﻿{"id":176,"date":"2026-03-31T20:32:17","date_gmt":"2026-03-31T15:02:17","guid":{"rendered":"https:\/\/blogs.infosys.com\/cybersecurity\/?p=176"},"modified":"2026-04-10T15:31:12","modified_gmt":"2026-04-10T10:01:12","slug":"rethinking-risk-appetite-why-every-organization-needs-a-living-framework","status":"publish","type":"post","link":"https:\/\/blogs.infosys.com\/cybersecurity\/cybersecurity\/rethinking-risk-appetite-why-every-organization-needs-a-living-framework.html","title":{"rendered":"Rethinking Risk Appetite: Why Every Organization Needs a Living Framework"},"content":{"rendered":"<h6><strong>Introduction<\/strong><\/h6>\n<p>Risk appetite has quietly become one of the most misunderstood and underutilized tools in enterprise governance. For years, organizations treated it as a compliance artefact \u2014 a document created once, reviewed infrequently, and rarely connected to day\u2011to\u2011day decision\u2011making. That approach might have worked in a slower, more predictable world. It does not work anymore.<\/p>\n<p>At its core, <strong>risk appetite<\/strong> defines the nature and extent of risk the enterprises are willing to accept while working toward their strategic objectives. It reflects Board and Management expectations about acceptable levels of uncertainty, loss, or disruption, and provides a reference point against which decisions, investments, and tradeoffs are evaluated across the enterprise.<\/p>\n<p>Today\u2019s operating environment is shaped by rapid geopolitical shifts, AI\u2011driven threats, quantum\u2011era uncertainty, and the deep convergence of OT, IT, cloud, and digital systems. Regulators across sectors are raising expectations, supply chains are more fragile than ever, and operational disruptions now carry consequences that extend far beyond financial loss.<\/p>\n<p>In this landscape, risk appetite cannot be static. It must evolve into a living governance instrument \u2014 one that continuously reflects the organization\u2019s strategy, technology footprint, and external environment.<\/p>\n<p>This blog explores what a modern risk appetite framework looks like, why traditional models are no longer sufficient, and how organizations across industries can build a system that is measurable, resilient, and Board\u2011ready.<\/p>\n<h6><strong>Why traditional risk appetite models are no longer enough<\/strong><\/h6>\n<p>Many organizations still rely on qualitative statements such as <em>low tolerance for cyber risk.<\/em> These are well\u2011intentioned but ultimately unenforceable. Without quantified thresholds, they cannot guide decisions, justify investments, or withstand regulatory scrutiny.<\/p>\n<p>Five forces are driving the need for a more dynamic approach:<\/p>\n<p><strong>1. Geopolitical Volatility<\/strong><\/p>\n<p>Sanctions, export controls, and supply chain weaponization now reshape risk exposure in real time. Appetite must explicitly address geopolitical scenarios.<\/p>\n<p><strong>2. AI as Both Attacker and Asset<\/strong><\/p>\n<p>AI\u2011powered phishing, deepfake social engineering, autonomous scanning, and model\u2011drift risks demand a formal AI risk appetite \u2014 something most organizations still lack.<\/p>\n<p><strong>3. Quantum Computing<\/strong><\/p>\n<p>With post\u2011quantum cryptography standards now published, <em>harvest\u2011now, decrypt\u2011later<\/em>\u00a0risk is already live for organizations with long\u2011lived data or OT systems.<\/p>\n<p><strong>4. OT \/ IT \/ Digital Convergence<\/strong><\/p>\n<p>Operational systems \u2014 clinical systems, trading platforms, grid SCADA, plant controls \u2014 are increasingly network\u2011connected. Excluding them from risk appetite is no longer defensible.<\/p>\n<p><strong>5. Regulatory Acceleration<\/strong><\/p>\n<p>NIS2, DORA, the EU AI Act, HIPAA updates, SEC rules, and sector\u2011specific obligations now require demonstrable, quantified appetite.<\/p>\n<h6><strong>A Modern Risk Appetite Framework: A Continuous, Connected System<\/strong><\/h6>\n<p>A contemporary risk appetite model is not a document \u2014 it is an ecosystem. Seven components form the backbone:<\/p>\n<p><strong>1. Crown Jewels<\/strong><\/p>\n<p>Tier assets by consequence of compromise \u2014 not by who owns them. Critical operational systems must be included.<\/p>\n<p><strong>2. Business Impact Analysis (BIA)<\/strong><\/p>\n<p>Quantify disruption cost using RTO, RPO, MTPoD, and MBCO. These values directly set appetite thresholds.<\/p>\n<p><strong>3. Loss Expectancy &amp; Cyber Risk Quantification<\/strong><\/p>\n<p>Convert risk into financial terms (ALE) and probability ranges (VaR). This is the bridge between the Board, the CFO, and the risk function.