Business risk decisions
A deferred fix needs a fresh reason
A cyber risk review checks whether an earlier decision to accept or defer a security issue still makes sense. Start with the reason for that decision, compare it with current evidence, and record what the business will do next. A risk marked low last year should not stay low simply because nobody reopened the conversation.
For a Sydney business owner, this can be a familiar budget discussion. An application upgrade was postponed until a quieter period. A supplier kept remote access because a project was still running. The decision had a reason at the time. The question is whether that reason still holds.
This guide turns that question into a practical discussion with your IT support team. It covers existing risk decisions, the evidence worth requesting and the point at which management needs to approve action. The downloadable checklist gives you a record to keep after the meeting.
Reasons to reopen a decision
Look for changes in the conditions you relied on
A calendar reminder is useful, but some events need an earlier review. Check the specific assumption affected by each change.
The system is more exposed
A remote connection, new integration or changed firewall rule can create a route that did not exist when the risk was accepted. Ask IT to show the current connections and who can use them. The original network diagram may no longer describe the system.
The protection has changed
A vendor may have ended support, a patch may have failed, or a security tool may no longer cover the device. Check the actual version and control status. Ownership also matters when a supplier or employee who maintained the protection has left.
The business depends on it more
An application once used by one team may now support billing across the company. More sensitive information or a shorter recovery window can increase the consequence of failure. A technically unchanged system can carry a different business risk.
The threat information has changed
A supplier advisory, credible exploitation report or new attack capability can change remediation priority. Ask which finding applies to your environment. A general headline should prompt investigation, rather than an automatic purchase or a blanket change to every rating.
The current guidance
AI makes old assumptions worth testing
ASD's Frontier AI cyber threat considerations for boards of directors, developed with the AICD and published on 5 August 2026, asks leaders to examine the assumptions behind their risk assessments. It specifically questions delays based on perceived low exposure or severity.
The guidance warns that frontier AI can combine lower-severity weaknesses into high-impact compromises. That is a reason to examine attack paths and business consequences together. A technical severity score describes characteristics of a vulnerability. It does not, by itself, determine the risk to your business or prove that a decision to defer remediation remains sound.
There are limits to the evidence. ASD's April update, revised in May, explains that some AI attack demonstrations used simulated environments without active defenders. Demonstrated capability and forecasts of wider use are different from proof that every real attack has become faster. Properly implemented controls still matter.
Our guide to outdated IT equipment and AI cyber attacks covers equipment replacement. This article addresses the management decision behind a deferral, including risks involving supported software, supplier access and recovery arrangements.
Evidence before approval
Ask IT for a small decision pack
A long scan report can hide the decision you need to make. Request a short summary linked to the underlying records. Keep sensitive technical detail in an access-controlled location.
Original decision
Record the affected system, finding, date and approving person. Keep the original reason for acceptance and any conditions attached to it. If the business cannot find that record, mark the rationale as unknown and arrange a fresh assessment.
Current position
Request dated evidence of exposure, patch status and access permissions. Check whether protective controls are operating. State what was tested and what was outside scope. An untested assumption should remain visible as an uncertainty.
Business impact
Identify the work that would stop, the information at risk and the recovery requirements. Ask for the latest relevant restore or continuity test. A successful backup job alone does not show that staff can resume the business process.
Options and recommendation
Ask IT to compare remediation with temporary controls and continued acceptance. Each option needs an owner, cost or estimate basis, operational impact and remaining risk. Separate urgent containment from a longer replacement project.
Illustrative example
The supplier access that outlasted the project
Consider a hypothetical accounting firm. It allowed a software supplier remote access during an application migration. Management accepted the temporary arrangement because access was restricted to a named technician and was due to end when the migration finished.
The migration is complete. During a review, the firm discovers that the supplier account remains enabled and its permissions cover a newer shared folder. The original approval has not changed, but the conditions behind it have. This is a fictional teaching example, not a Milnsbridge client case study.
