An оrgаnizаtiоn cаnnоt patch a legacy system. It isolates the system on its own VLAN behind tightly scoped ACLs, purchases cyber-insurance covering losses arising from that system, and records an annually reviewed sign-off from the system owner accepting what remains. Which combination of risk responses is present?