Arctiq Main Blog

The Risk Was Accepted the Day Nobody Signed For It

Written by Eddie Skey | Oct 1, 2026, 1:12:25 PM

Key Takeaways

  • Silence is not risk acceptance. A known exposure without a documented decision and accountable owner remains unmanaged risk.
  • Risk acceptance should be explicit and documented. A real acceptance identifies who approved it, why other treatment options were rejected, when it will be reviewed, and where it should be escalated if conditions change.
  • Accepted risks require ongoing review. They should be visible in a shared register and revisited as conditions, dependencies, and business impact change.
  • Higher-impact risks require stronger governance. Risks involving regulated data, critical systems, or material business impact should be escalated according to defined thresholds and may require committee sign-off.
  • A risk that was never formally accepted was never actually decided. Allowing an exposure to persist by default does not close the decision-making loop.


The first piece in this series
argued that green dashboards hide residual risk. The second argued that a closed ticket is not proof anything was actually fixed. Both pieces kept circling the same unfinished question: who decided to leave this exposed, and where is that decision written down? This piece is about that decision, the one stage of the process almost no program does on purpose.

Every exposure that does not get remediated, compensated, or retired ends up in the same place: accepted. That is not a failure state. It is a legitimate outcome. Not every finding is worth the cost of fixing it. But acceptance is supposed to be a decision, made by someone, on the record, with a reason and an expiration date. Most of the time it is not a decision at all. It is silence that gets treated like one.

Three treatment options are safe to write down. The fourth one has your name on it.

Four options. One nobody chooses on purpose

Remediate, compensate, accept, retire: the four treatment options from the first blog look like a level playing field. They are not.

  • Remediate looks like progress. The ticket shows work done.
  • Compensate looks like diligence. A control went in, even if it is not a full fix.
  • Retire looks final. The asset is gone, so is the argument about it.
  • Accept looks like exposure with a name attached to it.

The first three all produce a record that reads well in a review. The fourth produces a sentence that says, in effect, we know about this, and we are choosing not to fix it. Almost nobody wants to be the name on that sentence. So instead of writing it, most programs just never get there. The finding does not get accepted. It gets forgotten, deprioritized, or left in a queue long enough that nobody remembers it was ever a live decision.

Silence is not the same as acceptance

Ask a security team whether a given risk was accepted, and a common answer is some version of: everybody knows about it. That is not acceptance. That is an open secret with no owner.

A real risk acceptance has four parts a rumor does not: a named individual who signed it, a written reason the other three options were rejected, a date it gets reviewed again, and a person to escalate to if the assumptions behind it change. Strip any of those out and what is left is not a decision. It is just an exposure nobody got around to closing, dressed up in the language of a choice that was never actually made.

This is exactly the gap the first two blogs kept running into. The one percent that never gets closed, the fix that never gets verified: in both cases, somebody down the chain almost certainly knew. Knowing is not the same as deciding. A known gap with no signature is not a managed risk. It is an unmanaged one that everyone has simply gotten used to.

The first piece asked for a named owner on every ranked residual exposure. This is where that requirement actually gets tested, not when the exposure is found, but when someone has to put their name on the decision to leave it.

What that costs in practice

Target's 2013 breach is often told as a story about a missed alert. It is more accurately a story about a decision that never got made. Target had installed a malware detection system months before the attack, and its monitoring team in Bangalore saw the alerts, flagged as the system's most urgent classification, and passed them to the security operations center in Minneapolis. The alerts went without a response. The system also had a feature that could have automatically deleted the malware; that feature had been switched off.

None of that reflects one formal decision to accept the risk of leaving the alerts unactioned. Nobody signed anything saying the automatic-removal feature would stay disabled, or that alerts of that severity would not get an immediate response. What existed instead was a set of informal defaults that nobody owned and nobody reviewed, and those defaults functioned exactly like an accepted risk without ever being one. The cost of that gap turned out to be roughly forty million payment card numbers and a breach that remains one of the most studied retail intrusions on record.

A default nobody reviewed is not a decision. It is a risk accepted by accident.

