A sentence is not an appetite
Many appetite statements read “we have a low appetite for cyber risk”, which cannot be measured and therefore never binds anyone. A usable appetite is set per risk category (data confidentiality, service availability, third-party exposure, regulatory non-compliance) with a scale the register already uses, so that each residual risk can be compared to it. It is approved by the board or the risk committee, which is what makes an acceptance above appetite a governed decision rather than a quiet default.
Breach alerts and the acceptance ladder
Once thresholds exist, two mechanisms follow. First, a breach alert: when a residual score or a key risk indicator crosses its threshold, the owner is notified and the item enters the treatment queue. Second, an acceptance ladder: who may accept a risk above appetite, for how long, and with what compensating controls, with the acceptance recorded, dated and reviewed at expiry. Without the ladder, appetite is exceeded by whoever answers last.
What boards are now asked for
NIS2 makes management bodies responsible for approving cyber risk-management measures and overseeing their implementation; DORA asks financial entities to set and periodically review a digital operational resilience strategy with a risk tolerance for ICT risk. In both cases the supervisor can ask to see the appetite, the measurements against it and the decisions taken when it was exceeded. A board pack that shows the three answers the question before it is asked.