Risk Tolerance
Risk tolerance is the operational-level threshold that translates strategic risk appetite into specific quantitative or qualitative limits that management can monitor exposure against and use to trigger escalation.
Tolerance vs. Appetite
Risk appetite is the strategic-level statement of willingness to take risk. Risk tolerance is the operational threshold that makes appetite actionable. Appetite might be "we accept moderate cyber risk." Tolerance would be "we will not exceed $X in 1:100 annual cyber loss exposure at the enterprise level."
Tolerance is what management actually monitors against. When exposure approaches or exceeds tolerance, escalation and treatment are triggered.
Cyber Risk Tolerance Specifics
Cyber tolerance is typically expressed in quantified terms, using outputs from CRQ. Common forms include enterprise-level thresholds on 1:100 or 1:250 annual loss, scenario-level thresholds for specific high-impact events, and control-effectiveness thresholds for specific critical controls.
Tolerance may also include qualitative red lines: specific activities, jurisdictions, or data categories that will not be entered regardless of financial analysis.
Tolerance in Governance
Tolerance thresholds are typically approved at the board or executive committee level as part of the risk appetite framework. Management then reports against them, with defined escalation paths when thresholds are approached or breached. Tolerance is one of the primary mechanisms boards use to exercise ongoing cyber oversight.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


