Cláudio Gonçalves
← Back to Expertise

Risk Management

Treating risk as something to be surfaced and reduced before it becomes an incident, an audit finding, or a headline.

Risk management runs through every year of this journey, but it became an explicit discipline with the audit-driven precision of 2016, the zero-incident mandate of 2019, the pandemic-era threat surge of 2020, and the formal risk-impact analysis work of 2021.

In practice

  • Vulnerability remediation and audit preparation
  • Formal risk-impact analysis: unauthorized access, exploitation paths, controls assessment
  • Security hygiene as continuous practice rather than a point-in-time control (malware response, endpoint compliance, firewall and VPN hardening)
  • Crisis-driven risk response (ransomware containment, pandemic-era remote-access risk)
  • Risk awareness embedded in architecture review instead of bolted on as a separate compliance step

Why it matters

Every architectural decision is a risk decision, whether or not anyone labels it one. Making that explicit rather than assumed is most of the work; the rest is knowing when to say no to delivery pressure and being willing to be unpopular for an afternoon.

The 2021 risk-impact analysis on the planning and scheduling software is the shape of it. The question was never whether the tool worked. It was who could reach what through it, and what happened if they shouldn't have been able to.


Where this shows up in the journey