<\/p>\n<p><strong>4. CMDB<\/strong><\/p>\n<p>An authoritative inventory \u2014 including OT, medical devices, trading systems, and grid controls \u2014 is essential for meaningful quantification.<\/p>\n<p><strong>5. Setting Appetite<\/strong><\/p>\n<p>Board\u2011approved thresholds and KRI bands per risk category. No more qualitative\u2011only statements.<\/p>\n<p><strong>6. Controls &amp; KRIs<\/strong><\/p>\n<p>ROSI\u2011based investment decisions and automated monitoring that signals when thresholds are approached.<\/p>\n<p><strong>7. Monitor &amp; Adapt<\/strong><\/p>\n<p>A continuous loop. AI deployments, cloud migrations, M&amp;A, geopolitical shifts, regulatory changes, and incidents must trigger immediate review.<\/p>\n<h6><strong>What Good Governance Looks Like?<\/strong><\/h6>\n<p>Across industries, mature organizations share five traits:<\/p>\n<p><strong>1. Board Ownership<\/strong><\/p>\n<p>The Board signs the appetite, reviews breaches, and understands the financial exposure.<\/p>\n<p><strong>2. Critical Systems in Scope<\/strong><\/p>\n<p>Operational systems \u2014 trading cores, EMR systems, grid SCADA, plant controls \u2014 are included in Crown Jewels, CMDB, and BIA.<\/p>\n<p><strong>3. Quantified Thresholds<\/strong><\/p>\n<p>ALE, VaR, and ROSI are standard inputs to decision\u2011making.<\/p>\n<p><strong>4. Supply Chain Reality<\/strong><\/p>\n<p>Concentration limits are explicit. Third\u2011party dependencies are mapped. Exceeding thresholds triggers escalation.<\/p>\n<p><strong>5. Living Governance<\/strong><\/p>\n<p>Appetite is refreshed every 6\u201312 months and whenever the environment changes.<\/p>\n<p>The opposite patterns \u2014 qualitative\u2011only statements, OT excluded as <em>operations,<\/em> no quantification, no refresh triggers \u2014 are the root causes of major failures.<\/p>\n<h6><strong>Four principles every organization must adopt<\/strong><\/h6>\n<p><strong>1. Critical operational systems must be in scope \u2014 no exceptions.<\/strong><\/p>\n<p>If a system can halt operations, harm patients, disrupt the grid, or stop trading, it belongs in the appetite framework.<\/p>\n<p><strong>2. Appetite must be expressed in financial terms.<\/strong><\/p>\n<p><em>Low tolerance<\/em>\u00a0is not governance. Boards must know the ALE and VaR for their top scenarios.<\/p>\n<p><strong>3. Refresh every 6\u201312 months.<\/strong><\/p>\n<p>The risk surface changes too quickly for multi\u2011year cycles.<\/p>\n<p><strong>4. Test resilience \u2014 do not declare it.<\/strong><\/p>\n<p>Failover, recovery, and manual fallback must be validated through exercises, not assumed.<\/p>\n<h6><strong>When It Works \u2014 and When It Fails<\/strong><\/h6>\n<p><strong>1. When It Works \u2014 Hypothetical Scenarios<\/strong><\/p>\n<ul>\n<li><strong>Hypothetical Scenario A \u2014 Financial Services<\/strong><\/li>\n<\/ul>\n<p>A regional bank quantifies its risk appetite for the first time, calculating a $95M Value at Risk (VaR) for a large\u2011scale data breach. With quantified thresholds in place, the Board approves targeted controls, and automated KRIs are deployed within six months. Decision\u2011making becomes faster, more defensible, and aligned to financial exposure.<\/p>\n<ul>\n<li><strong> Hypothetical Scenario B \u2014 Healthcare<\/strong><\/li>\n<\/ul>\n<p>A hospital network acquires a regional clinic group and uses the integration as a trigger to reassess its risk appetite. Crown Jewels and BIA exercises reveal gaps in clinical system resilience. New MTPoD thresholds are set, and inherited risks are quantified. The organization enters the post\u2011acquisition period with a clear, Board\u2011approved appetite position.<\/p>\n<p><strong>2. When It Fails \u2014 Hypothetical Scenarios<\/strong><\/p>\n<ul>\n<li><strong>Hypothetical Failure Scenario A \u2014 Energy Utility<\/strong><\/li>\n<\/ul>\n<p>An energy provider excludes grid SCADA systems from its risk appetite, treating them as <em>operations, not security.<\/em> A ransomware incident crosses into OT, forcing a 36\u2011hour suspension of grid operations. With no ALE, no MTPoD, and no regulator\u2011aligned thresholds, the organization faces \u20ac45M in losses and significant regulatory scrutiny.<\/p>\n<ul>\n<li><strong>Hypothetical Failure Scenario B \u2014 Fintech<\/strong><\/li>\n<\/ul>\n<p>A fintech platform relies heavily on a single cloud provider but has no supply\u2011chain concentration thresholds in its appetite. When the provider experiences a major outage, the platform is offline for 18 hours. The incident exceeds what the Board would have considered acceptable \u2014 but no quantified appetite existed to guide decisions or investments.