However, few traditional methodologies adequately address the contextual variability of threat given modifications in the core environment. This is a fatal flaw when contemplating extremely distributed applications or Web services. Most companies will categorise risks as “high risk” or “low risk” with the previous taking precedence for obvious reasons. It can be an opportunity for security leaders to educate business leaders about potential threat exposures. With organisations now spending upwards of $150bn on safety and risk management know-how yearly, ESRM is now a key ingredient within the recipe for business success. So, what is Enterprise Security Risk Management and how are you going to implement an ESRM technique into your small business operations?