The cyber risk register is a static document disconnected from live telemetry, so risks aren't linked to the assets, services and controls they concern. Governance describes a world that no longer matches the estate.
"Is our risk register actually linked to live assets, services and controls, or a document that's already stale?"
Live risk register
Stale risk entries
To first outcomes