Cyber risk quantification expresses security risk in financial terms rather than on a qualitative scale. Instead of a red cell on a heat map, the output is a distribution of possible losses over a period.
Heat maps do not support decisions about money. A risk rated high and a risk rated medium give no basis for choosing where to spend, and no way to compare a security investment against any other use of the same capital.
A loss distribution does. It also lets security be discussed in the language the rest of the organization already uses for risk, which is usually the real motivation.
Decomposing a risk into the frequency of loss events and the magnitude when they occur.
Estimating each as a range with a stated confidence rather than a point value, since the honest answer is uncertain.
Running the ranges through a simulation, usually Monte Carlo, to produce a distribution.
Reading the output as a loss exceedance curve: the probability of losing at least a given amount in a year.
The FAIR model is the most widely used framework for this and provides the decomposition and vocabulary.
The output is only as good as the estimates going in, and the estimates are usually expert judgement. A simulation applied to guesses produces a precise-looking distribution over guesses. The precision is real and the accuracy is unknown.
Presenting a curve to a board implies a rigour the inputs may not support. The responsible version states the inputs and their basis alongside the output.
CRQ models consume facts. Asset counts and criticality. Control coverage across the actual population. Historical incident frequency. Remediation timeliness.
If those inputs are themselves estimates, or are computed differently each period, the model output cannot be compared across periods and cannot be defended when challenged.
This is the sequence that matters. A probabilistic model belongs on top of a deterministic factual base, taking measured facts as input. Built the other way round, with estimates feeding estimates, nothing underneath can be checked.
From the blog