So how does one express risk appetite? A lazy way may be to relate it to the results of risk assessments. For example, one could express risk appetite as a simplistic statement saying that the organization is comfortable living with risk rated medium or low, but not with risk rated high or critical. The trouble with this approach is that it lacks clarity and specificity, and, therefore, it is open to challenges by business managers and technologists alike. It is not specific because it focuses on a rating that is one level removed from the risk itself and, as an abstraction of the seriousness of the underlying issue, represents the technology risk manager’s perspective, which may not be shared by others.