Do risk awareness and risk management strategies actually make a difference?

If cyber attacks are a matter of when, not if, it's tempting to ask whether risk awareness and risk management are effective

Do risk awareness and risk management strategies actually make a difference? at ITPro