Cyber Risk Appetite Statements That Can Be Breached
Most cyber risk appetite statements cannot be breached. A board approves language about maintaining a low tolerance for disruption, the statement enters the policy library, and no observable event in the following three years violates it. A statement no event can cross is a value rather than a control. Making one testable requires four terms that get used interchangeably and mean different things, thresholds expressed in units something can exceed, and a defined response for when it does.