The idea of risk permeates the information security field. We use terms like ``risk management'', ``risk assessment'', ``risk model'' and ``risk analysis'' every day, and those topics are themselves the subject of countless papers and articles in security journals and magazines. But has the concept of risk become so ingrained within our profession that we have become over confident about how much we really understand it? In this paper I discuss how difficult it is to truly understand risk. I describe why we need to fundamentally reassess many of our current activities that involve trying to calculate and manipulate risk. I also make several proposals for how we can collectively treat risk in a more pragmatic and realistic way.