Risk and Governance

How much IT risk is acceptable?

IT risk is a business decision, not an IT decision. The board or owner decides how much risk to accept, IT presents the options and costs, and residual risk is documented in writing in a risk register reviewed quarterly. Essential Eight Maturity Level 1 is the minimum for insurability and most customer contracts; ML2 is the target for most Australian SMBs. Without a stated tolerance, every investment argument is a debate.

See how to frame risk for the board
Updated By Real Bytes

IT risk is a business decision, not an IT decision

The question is not whether IT wants more security, it is how much risk the business accepts. A board that owns that decision invests properly, avoids blame games and aligns spend to outcomes. A board that does not ends up surprised, under-insured and reactive.

Risk tolerance is a statement, not a feeling. It says what the business will and will not accept in financial, reputational and regulatory terms. IT maps the threats and controls, presents residual risk at different investment levels, and the business accepts the remainder in writing.

Who decides risk tolerance

The board or owner decides risk tolerance. Not the IT manager, not the MSP. IT presents the options, costs and consequences. The business owners accept the residual risk. This is the single most important governance principle in IT security.

  • IT maps threats and controls

    IT identifies the threats, the current controls and the gaps. This is the technical assessment, not the business decision.

  • IT presents residual risk

    IT presents residual risk at different investment levels: what changes if we spend X, what changes if we spend Y. Options, not opinions.

  • Board accepts residual risk

    The board or owner accepts the residual risk in writing. In minutes, not verbally. This is the business decision.

  • Review quarterly

    The risk register is reviewed quarterly or after a major change. Technology and threats change fast; an annual review is not enough.

Framing IT risk for the board

The board needs dollars, not jargon. Tell them what a ransomware recovery costs and how likely it is, then present three options: accept, mitigate or transfer to insurance. Each with a price.

  • Use dollars, not jargon

    Tell the board ransomware recovery is estimated at $2 to 6 million over 60 days, not that you lack immutable backups. Money is the language the board speaks.

  • Quantify likelihood

    Use Annualised Loss Expectancy: likely frequency multiplied by cost per event. Even a rough estimate beats a feeling.

  • Present three options

    Accept the risk, mitigate it with controls, or transfer it to insurance. Each option has a cost and a residual risk level.

  • Map to existing tolerance

    The board already accepts financial, reputational and regulatory risk in other areas. Map IT risk to the same scale so it is comparable.

Track the risk score over time. A board that sees the trend, not just the snapshot, understands whether things are getting better or worse. Momentum matters more than any single number.

Essential Eight maturity and risk

Essential Eight Maturity Level is the simplest anchor for Australian SMBs. It gives the board a grade that insurers, regulators and major customers understand. Each level represents a defined set of controls and a corresponding risk posture.

  • ML0: not acceptable

    No deliberate mitigation. Unacceptable for any commercial business handling customer data or operating online.

  • ML1: minimum insurable

    Minimum for insurability and most customer contracts. Most insurers will not bind cover below ML1.

  • ML2: SMB target

    Target for most SMBs. Insurance premium benefit and strong protection against common attacks.

  • ML3: regulated sectors

    Required for regulated industry, defence, government and critical infrastructure. The highest practical level for most.

Moving from ML1 to ML2 typically reduces cyber insurance premiums by 15 to 30 per cent, depending on the insurer and sector. The saving often covers the cost of the uplift.

Insurance implications

Cyber insurance is no longer a blanket shield. Insurers ask detailed questions about MFA, backups, EDR, admin controls and incident response. Gaps mean higher premium, higher excess or denied claims. Your risk register is effectively your insurance application.

  • Insurers assess controls

    MFA on every account, EDR on every endpoint, immutable backups, separate admin accounts and a tested IR plan are baseline expectations.

  • Gaps cost money

    Missing controls mean higher premiums, higher excess or coverage exclusions. Some insurers will not quote at all below ML1.

  • Disclosure is ongoing

    Material changes to your security posture must be disclosed to your insurer. A control that lapses after binding can void cover.

Quantifying risk in dollars

These are the cost ranges we use to frame IT risk for Australian boards. They are indicative, not precise, but they give the board a number to work with instead of a vague feeling.

