PAUL MAXWELL · ACCEPTABLE RISK

About Paul

I’m Paul Maxwell. I’m a cyber and governance practitioner, and most of my working life has been spent asking a simple question: does this actually work when the organisation is under pressure?

Where that mindset came from

I started out as a Royal Navy engineering artificer. My job was maintenance and readiness. If something mattered, it got checked, tested and owned. If it didn’t, it failed at the worst possible time.

That mindset stayed with me. It is why I’m sceptical of “we’ve documented it” as a comfort blanket.

What I’ve learned

Across decades of work in cyber security, information assurance, technology risk and governance, I’ve seen the same pattern repeat in defence, government and commercial environments.

Organisations rarely fail because they have never heard of the right framework. They fail because controls drift, ownership becomes vague, supplier assumptions go untested, recovery plans are never rehearsed and assurance starts to describe intention rather than reality.

A lot of my work has been about closing that gap: making risk concrete enough that someone can own it, test it, evidence it and make a decision about it.

How I think about governance

I care less about how good something looks on paper and more about whether it works in real life.

  • Who owns it?
  • What does “good” look like in day-to-day operation?
  • What evidence proves the claim?
  • What happens when the organisation is put under pressure?
  • What decision does leadership actually need to make?

The principle is simple: find the real risk, not the documented risk, then turn it into something owned, prioritised and provable.

The work behind the writing

I currently work at partner level in Governance, Risk and Compliance, with responsibility for growth and delivery across public and private sector clients.

Before that, I founded and ran Stratia Cyber, building a cyber security consultancy focused on practical assurance, security leadership and high-assurance delivery.

Professional proof

Credentials are useful proof, but they are not the point. My current professional designations, certifications and assurance roles include FCIISec, FBCS, ChCSP, CITP, CISSP and CISA, and I am a Defence Cyber Certification (DCC) Level 0–3 Assessor.

They matter because some readers need independent evidence of professional standing. They do not replace judgement, operating experience or evidence.

Why Acceptable Risk exists

Acceptable Risk is my public library of what I’ve seen work, what I’ve seen fail, and the disciplines that stop organisations being surprised by problems they thought they had already governed.

It is deliberately not a services catalogue. The aim is to make governance more useful by asking what is actually happening, what consequence follows, what evidence exists, who owns the issue and what decision is required.

Because “documented” isn’t a mitigation strategy.