Risk appetite: from sentence to number
A statement approved in the minutes does not tell an analyst what to do. How to turn appetite into a limit, and a limit into acceptance criteria.
Read article →Guides, analysis and news on Enterprise Risk Intelligence, cyber risk, GRC and compliance.
A statement approved in the minutes does not tell an analyst what to do. How to turn appetite into a limit, and a limit into acceptance criteria.
Read article →Compliance deadline passed in March 2026. The 14 mandatory minimum controls, the Pix requirements, and what ISO 27001 already covered.
Read article →An institution that outsources data processing or cloud still answers for the service. What the rule requires, article by article.
Read article →Version 2.0 added Govern and dropped the critical-infrastructure framing. What changes, and how it sits alongside ISO 27001.
Read article →The heat map ties together risks two orders of magnitude apart. When the decision is about budget, a colour is not enough.
Read article →The 93 controls across four themes, the eleven that are new in 2022, and what an auditor accepts as evidence.
Read article →Nobody fixes 48,000 vulnerabilities a year. The question is not how many you close but which — and CVSS alone answers that badly.
Read article →The numbers look alike; the roles do not. What each standard in the 27k family does, and which one you actually need.
Read article →The standard you get audited against demands a risk assessment and does not say how to run one. ISO 27005 answers that — and it changed in 2022.
Read article →Not a list of IT controls. What the standard actually requires, what changed in 2022, and when certification pays off.
Read article →