<\/p>\n<h6><strong>Conclusion<\/strong><\/h6>\n<p>Risk appetite is no longer a compliance checkbox. It is the mechanism that connects strategy, technology, and operational reality. Organizations that treat appetite as a living system \u2014 quantified, Board\u2011owned, OT\u2011inclusive, and continuously refreshed \u2014 make better decisions, recover faster, and avoid the blind spots that lead to crisis.<\/p>\n<p>Those that don\u2019t are increasingly exposed to risks they never intended to accept.<\/p>\n<h6><strong>Bibliography<\/strong><\/h6>\n<p>\u2022 <a href=\"https:\/\/www.ibm.com\/reports\/data-breach\">IBM Security (2025) Cost of a Data Breach Report 2025<\/a><br \/>\n\u2022 <a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\">Verizon (2025) Data Breach Investigations Report (DBIR) 2025<\/a><br \/>\n<a href=\"https:\/\/www.weforum.org\/publications\">\u2022 World Economic Forum (2025\/2026) Global Cybersecurity Outlook<\/a><br \/>\n\u2022 <a href=\"https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\">NIST (2024) Post\u2011Quantum Cryptography Standards<\/a><br \/>\n<a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\">\u2022 EU (2022) NIS2 Directive<\/a><br \/>\n\u2022<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\"> EU (2022) Digital Operational Resilience Act (DORA)<\/a><br \/>\n\u2022<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32024R1689\"> EU (2024) Artificial Intelligence Act<\/a><br \/>\n\u2022 <a href=\"https:\/\/www.iso.org\/standard\/65694.html\">ISO (2018) ISO 31000: Risk Management Guidelines<\/a><br \/>\n\u2022 <a href=\"https:\/\/www.coso.org\">COSO (2017) Enterprise Risk Management: Integrating with Strategy and Performance<\/a><\/p>\n<h6><strong>Acronyms &amp; Expansions<\/strong><\/h6>\n<p>ALE \u2014 Annual Loss Expectancy<br \/>\nAI \u2014 Artificial Intelligence<br \/>\nARO \u2014 Annual Rate of Occurrence<br \/>\nBIA \u2014 Business Impact Analysis<br \/>\nCMDB \u2014 Configuration Management Database<br \/>\nCOSO ERM \u2014 Committee of Sponsoring Organizations Enterprise Risk Management<br \/>\nCRQ \u2014 Cyber Risk Quantification<br \/>\nDORA \u2014 Digital Operational Resilience Act<br \/>\nEMR \u2014 Electronic Medical Record<br \/>\nFAIR \u2014 Factor Analysis of Information Risk<br \/>\nHIPAA \u2014 Health Insurance Portability and Accountability Act<br \/>\nIEC 62443 \u2014 Industrial Automation and Control Systems Security Standard<br \/>\nISO 31000 \u2014 International Standard for Risk Management<br \/>\nKRI \u2014 Key Risk Indicator<br \/>\nM&amp;A \u2014 Mergers and Acquisitions<br \/>\nMBCO \u2014 Minimum Business Continuity Objective<br \/>\nMTPoD \u2014 Maximum Tolerable Period of Disruption<br \/>\nMTTR \/ MTTD \/ MTTRec \u2014 Mean Time to Repair \/ Detect \/ Recover<br \/>\nNIS2 \u2014 Network and Information Security Directive 2<br \/>\nOT \u2014 Operational Technology<br \/>\nPQC \u2014 Post\u2011Quantum Cryptography<br \/>\nRAS \u2014 Risk Appetite Statement<br \/>\nROSI \u2014 Return on Security Investment<br \/>\nRPO \u2014 Recovery Point Objective<br \/>\nRTO \u2014 Recovery Time Objective<br \/>\nSCADA \u2014 Supervisory Control and Data Acquisition<br \/>\nVaR \u2014 Value at Risk<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Risk appetite has quietly become one of the most misunderstood and underutilized tools [&hellip;]<\/p>\n","protected":false},"author":1061,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[17],"tags":[45,58,26,32,37,75,76,20,49,33,63,8,73,67,19,72,46,64,74,62],"coauthors":[71],"class_list":["post-176","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","tag-ai","tag-ai-security","tag-artificial-intelligence","tag-compliance","tag-cyber-resilience","tag-cyber-risk","tag-cyber-risk-framework","tag-cybersecurity","tag-digital-transformation","tag-governance","tag-ics-scada-security","tag-infosys-cybersecurity","tag-it-ot-convergence","tag-ot-security","tag-quantum-computing","tag-risk-appetite","tag-risk-management","tag-scada","tag-security-regulations","tag-security-strategy"],"acf":[],"_links":{"self":[{"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/posts\/176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/users\/1061"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/comments?post=176"}],"version-history":[{"count":9,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/posts\/176\/revisions"}],"predecessor-version":[{"id":197,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/posts\/176\/revisions\/197"}],"wp:attachment":[{"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/media?parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/categories?post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/tags?post=176"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.infosys.com\/cybersecurity\/wp-json\/wp\/v2\/coauthors?post=176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}