Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 8 of 15
Introducing cyber security risk quantification

An introduction to analysing risk quantitatively, and why you might use this technique.
Introduction
More people are adopting cyber security risk quantification as a way of improving their risk analysis and communication. Doing so can allow you to talk about cyber security risk in terms that may be more familiar to your stakeholders, and more relevant to the wider business context of your organisation. Many people are put off trying to quantify risks due to misconceptions about whether they have the necessary knowledge or data. This guidance introduces cyber security risk quantification, addresses some myths, and talks about why you might use it.
What is quantification ?
Quantification is defined as “the expression or measurement of the quantity of something”. Applied to cyber security risk analysis, that could mean using statistical modelling to measure how much risk you have. For risk communication, quantification could mean:
- expressing the likelihood or the impact of a risk as quantities such as once a week, month or year
- the downtime of a system in hours
- the cost of remediation as a monetary value for impact.
Ordinal numbers (1st, 2nd, 3rd, etc) or labels (low, medium, high) don’t measure the quantity of something; they represent position or order. In cyber security, ordinal numbers or labels are often used to score findings or risks on their likelihood or impact. These are ordinal labels rather than measured quantities, and so are not an example of cyber security risk quantification. Some approaches to risk assessment and risk analysis seek to combine these labels or ordinal numbers using mathematical operations, and because these are not measured quantities this should be avoided.
Risk quantification myths
There are a lot of misconceptions around cyber security risk quantification that can put people off trying it for themselves. Before we discuss why you might consider quantification, the table below seeks to debunk some of these myths.
| Myth | Reality |
|---|---|
| I don’t have the data. | You can apply quantification to data that you already have. If you don’t have a lot of confidence or certainty in your data, quantification offers a way for you to capture this explicitly.
You may have access to more data than you think. To get the best results, we recommend making use of a variety of data sources including open source reports, previous incidents, log data, and the opinions of experts in your organisation. It’s not the case that a quantitative approach requires you to only use objective, quantitative data sources.
The key is understanding what questions you want to answer and identifying the data you need to do that. If you do want more information on using quantitative data in your organisation, the NCSC blog on data driven security can help. |
| I can’t put an exact value on a risk. | You shouldn’t be overly precise when quantifying risk. One of the benefits of quantification is how it allows you to be explicit about how much uncertainty you have around an estimate. If an incident could cost you between £100 and £10,000, then you can make that explicit and build it into your models or communications. Even if your uncertainty ranges are really wide, this will at least make your uncertainty or lack of data clear to stakeholders and decision makers. |
| You can’t measure cyber risks in the same way you can with other risks. | Common concerns, such as a lack of historical incident data or the perceived inability to quantify intangibles (like reputational risk) are not problems unique to cyber security. Other disciplines have found ways to use quantification despite these concerns. Whilst you may not be able to measure a more abstract concept (like reputation) directly, you may be able to quantify the impact of reputational damage by considering things like the reduction in numbers of new customers, or a drop in share price.
You don’t have to use money as your measure when quantifying risk. You could use the time it takes to restore a system following an incident or the number of devices affected if they are more applicable measures. All of these are potential ways to quantify the impact of a risk to provide insight into what could happen if a risk is realised. |
| I don’t have the skills or knowledge to use quantification. | You don’t need an army of mathematicians or economists to apply quantification. Quantifying your risk could mean making an estimate based on available data and doesn’t have to involve complex statistical modelling. If you are interested in exploring statistical methods, these don’t require a degree in statistics. Many techniques can be applied using a spreadsheet. |
| I’ll have to restart my risk management process from scratch. | There’s no need to throw any of your existing analyses or tools away. You can introduce quantification alongside your existing approach without needing extra analysis or time.
You don’t need to apply quantification to every area of your risk management process; you may choose to apply it to a particular analysis to support a specific decision you need to take.
If you did want to adopt a quantitative approach more widely, quantitative risk standards, like FAIR, are compatible with other standards, tools, or frameworks you may be using in your organisation such as ISO27005 or the NIST cybersecurity framework. |
Why might you use cyber security risk quantification ?
Quantifying risks can help express them in ways that are more applicable to a business context. For example, you can estimate the likelihood of a risk occurring using frequencies or percentages ('We expect this event to occur once within the next 6 months').
Similarly you can express the potential impact of a risk quantitatively. This could include using monetary value, the number of devices affected, the number of critical services affected, or how long critical systems or services will be unavailable.
Combined, this would allow you to describe risks using likelihood and impact, for instance, ‘Based on our current security controls, we are 90% confident this risk will occur at least once in the next year, and that it will cost between £5,000 and £25,000 if it occurs’. Framing risks in this way can help answer business questions such as ‘How much risk do we have?’ and can make conversations about whether risks are likely to exceed risk tolerance levels easier to manage.
Risk quantification can make it easier to perform cost benefit analysis. As well as deriving quantitative estimates for how often a risk will occur (or the impact it will have), you can also estimate by how much a proposed control will reduce that risk. These estimates could be informed by a range of sources such as assurance activities, evaluations of the efficacy of a control, or expert knowledge of how a proposed control will integrate into your system.
Comparing the estimated reduction in the likelihood or impact with the cost of a new control can help decision makers choose whether to implement a control (or not). This helps ensure limited security resources are managed as efficiently as possible. Similarly, when there are multiple options for which controls to implement, weighing up the reduction in risk each option offers (as well as their cost) can help you make more informed decisions.
It’s hard to compare two risks both rated as ‘high’ or 5/5 and decide which one needs addressing first. If the risks are quantified in a way that offers more granularity and visibility for what a risk could mean for your organisation, it can help practitioners and decision makers decide which risk to address first.
There is a lot of uncertainty in cyber security which often goes unacknowledged. This can lead to unexpected outcomes and damage trust with key stakeholders. Quantifying risk allows you to be explicit about how much uncertainty you have in your analysis, by allowing you to represent the likelihood or impact of a risk occurring as a ‘distribution’ rather than a single value.
If you are using ordinal labels to communicate your risks, quantification can help your analyst team make explicit what is meant by each label and agree when something becomes a ‘high’ rather than a ‘medium’ or ‘low’ risk. Analysts assigning different labels to the same risks can be a pitfall of ordinal ratings systems, so having clear quantified definitions can ensure everyone is on the same page.
As with all approaches to risk analysis, you should take care to document your assumptions in case these need to be revisited later. You should also seek to provide information on what data sources or processes you have used to reach your conclusions when communicating risks.


