← Cyber risk

Cyber risk / Method

Give protection decisions a quantified basis.

Connect technical exposure to the business consequences you need to manage. Make the evidence, assumptions and uncertainty available to the people deciding what to protect and fund.

Define the decision and the scenario

Begin with the business activity at risk and the decision the analysis needs to support. Identify the relevant assets, the threat event and the consequences for operations, people or data.

A clear scenario gives technical and business stakeholders a shared scope. Mapping assets to the activities they support helps identify where disruption would matter and which protection choices are relevant.

Understand frequency and magnitude

Our cyber risk work uses the FAIR approach to relate the frequency of loss events to their potential magnitude. Controls, threat conditions and the organisation’s circumstances inform the estimates.

Loss exposure combines how often a loss event may occur with how much it may cost.

For a defined period, expected loss considers both loss-event frequency and loss magnitude. The financial consequences can include operational interruption, response and recovery costs, and other losses relevant to the scenario. The range of possible outcomes is important alongside any central estimate.

Make the assumptions inspectable

Document the available evidence, the estimates it supports and the gaps that require judgement. Use ranges where the data cannot support a single value, and examine which assumptions have the greatest influence on the result.

Probability estimates can be updated as relevant evidence becomes available. Bayesian reasoning provides a way to relate an initial estimate to new observations; the quality and relevance of those observations remain part of the review.

This gives stakeholders a way to discuss what they know, where uncertainty remains and what additional information could change the decision.

Compare investment options

Evaluate the current exposure and how it could change with proposed controls. Compare the potential reduction in loss with the investment and operating costs of the protection.

The result supports a decision about priorities, accepted exposure and further investigation. Revisit the analysis when meaningful changes to the assets, controls or business context affect its assumptions.