Cyber risk appetite: why the board needs to put it in writing

Without a stated threshold, every security decision gets made from scratch — and justified after the fact.

Almost every company has a stated risk appetite for credit, for liquidity, for currency exposure. Far fewer have one for cyber risk — and the result is that every security decision (accepting a residual risk, delaying a critical patch, approving a supplier with weak controls) gets made case by case, often by whoever has the least visibility into the commercial consequences of the choice.

What putting the appetite in writing actually means

It doesn’t mean an abstract number. It means a few sentences the board explicitly approves: which categories of risk the company is willing to accept within certain limits, which always require explicit senior approval, and which are non-negotiable regardless of the cost of mitigating them — typically, the ones that would irreversibly compromise business continuity or the trust of customers and regulators.

A stated appetite also changes how technical teams present options: instead of asking "can we accept this risk?", they can check whether it already sits within an approved threshold, and reserve the board’s attention for genuine exceptions. That cuts both the time lost in unnecessary escalations and the risk that a material decision slips through without proper visibility.

The risk of not having one

Without a stated appetite, every decision risks being judged with hindsight, against the harshest possible standard — the one that applies after an incident, not the one it was reasonable to decide against beforehand. A written, approved appetite protects whoever made the decision just as much as it guides whoever has to make the next one.

The takeaway

Cyber risk appetite doesn’t remove uncertainty. It makes it explicit, puts it in writing, and has it approved by whoever is accountable for it — so later decisions have a yardstick, instead of having to invent one every time.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.