RESILIENCE EXCEPTIONS & RISK ACCEPTANCES

Temporary resilience risk decisions are made under pressure and rarely revisited, so expired acceptances leave services exposed with no owner. The temporary becomes permanent.

Actors

  • Head of Cyber Resilience
  • Risk Owners
  • CISO

Systems / Vendors

  • GRC platform
  • CMDB / service mapping
  • Risk register

Business Question

"Which resilience risks did we accept temporarily that are now permanent and past their expiry?"

What SPoG Does

  • Tracks temporary resilience risk decisions and their expiry.
  • Flags expired acceptances that leave services exposed.
  • Keeps resilience risk time-bound and owned.

Outcome Metrics

−40%

Expired acceptances

1

Live acceptance register

6–10 wks

To first outcomes