PRACTITIONER-LED GOVERNANCE THINKING
Practical governance thinking for when the paperwork stops being enough.
Cyber, privacy, AI, suppliers and resilience rarely stay inside their own boxes. Acceptable Risk is a practitioner-led library about what happens when governance meets operational reality — the evidence, ownership, consequences and decisions that matter.
Because “documented” isn’t a mitigation strategy.
START HERE
Three pieces that explain the worldview.
The Risk Register Nobody Looks At
When a governance artefact exists but no longer shapes decisions.
Your Risk Appetite Doesn’t Matter When You Inherit Theirs
How dependencies turn somebody else’s control choices into your exposure.
Three AI Certifications, Three Governance Problems
Why assurance labels do not remove the need for ownership and judgement.
Explore by subject
Governance Without Theatre
Evidence, ownership, accountability and leadership decisions.
Data Privacy in Practice
Privacy as an operating discipline rather than a paperwork exercise.
AI Governance: Practitioner View
Inventory, oversight, evidence and accountability around real AI use.
Defence, Certification & Supply Chain
Assurance, dependencies, suppliers and demonstrable trust.
Latest thinking
You Bought the Data. You Still Own the Decision.
Buying third-party marketing data does not settle how you can use it. The organisation still needs to understand the source, intended purpose, authority, evidence and who owns the decision.
DCC: Five Things I’ve Learnt as an Assessor
Five practical lessons from Defence Cyber Certification assessment preparation: scope, evidence, Cyber Essentials, proactive certification and independent assurance.
The Defence Supply Chain Risk Nobody Priced In
Every prospective defence supplier who calls me wants roughly the same thing: help understanding what the MOD actually requires, so they can get into the supply chain and start earning from it. Nobody opens the conversation asking what they’re taking on. They open it asking how to get in. One of them, a small manufacturer…
The Danzell Problem Nobody in the Supply Chain Has Fixed Yet
In July, I was running an assurance review with a defence supplier just as their annual SAQ renewal came up. Everything on their end was spotless. Cyber Essentials reissued under the new Danzell requirements? Done in June. Cloud-wide MFA, tighter patch windows, and social media brought into scope? All checked off. It was a textbook…
About Paul
Paul Maxwell is a cyber and governance practitioner with experience across defence, government and commercial environments. He writes about the gap between what organisations say is controlled and what the evidence shows is actually working.