A well-defined cyber risk appetite is foundational to building any firm's information security program in alignment with a firm’s business objectives and values. Yet guidance on what makes a cyber risk appetite effective--especially for firms that will significantly rely on cloud platforms--is arguably lacking, including standards for establishing risk appetite compliance thresholds from KPIs, KRIs, and KCIs. This talk will share current and forthcoming guidance and practices for developing a cyber risk appetite pertinent for firms that will rely on secure critical cloud-based operations.