Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Governance

Cyber risk appetite

Cyber risk appetite is the amount and type of cybersecurity risk an organization’s leadership is willing to accept in pursuit of its objectives, expressed as thresholds that individual risks and indicators can be measured against. A risk within appetite is monitored; a risk above it must be treated, transferred or explicitly accepted at the right level of authority. Tolerance is the operational margin around the appetite, the point at which an indicator triggers an alert.

A sentence is not an appetite

Many appetite statements read “we have a low appetite for cyber risk”, which cannot be measured and therefore never binds anyone. A usable appetite is set per risk category (data confidentiality, service availability, third-party exposure, regulatory non-compliance) with a scale the register already uses, so that each residual risk can be compared to it. It is approved by the board or the risk committee, which is what makes an acceptance above appetite a governed decision rather than a quiet default.

Breach alerts and the acceptance ladder

Once thresholds exist, two mechanisms follow. First, a breach alert: when a residual score or a key risk indicator crosses its threshold, the owner is notified and the item enters the treatment queue. Second, an acceptance ladder: who may accept a risk above appetite, for how long, and with what compensating controls, with the acceptance recorded, dated and reviewed at expiry. Without the ladder, appetite is exceeded by whoever answers last.

What boards are now asked for

NIS2 makes management bodies responsible for approving cyber risk-management measures and overseeing their implementation; DORA asks financial entities to set and periodically review a digital operational resilience strategy with a risk tolerance for ICT risk. In both cases the supervisor can ask to see the appetite, the measurements against it and the decisions taken when it was exceeded. A board pack that shows the three answers the question before it is asked.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.