Indicative cost ranges for common IT risk scenarios in Australia

Risk scenario
Ransomware
Indicative cost
$500k to $5M
Key driver
Size, downtime, notification and reputation
Risk scenario
Business email compromise
Indicative cost
$50k to $1M+
Key driver
Invoice fraud is growing faster than ransomware
Risk scenario
Data breach (Privacy Act)
Indicative cost
Up to $50M
Key driver
OAIC penalties for serious or repeated breaches
Risk scenario
Operational disruption
Indicative cost
Per hour of downtime
Key driver
Revenue-generating systems down
Risk scenario
Reputational damage
Indicative cost
Hard to quantify
Key driver
Customer churn, tender disqualification, press

These ranges are indicative. The actual cost depends on the size of the business, the sector, the data involved and the speed of response. Use them to start the board conversation, not to replace a proper assessment.

Common mistakes in IT risk management

These are the mistakes we see in every business that gets caught out. Each one turns a manageable risk into an expensive surprise.

  • Treating IT risk as an IT problem

    Board ownership is required. Without it, investment follows noise instead of priority and no one accepts the residual.

  • No documented risk tolerance

    Without a stated tolerance, every investment argument is a debate. Write it down, agree it and review it.

  • No risk register

    Without a register, risks drift, controls lapse and nobody knows the current picture. A simple spreadsheet is enough to start.

  • Accepting risk verbally

    Risk acceptance needs to be in writing, in minutes, audited. Verbal acceptance is not acceptance.

  • Reviewing annually only

    Technology and threats change quarterly. Annual risk reviews are too slow for the pace of change.

How we run an IT risk assessment

We scope an IT risk assessment as a fixed-fee engagement. You receive a board-ready risk register, a scored posture against Essential Eight and a prioritised treatment plan with costs.

  1. Step 1

    Assess current posture

    We assess your environment against Essential Eight maturity levels. You receive a scored report with every gap identified.

  2. Step 2

    Build the risk register

    We build a board-ready risk register with likelihood, impact and treatment options. You review it with us before it goes to the board.

  3. Step 3

    Agree tolerance and treatment

    We facilitate a tolerance discussion with your board or owner. You agree what to accept, mitigate and transfer, in writing.

  4. Step 4

    Review quarterly

    We review the register quarterly and after major changes. You see the trend, not just the snapshot.

Common questions

Who should decide IT risk tolerance in a business?

The board or business owner decides IT risk tolerance, not the IT manager or MSP. IT maps the threats and controls, presents residual risk at different investment levels, and the business accepts the remaining risk in writing. Without board ownership, investment follows noise instead of priority.

What Essential Eight maturity level should my business target?

Essential Eight Maturity Level 1 is the minimum for insurability and most customer contracts. Level 2 is the target for most Australian SMBs and typically reduces cyber insurance premiums by 15 to 30 per cent. Level 3 is required for regulated sectors, defence, government and critical infrastructure.

How do you quantify IT risk for the board?

Use dollars, not jargon. Tell the board what a ransomware recovery costs and how likely it is, using Annualised Loss Expectancy: likely frequency multiplied by cost per event. Present three options: accept the risk, mitigate it with controls or transfer it to insurance. Each option has a cost and a residual risk level.

What is a risk register and why do I need one?

A risk register is a documented list of identified risks, their likelihood, impact, current controls and treatment plan. It lets the board see the current risk picture at a glance and track whether it is improving. Without one, risks drift, controls lapse and nobody knows the current posture. A simple spreadsheet is enough to start.

How often should IT risk be reviewed?

At least quarterly, or after any major change such as a new system, a new vendor, a breach or a significant staff change. Annual reviews are too slow for the pace of technology and threat change. The risk register should track trend over time so the board sees momentum, not static snapshots.

Does cyber insurance replace IT risk management?

No. Cyber insurance transfers some financial risk but does not replace controls. Insurers ask detailed questions about MFA, backups, EDR, admin controls and incident response before binding cover. Missing controls mean higher premiums, higher excess or denied claims. Insurance is one of three treatment options, alongside accepting and mitigating risk.

Get clear on your risk posture

We run IT risk assessments, produce board-ready risk registers and align controls to a defined maturity and tolerance level. You receive a scored report against Essential Eight, a prioritised treatment plan and a quarterly review cadence. Tell us your environment and we will scope the assessment.