What it means
Most frameworks sort risk into categories so that related items can be owned, compared and reported together. Common groupings include strategic, operational, financial, compliance and legal, technology and cyber, people, and third-party or supply-chain risk. Some sectors add their own: clinical and care quality in health, safety and environmental in industrial operations.
Categories are a reporting convenience rather than a truth about the world. The risks that cause the most trouble usually cross several at once — a supplier failure is simultaneously operational, financial, compliance and reputational — so a category structure that forces a single home can hide the connection.
Where MyRISK fits
What we do about it
MyRISK works across all risk rather than cyber alone, which is why every sector page carries at least one example that is not cyber, privacy or AI. Categories matter less to us than whether a risk has an owner, a consequence somebody can name, and an action that moves.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.