Risk appetite needs operational thresholds
"We have a low appetite for cyber risk" cannot be acted on by anybody.
To change a decision it has to reach numbers: how long we tolerate being unable to trade, how much data loss is acceptable, what severity of finding stops a release. Without thresholds, appetite is a sentiment in a board paper, and every practical decision is made without reference to it.
More on Governance and risk
- 'compliance means secure'Certified, and propped open
- Risk is about uncertain impact, not merely bad thingsWhere it might land
- A risk register is a decision queue, not a museumNot a display case
- Risk acceptance spends organisational toleranceSigned, and spent
- Control effectiveness is separate from control existenceTicked, and still empty
- Risk owners need authority over the consequenceThe name, not the lever
