Risk Appetite

Risk appetite is the amount and type of risk an organization is willing to take in pursuit of its strategic objectives, set by leadership and expressed at the enterprise level as a strategic anchor for risk management decisions.

Risk Appetite vs. Risk Tolerance

Risk appetite is a strategic-level statement about the organization's willingness to take risk in pursuit of objectives. Risk tolerance is the operational-level threshold that translates appetite into specific limits that management can monitor against.

Appetite is the qualitative direction. Tolerance is the quantitative boundary. Both are needed, and both should be set consistently across risk categories.

Setting Risk Appetite for Cyber

Cyber-specific appetite is typically expressed as part of the enterprise risk appetite framework, describing the organization's willingness to accept cyber risk relative to other risk categories. Mature statements are quantified where possible, describing appetite in financial terms rather than through qualitative words like "low" or "moderate."

See cyber risk appetite statement for the specific cyber articulation.

Risk Appetite in Governance

Boards typically approve risk appetite as part of their oversight role. The approved appetite then serves as the reference against which management reports on risk posture and against which the board evaluates whether risk is being managed within agreed bounds.

Regulatory frameworks including DORA, NIS2, and the SEC Cyber Disclosure Rule increasingly expect explicit risk appetite statements for cyber.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.