The Office of Personnel Management's 2015 breach shows the same pattern over a much longer timeline. Starting in 2007, OPM's own Inspector General repeatedly identified serious weaknesses in the agency's information security governance, rating it a “material weakness” through 2013 before downgrading it to a “significant deficiency” in 2014. A congressional investigation later concluded the breach was preventable, and that OPM leadership had failed to act on the Inspector General's repeated findings. Nobody at OPM ever formally accepted the risk the audits kept describing. It was simply restated, on schedule, by an outside auditor, for the better part of a decade, without ever turning into a decision anyone owned.

Target's gap was a single alert nobody acted on in the moment. OPM's was the same underlying concern, raised repeatedly over eight years, with the same result: no signature, no rationale, no expiration date, just an exposure everyone with access to the audit already knew about.

Where this leaves the loop

This blog series has borrowed Boyd's OODA loop twice now to describe where programs stall. The first piece pointed at leadership watching a dashboard instead of the fight. The second showed the loop breaking at Act, when nobody observes whether a remediation actually worked. This is the same loop breaking one stage earlier. A risk that never gets formally accepted never reaches Decide at all. It sits between Orient and Decide indefinitely, informally understood but never actually resolved, which means the loop cannot close, because it was never allowed to complete a cycle in the first place.

This is also exactly where Audit, Risk, and Compliance should already be looking. Formal risk acceptance is not a new requirement this piece is inventing. Established risk management frameworks already address formal risk acceptance. ISO 27001, for example, requires risk owners to approve the risk treatment plan and accept the residual information security risks. The gap is not a missing framework. It is a framework everyone already has, being satisfied with a blank field instead of an honest answer.

What a real acceptance requires

  1. A named individual signs it. Not a team, not a department, not “security leadership.” One person whose
    name is on the decision.

  2. A written reason. Why this option, and not remediate, compensate, or retire. If there is no good answer, that is usually a sign the decision has not actually been made.

  3. A review date. Acceptance is not permanent. It is a decision that was correct given what was known and true at the time, and it needs to be checked against what is known and true now.

  4. An escalation path. If the assumptions behind the acceptance change (new exploit activity, a new dependency, a change in exposure), someone specific needs to hear about it, not everyone in general.

None of this requires new process infrastructure. Most GRC and risk platforms already have a field for this. What they do not have is a culture that insists the field gets filled in honestly instead of left blank.

That is what one acceptance record needs. Here is what it takes to make sure acceptances actually happen instead of quietly not.

1. Give accept a standing line item in every review. Most residual exposure reviews track open findings and closure counts. Add one more line: how many exposures were formally accepted this cycle, and how many are still sitting with no decision at all. An empty line becomes something someone has to explain.

2. Put every acceptance on a shared register, not in someone's ticket. An acceptance that lives in one person's queue is invisible to everyone else. A shared register makes every decision visible to whoever has to review it next.

3. Put the review date on the calendar, not just in the record. A review date means nothing if nobody is tracking it. This belongs on the same standing agenda as the Residual Exposure Review from the first piece: an Acceptance Review, where expired decisions get re-decided, not silently rolled forward.

4. Escalate anything above a set threshold to a named committee, not a named individual. Low-impact acceptances can sit with one owner. Anything touching regulated data, crown-jewel systems, or material business impact should require sign-off from a body, not one person quietly deciding alone.

"Now the general who wins a battle makes many calculations in his temple ere the battle is fought. The general who loses a battle makes but few calculations beforehand. Thus do many calculations lead to victory, and few calculations to defeat: how much more no calculation at all!" — Sun Tzu, The Art of War

Sun Tzu was not just ranking good plans above bad ones. He was ranking any plan above none. A risk that gets formally accepted, even for the wrong reasons, is still a calculation someone made and can be checked. A risk that gets silently absorbed because nobody wanted to sign for it is the condition Sun Tzu ranked as the worst of all three: no calculation at all.

The dashboard was green. The ticket was closed. The risk was never signed for. None of those close the loop.

A risk nobody signed for was never accepted. It was just never decided.

If your program can't produce a named owner, a written reason, and a review date for every accepted risk, Arctiq's Cybersecurity Advisory Services can help you build a real acceptance process instead of an informal one. Connect with us to get started.