PRACTITIONER-LED GOVERNANCE THINKING
Practical governance thinking for when the paperwork stops being enough.
Cyber, privacy, AI, suppliers and resilience rarely stay inside their own boxes. Acceptable Risk is a practitioner-led library about what happens when governance meets operational reality — the evidence, ownership, consequences and decisions that matter.
Because “documented” isn’t a mitigation strategy.
START HERE
Three pieces that explain the worldview.
The Risk Register Nobody Looks At
When a governance artefact exists but no longer shapes decisions.
Your Risk Appetite Doesn’t Matter When You Inherit Theirs
How dependencies turn somebody else’s control choices into your exposure.
Three AI Certifications, Three Governance Problems
Why assurance labels do not remove the need for ownership and judgement.
Explore by subject
Governance Without Theatre
Evidence, ownership, accountability and leadership decisions.
Data Privacy in Practice
Privacy as an operating discipline rather than a paperwork exercise.
AI Governance: Practitioner View
Inventory, oversight, evidence and accountability around real AI use.
Defence, Certification & Supply Chain
Assurance, dependencies, suppliers and demonstrable trust.
Latest thinking
DCC: Five Things I’ve Learnt as an Assessor
Five practical lessons from Defence Cyber Certification assessment preparation: scope, evidence, Cyber Essentials, proactive certification and independent assurance.
The Defence Supply Chain Risk Nobody Priced In
Every prospective defence supplier who calls me wants roughly the same thing: help understanding what the MOD actually requires, so they can get into the supply chain and start earning from it. Nobody opens the conversation asking what they’re taking on. They open it asking how to get in. One of them, a small manufacturer…
The Danzell Problem Nobody in the Supply Chain Has Fixed Yet
In July, I was running an assurance review with a defence supplier just as their annual SAQ renewal came up. Everything on their end was spotless. Cyber Essentials reissued under the new Danzell requirements? Done in June. Cloud-wide MFA, tighter patch windows, and social media brought into scope? All checked off. It was a textbook…
It Gets Cleaner On The Way Up
A project team gets to a go-live meeting. Sign-off is on the agenda. The supplier has already been told the enterprise controls aren’t sufficient. But there’s a payment milestone attached to that go-live, and the meeting isn’t really about whether it’s safe to proceed. It’s about whether it can be made to look safe enough…
About Paul
Paul Maxwell is a cyber and governance practitioner with experience across defence, government and commercial environments. He writes about the gap between what organisations say is controlled and what the evidence shows is actually working.