security, rather than a backstop behind it, is how companies end up paying premiums for coverage that quietly does not apply when they need it.
Why does risk transfer matter for the CISSP exam?
Risk transfer is one of the four risk response options in Domain 1: Security and Risk Management, next to avoidance, mitigation, and acceptance. Candidates must know when each is appropriate and how insurance and contractual mechanisms shift, but never fully remove, exposure.