The floor is not the target
Every European security programme now has a regulator-shaped floor under it. NIS2 names the measures, DORA names the resilience testing, ISO 27001 names the management system. Each is a statement of the minimum a serious organization should already be doing, written to be met by an entire sector, in whatever shape that sector arrives.
That is exactly why the floor cannot be the target. A requirement written for everyone cannot know which of your services would stop the business if it went down on a Tuesday morning, or which supplier holds a credential into it. Meeting the minimum tells an auditor you are not negligent. It does not tell your board how much loss you are currently carrying.
A control set proves you met the minimum. It says nothing about what an attacker can reach.
What risk appetite actually fixes
Risk appetite is the number the floor is missing. It is the organization’s own statement of what it is prepared to lose, in revenue, in downtime, in customer trust, and unlike a directive it is specific to you. Stated properly, it converts an argument about tooling into an arithmetic problem: this service can be unavailable for four hours, therefore this dependency needs this treatment.
Discretionary security
requirement
Set by risk appetite
Minimal compliance
requirement
e.g., NIS2 · DORA · ISO 27001
Discretionary security requirement — Set by risk appetite
Minimal compliance requirement — e.g., NIS2 · DORA · ISO 27001
Drawing the bandwidth
Put the two on the same axis and you get a band rather than a line. The lower edge is what regulation compels; the upper edge is what your appetite justifies paying for. Everything between them is discretionary, the space where security leadership is actually exercised, and the only space where the answer to “why are we spending this” is yours to give.
The band is also a defence against the two familiar failure modes. Below it you are non-compliant. Above it you are buying assurance the business never asked for, usually because a control framework or a vendor set the ambition instead of you.
Where the two meet in practice
In practice the band is drawn per business service, not per organization. Scope the exercise to one service that genuinely carries revenue or obligation, draw its band, and the method transfers to the rest. Trying to draw one band for a whole company produces a number nobody recognizes and nobody defends.
What to do on Monday
Pick one service. Write down what the business would accept losing if it failed, in hours and in euros, and get someone outside security to agree with the number. Then list what is reachable from the outside that touches it. The gap between those two pages is your bandwidth, and it is usually the most useful document a security team produces all year.

