Cyber risk appetite: why the board needs to put it in writing
Without a stated threshold, every security decision gets made from scratch — and justified after the fact.

Almost every company has a stated risk appetite for credit, for liquidity, for currency exposure. Far fewer have one for cyber risk — and the result is that every security decision (accepting a residual risk, delaying a critical patch, approving a supplier with weak controls) gets made case by case, often by whoever has the least visibility into the commercial consequences of the choice.
What putting the appetite in writing actually means
It doesn’t mean an abstract number. It means a few sentences the board explicitly approves: which categories of risk the company is willing to accept within certain limits, which always require explicit senior approval, and which are non-negotiable regardless of the cost of mitigating them — typically, the ones that would irreversibly compromise business continuity or the trust of customers and regulators.
A stated appetite also changes how technical teams present options: instead of asking "can we accept this risk?", they can check whether it already sits within an approved threshold, and reserve the board’s attention for genuine exceptions. That cuts both the time lost in unnecessary escalations and the risk that a material decision slips through without proper visibility.
The risk of not having one
Without a stated appetite, every decision risks being judged with hindsight, against the harshest possible standard — the one that applies after an incident, not the one it was reasonable to decide against beforehand. A written, approved appetite protects whoever made the decision just as much as it guides whoever has to make the next one.
The takeaway
Cyber risk appetite doesn’t remove uncertainty. It makes it explicit, puts it in writing, and has it approved by whoever is accountable for it — so later decisions have a yardstick, instead of having to invent one every time.



