Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Market Risk
Cyber Security

Market Risk

← Back to Glossary
By NHI Mgmt Group Updated September 23, 2026 Domain: Cyber Security

Market risk is the chance that portfolio value will move because prices, volatility, or correlations change. In digital assets, it affects spot, futures, perpetuals, and options positions, and it requires controls that measure exposure across instruments rather than treating each trade in isolation.

What Market Risk Means in Practice

Market risk is not just price movement in isolation, it is the possibility that a position, strategy, or book changes in value because the whole market reprices around it. That includes direction, volatility, and the relationships between assets, which can make seemingly diversified positions move together at the same time.

For digital assets, the practical challenge is that spot, futures, perpetuals, and options often interact. A trade can look balanced on one venue or in one instrument while still carrying meaningful net exposure once funding, basis, gamma, and correlation effects are considered together.

That is why market risk is best understood as a cross-instrument measurement problem. If controls only review each trade on its own, they can miss concentration, offsetting positions that fail under stress, or exposures that become larger when liquidity worsens.

How Market Risk Is Measured and Managed

Market risk is usually measured by looking at sensitivity, scenario loss, and portfolio-wide exposure rather than single-trade profit and loss alone. Common lenses include delta, volatility, basis, correlation, and stress moves that test how the book behaves when markets gap, not just when they drift.

The point is to understand what actually drives loss across the portfolio. Two positions that appear opposite on paper can still produce the same downside if they share the same underlying market factor, or if one leg becomes harder to hedge when volatility expands.

Effective controls therefore focus on aggregation and consistency. Exposure needs to be measured at the level where risk is actually created, including across instruments, maturities, venues, and execution styles, so that the organisation sees the true net position before deciding whether to rebalance or reduce it.

Why Market Risk Becomes Harder in Digital Assets

Digital asset markets can reprice quickly, trade around the clock, and shift from orderly to dislocated with little warning. That makes traditional assumptions about liquidity, correlation stability, and continuous hedging less reliable, especially during leverage flushes or exchange-specific stress.

Perpetual futures and options add extra layers of sensitivity because funding, implied volatility, and strike positioning can change the risk profile even when spot prices look stable. A position may be directionally small but still vulnerable to a sharp change in volatility or basis.

Market risk also interacts with operational resilience. When liquidity thins, spreads widen, or venues fragment, the ability to exit or hedge can weaken just when the portfolio most needs protection. For that reason, risk measurement should be paired with realistic assumptions about execution and market depth.

Control Design and Governance for Market Risk

Market risk controls work best when they are designed around aggregation, limits, and escalation. A useful control set answers three questions: what is the true portfolio exposure, what scenarios would threaten it, and who is accountable for acting before losses become structural.

Governance matters because market risk is often distributed across desks, instruments, and venues. If ownership is fragmented, firms may see local hedges as complete even when the combined book still carries significant factor exposure.

For reference, NIST Cybersecurity Framework 2.0 is a useful governance model for organising risk oversight, while SOC 2 Trust Services Criteria (AICPA) can help frame control discipline around monitoring, availability, and integrity in operational environments.

Risk and Threat Considerations

Market risk matters because a portfolio can become vulnerable even when no single trade looks dangerous. Correlation breakage, volatility spikes, and liquidity collapse can turn a hedged book into a loss-making book very quickly, especially when positions are leveraged or concentrated.

Failure mechanism: The failure usually comes from assuming that relationships between instruments will remain stable, while the market is actually changing the correlations, implied volatility, or tradability that the hedge depends on.

Impact: The result can be unexpected drawdowns, forced liquidation, hedge slippage, and a rapid widening between paper exposure and executable exit price.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyMarket risk requires organisation-wide risk oversight and tolerance setting.
ID.RA — Risk AssessmentMarket risk depends on scenario analysis, exposure measurement, and stress testing.
PR.MA — MaintenanceReliable risk measurement depends on sound models, data, and operational control of the risk stack.
Recommendation — Set portfolio risk tolerance and escalate breaches through a defined governance process. Assess portfolio exposure under adverse price, volatility, and correlation scenarios. Maintain risk models and market data inputs so exposure calculations remain trustworthy.
CIS Controls v808 — Audit Log ManagementPortfolio risk oversight needs traceable monitoring and review of valuation and risk changes.
13 — Network Monitoring and DefenseMarket risk control relies on continuous monitoring of conditions that affect tradability and execution.
14 — Security Awareness and Skills TrainingRisk decisions depend on operators understanding correlation, leverage, and scenario loss.
Recommendation — Retain and review exposure changes so large swings are visible and attributable. Monitor market conditions and execution venues for signs of deteriorating liquidity or stress. Train traders and risk owners to recognise when apparent hedges fail under stress.
NIST AI RMFMAP — Measure, Analyze, and MonitorMarket risk is fundamentally a measurement and monitoring problem across evolving conditions.
GOV — GovernRisk appetite, ownership, and escalation for market exposure are governance concerns.
Recommendation — Measure exposure, analyze stress outcomes, and monitor changes in correlation and volatility. Define ownership for market exposure limits and review breaches through governance.

Practitioner Guidance

What to watch for: Focus on scenarios where a position is only safe if spreads, correlations, or funding remain stable. Those are the setups most likely to fail under stress and the ones most likely to hide risk when controls are instrument-by-instrument rather than portfolio-wide.

Practitioner takeaway: If the risk view cannot show net exposure across related instruments, it is usually underestimating market risk rather than managing it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org