Come Clean
Why no one will disclose their risk appetite
I used to think one of the Board's common cybersecurity questions was a bad one: "How do we compare to our peers?" I was firmly of the view that this ask was wrong-headed and ill-advised. Look to your own program. Understand your own risk exposure, and get it down below your own risk appetite. The cybersecurity version of "clean up your own backyard." What the shop down the road is doing tells you very little about whether your own house is in order, and chasing a peer number is a fine way to end up buying tools to move a percentile instead of reducing a loss.
I'm coming around to the other point of view.
There is a pragmatic utility in the Board asking this, and it took me longer than it should have to see it clearly. Knowing how your peers are doing is what lets you say, straight-faced, to your regulator, your shareholders (if you have those), and whatever other stakeholders come knocking after a bad day, that you were being reasonable. That you were doing enough. And, just as important in a world of finite budgets, that you weren't getting carried away with security spending either. The question isn't really about trying to do the bare minimum, it's about defensibility.
Once you see that, the question stops looking naive and starts looking like one of the more sensible things a fiduciary could ask. But when you go looking for the data to answer it, you discover that it does not exist, will not be supplied, and, if the history of every other high-consequence industry is any guide, is likely never going to be.
Reasonable compared to what?
When a regulator, a plaintiff's lawyer, or a shareholder with a grievance sits down to judge what you did, the test they apply is comparative by construction. What would a competent organization in your position, facing your threats, with your resources, have done? Not what would a perfect one have done, and pointedly not what did you decide was fine. Your own risk appetite is something you set yourself. "We were operating below our stated appetite" is not self-justifying on its own, because you drew the line and could have drawn it anywhere convenient. Mature programs anchor appetite to materiality thresholds and board oversight; unmoored from any external reference, it proves nothing. Regulators are contributing to the risk materiality discussion, but it's still largely up to the organization. The defensibility question is really a materiality question, which is where agency-theory governance actually fits.
So what does "reasonable" look like? Whether your decisions looked like the decisions a reasonable peer would have made. It is a bit circular, but the law lives with that circularity on purpose: reasonableness is defined by conduct, not by a fixed number, which is exactly why it needs a comparison set to mean anything. And it is well established far beyond security. The same idea, comparison to competent conduct, runs through several legal standards: negligence's reasonable-person test, the professional standard of care in medicine and engineering, and the prudent-person rule in fiduciary law. Did you patch on a cadence the rest of the field would recognize as sane? Did you carry insurance a firm your size would be expected to carry? Was your spend in the range that a company with your revenue and size spends, or were you the outlier who decided endpoint detection was optional? Every one of those questions is peer-relative. You cannot answer any of them by looking only at yourself.
The Board's instinct to externalize the benchmark seems to be the correct one. They are not asking a vanity question of "do we look OK?" They are asking the question that the outside world is going to ask them, but in advance, so they can prepare an honest answer. That is exactly what governance is supposed to do. I was perhaps too hasty to wave it off.
What would actually answer the question
To tell the Board you are reasonable relative to your peers, you need to know one specific thing about those peers: the line they drew. Their acceptable-risk decision. How much loss exposure they looked at and consciously chose to live with, and where they sit against that self-set line today.
Not their losses. Not their breach costs. Not how their attack surface looks from the outside. Those are outcomes and symptoms. The thing you need is the decision itself: "we examined a one-in-twenty chance of a fifty-million-dollar year and decided that was tolerable given our balance sheet." That is the datum that would let you say "and we made the same call, so we were in line with the field."
I've looked, and that data does not appear to be collected anywhere. At least I can't find it, if you can please let me know. But from what I can tell nobody publishes it. And once you understand why, you stop expecting them to.
What we reach for instead
We are not short of numbers that seem to answer the Board's ask. But look at what actually gets sold and cited as benchmarking.
External posture scores, BitSight, SecurityScorecard, Black Kite, Panorays, rank you against a cohort on what your perimeter looks like from the internet. Exposed services, certificate hygiene, patching latency on public-facing systems, leaked credentials. This is genuinely useful, but not quite what the Board is asking. A percentile on external hygiene tells you how tidy your front lawn is compared to the neighbours. It says nothing about how much risk you decided to accept. Two firms with identical BitSight scores can have very different appetites and internal control suites, and the score cannot tell them apart.
Maturity-band comparisons, the CMMI-style "you're a Level 3, the median in your sector is a Level 3.4," measure process, not appetite. Maturity is a proxy for how repeatable your practices are. A very mature program can still knowingly run loose on risk, and a scrappy one can be deeply conservative. Maturity and risk are different axes, and treating a maturity percentile as a reasonableness proof quietly conflates them. I made that case at length in The Maturity Mirage.
Compensation and program-shape studies, the IANS and Artico Search work, are the closest thing we have to an appetite proxy. They tell you what a company your size, in your sector, typically spends and how it staffs. If your budget as a fraction of revenue is in the normal band, you have a real, if crude, argument that your investment is reasonable. That's a spend-reasonableness signal. It is still not a risk-reasonableness signal, because two firms spending the same can be buying down very different amounts of risk.
