PRACTITIONER-LED GOVERNANCE THINKING

Practical governance thinking for when the paperwork stops being enough.

Cyber, privacy, AI, suppliers and resilience rarely stay inside their own boxes. Acceptable Risk is a practitioner-led library about what happens when governance meets operational reality — the evidence, ownership, consequences and decisions that matter.

Because “documented” isn’t a mitigation strategy.

START HERE

Three pieces that explain the worldview.

The Risk Register Nobody Looks At

When a governance artefact exists but no longer shapes decisions.

Your Risk Appetite Doesn’t Matter When You Inherit Theirs

How dependencies turn somebody else’s control choices into your exposure.

Three AI Certifications, Three Governance Problems

Why assurance labels do not remove the need for ownership and judgement.

Explore by subject

Governance Without Theatre

Evidence, ownership, accountability and leadership decisions.

Data Privacy in Practice

Privacy as an operating discipline rather than a paperwork exercise.

AI Governance: Practitioner View

Inventory, oversight, evidence and accountability around real AI use.

Defence, Certification & Supply Chain

Assurance, dependencies, suppliers and demonstrable trust.

Latest thinking

  • You Bought the Data. You Still Own the Decision.

    Buying third-party marketing data does not settle how you can use it. The organisation still needs to understand the source, intended purpose, authority, evidence and who owns the decision.

    Read

  • DCC: Five Things I’ve Learnt as an Assessor

    Five practical lessons from Defence Cyber Certification assessment preparation: scope, evidence, Cyber Essentials, proactive certification and independent assurance.

    Read

  • The Defence Supply Chain Risk Nobody Priced In

    Every prospective defence supplier who calls me wants roughly the same thing: help understanding what the MOD actually requires, so they can get into the supply chain and start earning from it. Nobody opens the conversation asking what they’re taking on. They open it asking how to get in. One of them, a small manufacturer…

    Read

  • The Danzell Problem Nobody in the Supply Chain Has Fixed Yet

    In July, I was running an assurance review with a defence supplier just as their annual SAQ renewal came up. Everything on their end was spotless. Cyber Essentials reissued under the new Danzell requirements? Done in June. Cloud-wide MFA, tighter patch windows, and social media brought into scope? All checked off. It was a textbook…

    Read

About Paul

Paul Maxwell is a cyber and governance practitioner with experience across defence, government and commercial environments. He writes about the gap between what organisations say is controlled and what the evidence shows is actually working.

About Paul Maxwell →