If a risk is "unsolvable" it gets accepted as is by the accountable person in the business side of things. They will/should have good reason why they can't solve it.
Plenty of companies keep their security teams + CISO after they get popped.
Plenty of companies keep their security teams + CISO after they get popped.