An incomplete response
Changing the register entry from low to medium leaves the access in place. The record still needs a decision about who requires access, which permissions are justified and when the exception ends.
A decision with follow-through
Confirm whether the supplier still needs access. If it does not, arrange approved removal and verify it. If access is required, agree a narrower arrangement, test the restrictions and document the remaining risk with a named approver and review date.
For network access, Managed FortiGate supports firewall configuration and documented change control. Application and identity permissions still need their own checks. A firewall cannot decide whether the supplier has a continuing business reason to access a folder.
Leave with a decision
Give each open risk an accountable next step
These are practical meeting outcomes, not risk scores. ASD's board guidance calls for timely remediation or mitigation, verified effectiveness and regular assurance.
Remediate
Remove the weakness or unnecessary exposure. Name the delivery owner, agree timing and record the test that will confirm the work succeeded.
Use temporary controls
If a permanent fix needs time, document the interim protection and its limits. Set an expiry or review date and keep the permanent action visible.
Accept the remaining risk
An authorised business decision-maker records why the residual risk is tolerable. Include the evidence, conditions and review trigger. IT advice informs the decision.
Escalate for a decision
Where evidence is missing or risk exceeds delegated authority, name the person who must decide and a deadline. Agree any immediate protective action with IT.
One-page working resource
Use the cyber risk review checklist
Download the one-page cyber risk review checklist PDF. Print one sheet for each accepted or deferred risk. It records the original rationale, changed conditions, evidence, decision, accountable people and next review date.
Work through it with the business owner of the affected process and the IT contact who can explain the evidence. Reference detailed reports instead of copying passwords, personal information or sensitive configurations onto the sheet. Store the completed record with your existing risk and change records.
Before closing an action, keep evidence that the agreed change worked. Reopen the record when a stated trigger occurs. Set review frequency to suit the risk and your obligations rather than treating an annual meeting as sufficient for every system. Suspected compromise needs incident response immediately, not a place on the next review agenda.
Common questions
Questions about reviewing accepted risks
Keep technical assessment and business approval connected. They answer different parts of the same decision.
Does a low severity finding always mean low business risk?
No. Technical severity is one input. Exposure, sensitive data, business dependence and the possibility of combining weaknesses can change the business impact and remediation priority.
Who should approve continued acceptance?
The person with authority to accept that business risk should approve it, using current technical advice. Record the approver and any conditions. Escalate decisions beyond delegated authority.
Can we accept a risk instead of meeting an obligation?
An internal risk acceptance does not remove legal, regulatory or contractual duties. Check the applicable obligation and obtain specialist advice where needed before relying on acceptance.
How often should an accepted risk be reviewed?
Set a review date based on the risk and applicable obligations, plus earlier triggers such as changed access, vendor support, exposure or threat information. Verify completed actions rather than waiting for the next scheduled review.
Source and context
Read the guidance behind the review
The primary sources are ASD and AICD's board guidance and ASD's frontier AI update, linked above. Kim Stewart-Smith's discussion of accepted risk and changing assumptions prompted this article. The checklist and illustrative example are Milnsbridge's practical interpretation, not official ASD or AICD templates.
Explore more
Support the decision with the right technical work
Choose the assessment or operational service that matches the finding. Confirm scope before commissioning the work.
Security assessment
Establish control evidence and a prioritised roadmap through our Essential Eight Assessment.
Day-to-day IT support
Connect maintenance and recurring issues with business decisions through Sydney IT support.
Managed firewall changes
Review configuration, firmware and network access with Managed FortiGate.
Financial services IT
Understand the support context for advisers and accounting teams through financial services IT support.
Discuss your next review
Turn an old exception into a current decision
Milnsbridge can help Sydney businesses connect technical findings with practical next steps. Our Essential Eight Assessment provides a baseline, evidence and a prioritised roadmap. Confirm the assessment scope and current framework guidance for your environment.
Our Sydney CBD and Penrith team publishes a 20-second average answer time for business-hours phone calls and 87% first-call resolution. See the measurement definitions.
Talk to a SpecialistAbout the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
