IT risk is a business decision, not an IT decision
The question is not whether IT wants more security, it is how much risk the business accepts. A board that owns that decision invests properly, avoids blame games and aligns spend to outcomes. A board that does not ends up surprised, under-insured and reactive.
Risk tolerance is a statement, not a feeling. It says what the business will and will not accept in financial, reputational and regulatory terms. IT maps the threats and controls, presents residual risk at different investment levels, and the business accepts the remainder in writing.
Who decides risk tolerance
The board or owner decides risk tolerance. Not the IT manager, not the MSP. IT presents the options, costs and consequences. The business owners accept the residual risk. This is the single most important governance principle in IT security.
IT maps threats and controls
IT identifies the threats, the current controls and the gaps. This is the technical assessment, not the business decision.
IT presents residual risk
IT presents residual risk at different investment levels: what changes if we spend X, what changes if we spend Y. Options, not opinions.
Board accepts residual risk
The board or owner accepts the residual risk in writing. In minutes, not verbally. This is the business decision.
Review quarterly
The risk register is reviewed quarterly or after a major change. Technology and threats change fast; an annual review is not enough.
Framing IT risk for the board
The board needs dollars, not jargon. Tell them what a ransomware recovery costs and how likely it is, then present three options: accept, mitigate or transfer to insurance. Each with a price.
Use dollars, not jargon
Tell the board ransomware recovery is estimated at $2 to 6 million over 60 days, not that you lack immutable backups. Money is the language the board speaks.
Quantify likelihood
Use Annualised Loss Expectancy: likely frequency multiplied by cost per event. Even a rough estimate beats a feeling.
Present three options
Accept the risk, mitigate it with controls, or transfer it to insurance. Each option has a cost and a residual risk level.
Map to existing tolerance
The board already accepts financial, reputational and regulatory risk in other areas. Map IT risk to the same scale so it is comparable.
Track the risk score over time. A board that sees the trend, not just the snapshot, understands whether things are getting better or worse. Momentum matters more than any single number.
Essential Eight maturity and risk
Essential Eight Maturity Level is the simplest anchor for Australian SMBs. It gives the board a grade that insurers, regulators and major customers understand. Each level represents a defined set of controls and a corresponding risk posture.
ML0: not acceptable
No deliberate mitigation. Unacceptable for any commercial business handling customer data or operating online.
ML1: minimum insurable
Minimum for insurability and most customer contracts. Most insurers will not bind cover below ML1.
ML2: SMB target
Target for most SMBs. Insurance premium benefit and strong protection against common attacks.
ML3: regulated sectors
Required for regulated industry, defence, government and critical infrastructure. The highest practical level for most.
Moving from ML1 to ML2 typically reduces cyber insurance premiums by 15 to 30 per cent, depending on the insurer and sector. The saving often covers the cost of the uplift.
Insurance implications
Cyber insurance is no longer a blanket shield. Insurers ask detailed questions about MFA, backups, EDR, admin controls and incident response. Gaps mean higher premium, higher excess or denied claims. Your risk register is effectively your insurance application.
Insurers assess controls
MFA on every account, EDR on every endpoint, immutable backups, separate admin accounts and a tested IR plan are baseline expectations.
Gaps cost money
Missing controls mean higher premiums, higher excess or coverage exclusions. Some insurers will not quote at all below ML1.
Disclosure is ongoing
Material changes to your security posture must be disclosed to your insurer. A control that lapses after binding can void cover.
Quantifying risk in dollars
These are the cost ranges we use to frame IT risk for Australian boards. They are indicative, not precise, but they give the board a number to work with instead of a vague feeling.
