Cyber Risk Compendium

Senior management / Board of Directors

Senior management and the Board of Directors set the organisation's risk appetite, allocate the budget for Controls, and are ultimately accountable for how well Risks to the organisation's Assets are managed.

In practice, senior management typically delegates the day-to-day Risk owner role to line managers or the CISO / Information Security Officer, but retains final sign-off on high-impact risks and major s. Regulated organisations (banks, critical infrastructure operators) often have explicit regulatory requirements for board-level oversight of cyber risk, e.g. under FINMA circulars or NIS2/CER-derived obligations.