Cyber insurance is an interesting one, and I'll come back to it, because carriers hold appetite data implicitly. When you select a ten-million-dollar retention (the deductible-like layer you cover before the policy pays out) and a fifty-million limit, you have revealed something concrete about how much risk you're willing to hold before you want someone else to pay. The big brokers, Marsh, Aon, WTW, hold this data across their whole book. But it comes out as aggregate loss ratios, never as a peer-comparable appetite curve you could hand your Board.
The incident corpora, DBIR, M-Trends, the Cyentia IRIS loss data, is the richest thing we have and still not quite what we are looking for here. They tell you, in exquisite detail, what happened. Frequencies, loss magnitudes, dwell times. What they do not contain, anywhere, is a reflection of what any of those organizations had decided was acceptable beforehand, what controls they had in place, how mature their ISMS was.
Line them all up and the pattern is: everything we collect pools what happened: losses, incidents, exposed surface, spend. Nothing pools what was decided. The acceptable-risk line is the one figure organizations almost never disclose beyond their own walls.
Cyber risk quantification already conceded this
Wade Baker, one of the Cyentia founders and a man who has spent his career applying data to security decisions, made an argument recently about using data versus human estimates in cyber risk models. Strip it down and it says something quietly radical. A base rate derived from real data has already absorbed the peer cohort's typical control performance. The FAIR notion of "Vulnerability," how likely a threat event is to become a loss given your controls, is baked into that base rate, because the number came from a population that already had controls. So when you go to adjust for your own controls, in this data-derived approach the only honest move left is a relative one: if your controls are better than the cohort's, adjust the likelihood down; if they're worse, adjust it up. His worked example was a five-billion-dollar manufacturer sitting at roughly a twenty-one percent annual likelihood of the loss event in question, rising to about twenty-four percent once you account for its below-par controls.
Sit with that for a second. The base rate is the cohort's rate. This means you can't evaluate your controls in isolation, because the data won't allow it; it forces you to grade yourself against the peer distribution whether you find that comfortable or not. Rick Howard picked this up in his First Principles newsletter and recast it in Tetlock's language of the outside view and the inside view (that framing is Howard's, not Baker's), swapping in a healthcare example to make the point land for a different audience. The argument drew serious engagement from the risk-quant community, and its core claim, that a data-derived base rate already embeds the cohort's control performance, is hard to dispute on its own terms.
Which is the Board's instinct, even if they can't quite articulate it that way. When a director asks how you compare to your peers, they are reaching for something close to what Baker's argument formalises. I spent years telling people to ignore the neighbours and mind their own exposure, and the best risk modellers in the field make the case that your own exposure is only meaningful relative to the neighbours.
But the base rate is built from loss and event data, not from pooled appetite decisions. So even the state of the art gives you a peer-relative frequency, an outside view on how often the bad thing happens to firms like you. It does not give you a peer-relative appetite, an outside view on how much of that firms like you have decided to tolerate. The quants have solved the easier half, because it was solvable. But the half the Board seems to care about, "were we reasonable in what we chose to accept," still has no data behind it.
Has anyone escaped this trap?
Cybersecurity likes to think its problems are new. They rarely are. I went looking for an industry that had cracked the peer-appetite problem, on the theory that we could learn from them. What I found instead was a very consistent story, and it is not the story I expected.
Aviation built the Aviation Safety Reporting System in the 1970s, run by NASA rather than the regulator, precisely so that pilots and controllers would file reports about near-misses and mistakes. What made it work was legal immunity: file a report through ASRS and, within limits set out in the regulations, the FAA can't use it to prosecute you. That immunity is why people tell the truth. Aviation layered on ASAP, FOQA and the ASIAS data-sharing effort run through MITRE. Enormous, mature, genuinely world-changing. And every bit of it pools events: reports, flight-data anomalies, incidents. The question of how safe is safe enough, the target level of safety, is set by the regulator through ICAO, not negotiated among airlines.
Nuclear power. After Three Mile Island in 1979 the US operators formed INPO; after Chernobyl the world's operators formed WANO in 1989. Both are built on shared fate: one plant's accident is the whole industry's problem, in public trust and in regulatory backlash, so they pool operating experience and run confidential peer reviews of each other. It is a good example of self-organised safety culture. And still what gets pooled is operating experience and events. The acceptable-risk line, the NRC's safety goals of a core-damage frequency below one in ten thousand per year, a large early release below one in a hundred thousand per year, individual risk held to a tenth of a percent of background, was set by the regulator, from the top, and handed down.
Banking pools operational-loss events through the ORX consortium, an anonymising intermediary that exists because Basel II made banks hold capital against operational risk. Losses above a reporting floor (on the order of twenty thousand euros) go into the pool. But how much capital you must hold against that risk, the actual line, is Basel's, set through the regulatory framework, not agreed between banks individually.
