Risk appetite needs operational thresholds

"We have a low appetite for cyber risk" cannot be acted on by anybody.

To change a decision it has to reach numbers: how long we tolerate being unable to trade, how much data loss is acceptable, what severity of finding stops a release. Without thresholds, appetite is a sentiment in a board paper, and every practical decision is made without reference to it.

More on Governance and risk