Skip to content
atlas

Risk appetite

How much risk leadership is willing to live with to reach the company's goals.

Draft - this entry has not been reviewed yet.

Formal

A leadership decision stating the amount and type of risk an organisation will accept, used as the line that decides whether a risk needs further treatment.

In plain English

Like how fast you are willing to drive - some people accept more danger to arrive sooner, others do not.

In practice

A pension fund's board writes down that it accepts no risk of losing members' data, but will live with short outages of the internal chat, and the IT security manager plans controls to match.

Why it matters

Without a stated limit, every risk decision becomes a matter of opinion, and leadership cannot be held to account.

Technical deep dive

ISO Guide 73:2009 (since replaced by ISO 31073:2022) defines risk appetite as the amount and type of risk an organisation is willing to pursue or retain, and defines risk tolerance separately as its readiness to bear the risk after treatment in order to achieve its objectives. COSO's 2017 framework Enterprise Risk Management - Integrating with Strategy and Performance adds a third concept, risk capacity, the maximum risk an entity can absorb before its survival or strategy is threatened. In practice appetite is the broad, board-level statement of intent, tolerance is the measurable band of acceptable variation around specific objectives, and capacity is the ceiling appetite must stay well under. NIST IR 8286, on integrating cybersecurity with enterprise risk management, uses the same split, with appetite set at enterprise level and tolerances cascaded down to organisational units and systems. The terms are often used interchangeably, but mixing them hides the difference between a strategic preference and an operational limit.

Useful appetite statements are specific by risk category and expressed in units the business already manages. "Low appetite for cyber risk" cannot drive a decision; "no more than four hours' outage of order handling per quarter", "no single event with more than a 1% annual probability of a loss above 20 million", or "no processing of special-category personal data outside the EU/EEA" can. With quantitative analysis the appetite can be drawn as a curve against the loss exceedance curve, and the gap between the two shows directly where treatment is needed. Many organisations also use a named scale such as averse, minimal, cautious, open and hungry per category, because appetite legitimately differs: a company may be open to risk in product innovation and averse in regulatory compliance.

Appetite operates through the risk acceptance criteria required before assessment by ISO/IEC 27001:2022 clause 6.1.2 a) 1): anything evaluated above them requires treatment or escalated acceptance. It is also cascaded into key risk indicators with thresholds that trigger reporting. Under NIS2 Art. 20(1), management bodies must approve the cybersecurity risk-management measures and oversee their implementation, which in effect makes the appetite a decision the management body owns rather than one delegated to the security function.

The frequent failure is a "zero appetite" statement. Residual risk is never zero, so such statements are either ignored or push risks out of sight; the realistic reading is "minimal", with explicit triggers for escalation. Appetite also contrasts with the risk profile: the profile is the risk the organisation actually carries, the appetite is what it is willing to carry.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Governance
  3. →Threat
  4. →Asset
  5. →Vulnerability
  6. →Impact
  7. →Likelihood
  8. →Risk
  9. →Risk appetite

Relationships

Don't confuse with
Risk profileResidual risk
Used with
Risk heat map

Sources & further reading

Standards & official texts

  • ISO/IEC 27005:2022

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.