Patient safety in the US runs on Patient Safety Organizations, created by the 2005 Patient Safety and Quality Improvement Act, whose entire enabling mechanism is a federal privilege that survives disclosure, so hospitals can report adverse events without having to worry so much about legal action. Insurance is even more blunt: carriers are allowed to pool loss data with each other only because the McCarran-Ferguson Act carved them a specific antitrust exemption back in 1945. Credit bureaus pool repayment events under the reciprocity regime the Fair Credit Reporting Act set up in 1970. The chemical industry built its process-safety incident database and Responsible Care program after Bhopal in 1984.
Seven industries. Two features recur. First, sharing usually happens behind a legal shield, immunity, privilege, or an antitrust exemption. Where there is none (nuclear's INPO, the chemical industry's incident database), it runs instead on a shared-fate norm strong enough to make silence unaffordable. Second, what they share is always events: losses, incidents, near-misses, the things that happened. In not one case does the industry voluntarily pool its members' decisions about how much risk to accept. And in every case where a shared acceptable-risk line does exist, a regulator handed it down from the top and everyone has to comply. The UK's Health and Safety Executive did exactly this with its Tolerability of Risk framework, fixing the boundaries of acceptable individual risk somewhere between one in a thousand and one in a million per year. Nobody voted on it. The regulator set it.
Why cyber won't be the exception
So cybersecurity wants the harder thing, a pool of the actual risk decisions, when in every high-consequence industry I could find, even the easier thing, a pool of events, needed a legal shield or a mandate to get off the ground. Cyber has neither.
We have no legal shield, and no shared-fate mechanism strong enough to stand in for one. There is no cyber equivalent of ASRS immunity or the PSO privilege or McCarran-Ferguson. Anything you write down about your risk decisions is discoverable, and in the current enforcement climate a candid record of what you chose to accept is not an asset, it's possibly a liability. Consider what you'd need to contribute to a peer-appetite pool: "In Q1 we assessed a one-in-twenty chance of a fifty-million-dollar loss and the committee accepted it." That is a very useful sentence for a plaintiff's lawyer. The exact motive that makes the Board want peer data, the desire to prove you were reasonable, is the reason almost no one will contribute theirs. The data you need to demonstrate you were reasonable is the data everyone else is most leery to reveal. The demand and the refusal come from the same rational instinct.
We also have no pooling intermediary with any teeth. An ORX for cyber risk appetite would need a legal basis to exist and a critical mass of firms willing to feed it the one number they most want to hide. Neither is on the horizon.
So what can we actually do?
I've come around on the question. I have not come around to pretending we can answer it with data we don't have.
Stop letting the substitutes launder into claims they can't support. If you put a BitSight percentile in the board deck, say out loud what it is: this ranks our external hygiene against a cohort, and it does not tell us whether the risk we've accepted is reasonable. The moment a posture score gets narrated as "we're in line with our peers on risk," you've told the Board something the number cannot back. This is rarely dishonesty. Most people leaning on these scores are doing the best they can with the data they have, and simply haven't clocked how wide the gap is between "our external hygiene ranks well" and "the risk we have chosen to accept is reasonable." Closing that gap starts with naming it out loud.
Use the revealed-appetite signal we actually have, which is insurance. Your own retention and limit selection, set against whatever benchmarks your broker will share, is the closest thing to peers putting real money behind their appetite. It's crude, it's mediated by underwriters, and the truly comparable book stays carrier-held, but it's the most honest proxy going, because someone is betting capital on it. Pair that with IANS and Artico spend and program data and you can at least tell the Board, defensibly, that your investment sits in the normal band for firms like yours. That's a real answer to half the question.
For the other half, demonstrate reasonableness of process directly, rather than trying to source it from peers who will never share. You can show a regulator that you quantified your exposure, that you compared it against the loss and frequency data that does exist, DBIR, IRIS, etc., that you made a deliberate, documented decision, and that you revisit it on a schedule. Reasonableness of process is defensible even when reasonableness-relative-to-peers is unknowable. That is the pragmatic substitution: give the Board and the regulator the thing peer comparison was always a proxy for, evidence of care, by a route that doesn't depend on data that isn't coming. And a steering committee that owns a written risk-appetite statement and materiality thresholds, the stewardship model I argued for here, at least makes the acceptable-risk line explicit.
Where this leaves us
Maybe cyber gets its cyber-Chernobyl moment eventually, after a shared-fate event bad enough that the whole field decides mutual survival beats mutual silence. If we genuinely want peer appetite data, the precedents tell us exactly what it would take: a legal shield that makes sharing safe, or a regulator willing to draw the line top-down the way the NRC did for nuclear reactors and the HSE did for tolerable risk. Left to voluntary action, it's unlikely to happen, for the same reasons it has never happened anywhere else. Waiting for the benchmark to arrive on its own is waiting for something the incentives strongly suggest will never come.
Until then, the Board will keep asking how we stack up against our peers, and they are right to ask. The honest answer is narrow. We can tell them how our attack surface looks from the outside, and roughly how much we spend compared to firms our size. We cannot tell them whether we drew the risk line in the right place, because the only people who know where they drew their own line have excellent reasons never to tell us. The question is reasonable. The silence that answers it is reasonable too.

Great article! Thanks!