| Risk scenario | Indicative cost | Key driver |
|---|---|---|
| Ransomware | $500k to $5M | Size, downtime, notification and reputation |
| Business email compromise | $50k to $1M+ | Invoice fraud is growing faster than ransomware |
| Data breach (Privacy Act) | Up to $50M | OAIC penalties for serious or repeated breaches |
| Operational disruption | Per hour of downtime | Revenue-generating systems down |
| Reputational damage | Hard to quantify | Customer churn, tender disqualification, press |
Indicative cost ranges for common IT risk scenarios in Australia
- Risk scenario
- Ransomware
- Indicative cost
- $500k to $5M
- Key driver
- Size, downtime, notification and reputation
- Risk scenario
- Business email compromise
- Indicative cost
- $50k to $1M+
- Key driver
- Invoice fraud is growing faster than ransomware
- Risk scenario
- Data breach (Privacy Act)
- Indicative cost
- Up to $50M
- Key driver
- OAIC penalties for serious or repeated breaches
- Risk scenario
- Operational disruption
- Indicative cost
- Per hour of downtime
- Key driver
- Revenue-generating systems down
- Risk scenario
- Reputational damage
- Indicative cost
- Hard to quantify
- Key driver
- Customer churn, tender disqualification, press
These ranges are indicative. The actual cost depends on the size of the business, the sector, the data involved and the speed of response. Use them to start the board conversation, not to replace a proper assessment.
Common mistakes in IT risk management
These are the mistakes we see in every business that gets caught out. Each one turns a manageable risk into an expensive surprise.
Treating IT risk as an IT problem
Board ownership is required. Without it, investment follows noise instead of priority and no one accepts the residual.
No documented risk tolerance
Without a stated tolerance, every investment argument is a debate. Write it down, agree it and review it.
No risk register
Without a register, risks drift, controls lapse and nobody knows the current picture. A simple spreadsheet is enough to start.
Accepting risk verbally
Risk acceptance needs to be in writing, in minutes, audited. Verbal acceptance is not acceptance.
Reviewing annually only
Technology and threats change quarterly. Annual risk reviews are too slow for the pace of change.
How we run an IT risk assessment
We scope an IT risk assessment as a fixed-fee engagement. You receive a board-ready risk register, a scored posture against Essential Eight and a prioritised treatment plan with costs.
- Step 1
Assess current posture
We assess your environment against Essential Eight maturity levels. You receive a scored report with every gap identified.
- Step 2
Build the risk register
We build a board-ready risk register with likelihood, impact and treatment options. You review it with us before it goes to the board.
- Step 3
Agree tolerance and treatment
We facilitate a tolerance discussion with your board or owner. You agree what to accept, mitigate and transfer, in writing.
- Step 4
Review quarterly
We review the register quarterly and after major changes. You see the trend, not just the snapshot.
Common questions
Who should decide IT risk tolerance in a business?
The board or business owner decides IT risk tolerance, not the IT manager or MSP. IT maps the threats and controls, presents residual risk at different investment levels, and the business accepts the remaining risk in writing. Without board ownership, investment follows noise instead of priority.
What Essential Eight maturity level should my business target?
Essential Eight Maturity Level 1 is the minimum for insurability and most customer contracts. Level 2 is the target for most Australian SMBs and typically reduces cyber insurance premiums by 15 to 30 per cent. Level 3 is required for regulated sectors, defence, government and critical infrastructure.
How do you quantify IT risk for the board?
Use dollars, not jargon. Tell the board what a ransomware recovery costs and how likely it is, using Annualised Loss Expectancy: likely frequency multiplied by cost per event. Present three options: accept the risk, mitigate it with controls or transfer it to insurance. Each option has a cost and a residual risk level.
What is a risk register and why do I need one?
A risk register is a documented list of identified risks, their likelihood, impact, current controls and treatment plan. It lets the board see the current risk picture at a glance and track whether it is improving. Without one, risks drift, controls lapse and nobody knows the current posture. A simple spreadsheet is enough to start.
How often should IT risk be reviewed?
At least quarterly, or after any major change such as a new system, a new vendor, a breach or a significant staff change. Annual reviews are too slow for the pace of technology and threat change. The risk register should track trend over time so the board sees momentum, not static snapshots.
Does cyber insurance replace IT risk management?
No. Cyber insurance transfers some financial risk but does not replace controls. Insurers ask detailed questions about MFA, backups, EDR, admin controls and incident response before binding cover. Missing controls mean higher premiums, higher excess or denied claims. Insurance is one of three treatment options, alongside accepting and mitigating risk.
Get clear on your risk posture
We run IT risk assessments, produce board-ready risk registers and align controls to a defined maturity and tolerance level. You receive a scored report against Essential Eight, a prioritised treatment plan and a quarterly review cadence. Tell us your environment and we will scope the assessment.

Remote Support