top of page

Chapter 3: Why Boards Struggle to See Cyber Risk and Its Effects Clearly.

Writer: Abena Kyei
Abena Kyei
May 31
4 min read

There have been ongoing discussions around how to make cybersecurity and information security risk more visible at board and executive leadership level.


How do we get boards to genuinely appreciate cyber risk beyond technical discussions?


How do we move cybersecurity away from being seen merely as:


  • an IT support issue,

  • a compliance exercise,

  • or simply “implementing a framework” because management requested it?



These are important conversations.


Over the next few weeks, my consulting practice will be exploring practical ways organisations, particularly financial institutions, can begin addressing this issue through enterprise risk management and risk governance structures already existing within organisations.


One thing I have increasingly come to realise through operational risk exposure is this:


The discussion should not begin from:


“How do we make the board understand cybersecurity?”


The discussion should begin much higher.


It should begin from:


  • enterprise risk appetite (the amount of risk an organisation is willing to accept or tolerate in pursuit of its objectives; determined and decided by the board of an organisation.)

  • enterprise risk governance,

  • risk capital,

  • and variance analysis.


A lot of people hear “risk appetite” in theory, but when you work closely with enterprise and operational risk structures, especially within banking environments, you begin to see what it actually looks like practically.


Risk appetite becomes measurable.


Risk exposure becomes measurable.


Loss tolerance becomes measurable.


Variance becomes measurable.


In many financial institutions, actual losses are compared against approved thresholds through variance analysis.


A simple way to think about it is:


Actual Losses ≤ Approved Risk Appetite Threshold = Within Appetite


Actual Losses > Approved Risk Appetite Threshold = Breach


Risk appetite becomes much more practical when actual losses are continuously monitored against board-approved thresholds through variance analysis.
Risk appetite becomes much more practical when actual losses are continuously monitored against board-approved thresholds through variance analysis.

This allows the board to compare the level of exposure it was prepared to tolerate against the actual exposure realised by the institution.


That is where governance becomes practical.


Another important point about risk appetite, risk capital, and variance analysis is that these are not merely end-of-year exercises.


In many financial institutions, monitoring is continuous.


Actual losses are monitored consistently against approved thresholds using cumulative year-to-date figures.


This means organisations are not waiting until year-end to determine whether risk appetite has been breached.


The monitoring process is ongoing.


As revenue accumulates year-to-date, actual losses are continuously compared against approved appetite thresholds tied to that revenue exposure.

This is why many variance analysis dashboards contain metrics such as:


  • cumulative year-to-date revenue,

  • cumulative year-to-date actual losses,

  • approved appetite thresholds,

  • and variance status.


In practice, some institutions update these monitoring dashboards:


  • weekly,

  • bi-weekly,

  • or at other regular intervals depending on governance requirements.


This makes risk governance dynamic rather than purely retrospective.


The institution is continuously checking:


Are actual losses still within the level of exposure the board previously agreed it was willing to tolerate?


That continuous monitoring process is what makes enterprise risk governance practical.


And this is also why cyber attribution becomes important.


If cyber and information security-related events are contributing significantly to cumulative operational losses throughout the year, organisations should be able to see that concentration clearly while monitoring risk appetite consumption in real time.


This is where the cyber governance discussion becomes extremely important. Because when cyber and information security incidents crystalise, they eventually translate into:


  • financial losses,

  • fraud losses,

  • systems disruption,

  • process failures,

  • customer impact,

  • operational disruption,

  • or regulatory exposure.


In many financial institutions, these losses are already captured within enterprise risk reporting structures and operational loss reporting mechanisms.


So, it is not necessarily that cyber risk is completely absent from enterprise governance structures.


The issue is often the way it is captured.


Once cyber-related losses are absorbed into broader enterprise loss reporting or operational loss reporting, the cyber causation behind those losses may no longer remain sufficiently visible at board level.


So, the board may see:


  • external fraud losses,

  • process management losses,

  • systems disruption,

  • or enterprise losses generally,


without clearly seeing how much of those losses are actually being driven by cyber and information security risk.


That is where I believe an important governance improvement can be made.


After total losses are reported and variance analysis is performed, organisations should also begin calculating how much of those losses can be attributed specifically to cyber and information security risk.


For example:


Cyber-Attributed Operational Loss Ratio = Cyber-Attributed Operational Losses / Total Operational Losses × 100%


Let’s say:


  • Cyber-Attributed Operational Losses = GHS 1,210,000

  • Total Operational Losses = GHS 3,420,000


Then:


GHS 1,210,000 / GHS 3,420,000 × 100% = 35.4%


Meaning:


35.4% of total operational losses were attributed to cyber and information security-related events.


This indicates that over one-third of the institution’s operational losses year-to-date were linked to cyber-related risk drivers, highlighting the growing operational and financial impact of technology and information security events within the organisation.


Cyber risk becomes much more visible at board level when organisations begin measuring how much operational loss exposure is actually being driven by cyber and information security-related events.
Cyber risk becomes much more visible at board level when organisations begin measuring how much operational loss exposure is actually being driven by cyber and information security-related events.

This allows boards and executive leadership to begin seeing cyber risk in financial and enterprise governance terms.


Not just as:


  • vulnerabilities,

  • attacks,

  • or technical incidents,


but as measurable enterprise exposure affecting risk appetite, loss tolerance, and organisational resilience.


Importantly, this does not necessarily mean organisations must completely abandon existing governance structures such as Basel operational risk classifications or existing variance analysis frameworks already being used within banking environments.


Those structures are already deeply embedded and tested over time.


The issue is not necessarily structural replacement.


The issue is visibility.


Cyber and information security risk need to become more visible within enterprise loss reporting and variance analysis structures already existing inside organisations.


That visibility is what can help elevate cyber governance discussions properly at board level.


This topic is explored further in our ongoing chapter series on our website:




This topic forms part of our broader work around:


  • enterprise risk management,

  • operational risk management,

  • governance, risk and compliance,

  • internal controls and assessments,

  • policy development,

  • capacity building and training,

  • and technology risk and governance.


Over the coming days and weeks, we will continue publishing more detailed discussions and practical governance insights on this topic through our ongoing chapter series on our website.

The next areas we will be exploring include:


  • how operational risk categories and risk areas are derived,

  • the historical and regulatory foundations behind these classifications,

  • how operational loss events are aggregated into defined risk categories,

  • and how these structures evolved within enterprise and banking risk governance frameworks.


For more detailed insights and updates, organisations and professionals may continue following our publications through our consulting practice website:


Oye Risk Consulting:


 
 
 

Comments


bottom of page