Risk appetite
How much risk leadership is willing to live with to reach the company's goals.
Draft - this entry has not been reviewed yet.
Formal
A leadership decision stating the amount and type of risk an organisation will accept, used as the line that decides whether a risk needs further treatment.
In plain English
Like how fast you are willing to drive - some people accept more danger to arrive sooner, others do not.
In practice
A pension fund's board writes down that it accepts no risk of losing members' data, but will live with short outages of the internal chat, and the IT security manager plans controls to match.
Why it matters
Without a stated limit, every risk decision becomes a matter of opinion, and leadership cannot be held to account.
Technical deep dive
ISO Guide 73:2009 (since replaced by ISO 31073:2022) defines risk appetite as the amount and type of risk an organisation is willing to pursue or retain, and defines risk tolerance separately as its readiness to bear the risk after treatment in order to achieve its objectives. COSO's 2017 framework Enterprise Risk Management - Integrating with Strategy and Performance adds a third concept, risk capacity, the maximum risk an entity can absorb before its survival or strategy is threatened. In practice appetite is the broad, board-level statement of intent, tolerance is the measurable band of acceptable variation around specific objectives, and capacity is the ceiling appetite must stay well under. NIST IR 8286, on integrating cybersecurity with enterprise risk management, uses the same split, with appetite set at enterprise level and tolerances cascaded down to organisational units and systems. The terms are often used interchangeably, but mixing them hides the difference between a strategic preference and an operational limit.
Useful appetite statements are specific by risk category and expressed in units the business already manages. "Low appetite for cyber risk" cannot drive a decision; "no more than four hours' outage of order handling per quarter", "no single event with more than a 1% annual probability of a loss above 20 million", or "no processing of special-category personal data outside the EU/EEA" can. With quantitative analysis the appetite can be drawn as a curve against the loss exceedance curve, and the gap between the two shows directly where treatment is needed. Many organisations also use a named scale such as averse, minimal, cautious, open and hungry per category, because appetite legitimately differs: a company may be open to risk in product innovation and averse in regulatory compliance.
Appetite operates through the risk acceptance criteria required before assessment by ISO/IEC 27001:2022 clause 6.1.2 a) 1): anything evaluated above them requires treatment or escalated acceptance. It is also cascaded into key risk indicators with thresholds that trigger reporting. Under NIS2 Art. 20(1), management bodies must approve the cybersecurity risk-management measures and oversee their implementation, which in effect makes the appetite a decision the management body owns rather than one delegated to the security function.
The frequent failure is a "zero appetite" statement. Residual risk is never zero, so such statements are either ignored or push risks out of sight; the realistic reading is "minimal", with explicit triggers for escalation. Appetite also contrasts with the risk profile: the profile is the risk the organisation actually carries, the appetite is what it is willing to carry.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Governance
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk appetite
Relationships
- Part of
- Risk management
- Requires
- RiskGovernance
- Unlocks
- Risk acceptance
- Don't confuse with
- Risk profileResidual risk
- Used with
- Risk heat map
Sources & further reading
Standards & official texts
- ISO/IEC 27005:2022
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…