What Acceptable Risk Means When Nobody Has Priced It

What Acceptable Risk Means When Nobody Has Priced It

Most organisations have a risk appetite statement. Almost all of them are written in adjectives — low appetite for regulatory risk, moderate appetite for operational risk — and adjectives cannot be compared against anything.

Here is a number to put against one of them.

The Australian Signals Directorate’s most recent threat report puts the average self-reported cost of cybercrime to a small business at $56,600 per incident, up 14%. Across all business sizes the average is $80,850, up 50%.

What that $56,600 actually buys — where the money goes, and which parts of it you can remove before anything happens — is taken apart in Cloud Geeks’ piece on exactly that. The question here is a different one: not what the figure covers, but what an organisation does differently once any figure exists at all.

The interesting question is not whether that figure is right for you. It is what an organisation does differently once it exists.

The number is not the decision

$56,600 is a mean across self-reported incidents of wildly varying severity. Most cost less. A few cost far more. Planning to the mean is planning to an outcome almost nobody experiences.

Its use is narrower and more valuable: it establishes an order of magnitude, and the order of magnitude is what most risk appetite statements are missing.

“We have a low appetite for operational disruption” is compatible with spending nothing and with spending a quarter of a million dollars. Attach a figure — even a rough, externally-sourced, acknowledged-as-imprecise figure — and the statement starts constraining decisions, because you can now ask whether a proposed control costs more or less than the thing it prevents.

Why the effective controls never make a budget

This is the part that matters at board level, and it is structural rather than a failure of will.

Strip an incident into its components and you get: downtime, establishing what happened, rebuilding, notification and legal, customers lost, and — usually smallest — money actually taken.

The two largest are downtime and establishing what happened. Both are determined before the incident, and neither is determined by a purchase.

Downtime is decided by whether a restore has been rehearsed. Not whether backups run. Whether somebody has performed a restore, timed it, and confirmed it produced working data. A business that has done this knows its outage in hours. One that has not does not know, and will discover the answer at the worst moment.

Investigation cost is decided by whether the logs exist. If sign-in and file-access history covers a useful period, scoping is a day’s work. If it has already rolled off — and lower licence tiers frequently retain less than the 30 days you may have to assess within — the investigation becomes inference, and inference is billed by the hour.

Both of those are exercises, not products. They have no vendor, no line item, no renewal date and nobody selling them. Which means they lose every budget round to things that do, and the things that do address the probability of an incident rather than its cost.

★ Insight ───────────────────────────────────── There is a straightforward governance fix, and it is a reporting change rather than a spending one. Most risk registers track controls by whether they are in place. Add a column for when each was last exercised. A backup in place and never restored, an incident plan in place and never walked through, an alert in place and never fired — all three read as green today, and all three are the reason an incident costs what it costs. ─────────────────────────────────────────────────

The insurance conversation, properly

Cyber insurance comes up immediately after the number does, and two features of it surprise boards.

Policies increasingly require specific controls to be in place, with multi-factor authentication the most common. A claim on a policy where the required control was not actually enabled is a difficult conversation at the worst possible time. The governance question is not “are we insured” but “can we evidence the controls the policy assumes”.

The waiting period matters more than the limit. Business interruption cover typically starts after a waiting period — 12, 24, sometimes 72 hours. Most small-business outages resolve inside that window, which means the cover that would have paid is the cover nobody read. A policy with a high limit and a 72-hour waiting period is, for a typical incident, insurance against nothing.

Insurance is a transfer of the tail. It does not address the incident you are actually likely to have, and it is frequently bought as though it did.

Why adjectives survive

It is worth being fair to the adjective, because it persists for reasons that are not laziness.

A number in a risk appetite statement is a commitment. “We accept up to $50,000 of annual expected loss from operational disruption” can be held against you — by a board, an auditor, an insurer, or a plaintiff. An adjective cannot, which makes it the safer thing to write and the reason most statements contain one.

The second reason is genuine difficulty. Expected loss requires a probability, and for a small organisation the probability of a cyber incident in a given year is not knowable from its own history, because its own history contains almost no events.

Both are real. Neither supports leaving the statement at “moderate”, because a middle option exists and is rarely taken: state the exposure without claiming the probability. “A three-day outage would cost us approximately $X” is a defensible, checkable sentence that requires no forecasting at all. It is arithmetic on your own revenue, and it converts the conversation from appetite to consequence — which is the half you can actually act on.

Three questions that turn an adjective into a decision

1. What does a day of not operating cost us?

Weekly revenue divided by five. Multiply by three for a plausible outage. That figure takes ten minutes and it is the one number that makes every subsequent conversation concrete. For most small businesses it lands uncomfortably close to the published average without anything having been stolen.

2. When was each control last exercised, and what happened?

Not “do we have backups”. When was one restored, how long did it take, did the data work. Not “do we have an incident plan”. When did anyone walk through it, and what did that reveal.

3. Which of our controls would we be unable to evidence to an insurer?

This is the question that finds the gap between the register and reality, and it finds it before a claim rather than during one.

What “acceptable” should mean

A risk is genuinely accepted when four things are written down: what is being accepted, who decided, when, and what would change the decision.

We use that structure internally for engineering decisions and it transfers directly. An acceptance that names the risk, the decision-maker, the date and the trigger for revisiting is a governance artefact. An acceptance that says “moderate appetite” is a sentence.

The difference shows up at exactly one moment — when the risk materialises and somebody asks whether it was considered. A dated record with a named decision-maker answers that. An adjective does not, and its absence tends to be read as an absence of thought rather than an absence of writing.

Where the number comes from matters as much as the number

One methodological point, because it decides how much weight the figure can carry.

$56,600 is self-reported. It reflects what businesses that chose to report an incident said it cost them. That introduces two biases pulling in opposite directions, and neither is small.

Businesses that report at all skew toward the more serious end — a minor incident absorbed internally never enters the dataset, which pushes the average up. But self-assessed cost tends to capture the visible components, the invoices and the obvious downtime, and to miss the diffuse ones, particularly customers who quietly did not return. That pushes it down.

The net direction is genuinely unknown, which is the honest position and also the useful one: treat it as an order of magnitude with real uncertainty rather than as a point estimate with false precision.

That matters practically because boards ask for precision the data cannot give. The right response is not to invent it but to move the conversation to the number that is precise and is yours — what a day of not operating costs your business — and to note that the external figure is only there to establish that the question deserves asking.

The honest summary

The published cost figure will not tell you what an incident costs your business. What it does is establish that the number is large enough to deserve a stated position, and most organisations do not have one — they have an adjective and a set of controls whose last exercise date nobody tracks.

Fixing that is free. It is a column in a register, a ten-minute revenue calculation, and a decision written down with a date on it.

Source: ASD Annual Cyber Threat Report 2024-25. Figures are self-reported averages, not a prediction for any individual business.


Risk governance, control assurance and the question of what your register is actually asserting is part of the advisory work we do through Ganda Tech Services, with security operations through Cloud Geeks.

Free Roadmap · 2026

Digital Transformation Roadmap 2026

A 12-month framework for Australian SMBs ready to modernise — phases, tools, and milestones.

We email a confirmation link first. No spam. Unsubscribe any time.