Presentation: Quantifying Risk in the Age of AI Threats

Presentation: Quantifying Risk in the Age of AI Threats

Background

On July 10th, 2025, Stern Security‘s Founder & CEO, Jon Sternstein spoke to financial organizations at the Carolinas Credit Union League event. Jon Sternstein discussed the essentials of quantifying cyber risk in the age of AI threats. The world is rapidly evolving and there are numerous way to conduct cyber risk quantification and business impact analysis activities to speak the language of the business.

Presentation Abstract

“Love, Lies, and Ledger Sheets: Quantifying Cyber Risk in the Age of AI Threats” by Jon Sternstein

In a world where artificial intelligence can mimic your voice and craft malware that slips past traditional defenses, cybersecurity is no longer about counting vulnerabilities—it’s about understanding business risk. Join Stern Security’s Founder & CEO, Jon Sternstein, as he unveils the evolving threat landscape through real-world stories (starting with a romance you won’t forget), and makes the case for why credit unions must shift from legacy reporting to actionable cyber risk quantification. Plus, a light look at global tensions and what they could mean for your cyber defenses.”

Conclusion

The presentation went into details about modern threats (AI deception threats, romance scams, gift card scams, wire transfer attacks, hacking incidents) in addition to proven solutions. Jon discussed various methodologies to quantify risk from simple to advanced options. Stern Security’s Velocity platform automates the cyber quantification needed to translate the security risk into business terminology and quickly help make security teams successful. The presentation include engaging true stories, laughs, “wow” factors, and audience participation cyber challenges. The credit unions left the event inspired and armed with the tools they need to increase their security posture to the next level.

Effective Cyber Risk Quantification

Effective Cyber Risk Quantification

On November 8th, 2024, the Raleigh ISSA Chapter hosted the Triangle InfoSeCon event, the largest cybersecurity event in North Carolina. Stern Security‘s Founder & CEO, Jon Sternstein gave a presentation titled “Effective Cyber Risk Quantification”.

Cyber risk quantification (CRQ) is often described as the process assessing the likelihood and impact of cybersecurity risks and scoring vulnerabilities or tying risks to financials. In the presentation, Jon Sternstein made the case that CRQ really comes down to translating cyber risk into business terms. Furthermore, the most effective means of quantifying risk can vary drastically between industries, companies, and individual recipients of the message. There are many methods of cyber risk quantification with varying levels of difficulty including, but not limited to, using breach reports to understand likelihood and financial impact, reviewing data breach and data mis-use fines from regulatory bodies, and the FAIR methodology.

The presentation detailed three true cyber risk quantification stories that Jon Sternstein experienced in his career. The first story was about implementing security initiatives in a healthcare organization. While the initial strategy had great reasons for deploying the various initiatives, they gained the most traction when the risks were tied to financial terms that the executives connected with. The breach numbers from the Ponemon report were used as a basis for the cyber risk quantification.

The second story involved a manufacturing company where the executives were not as concerned with the cost of records lost, but they were very concerned with the amount of downtime that the manufacturing plant could have experienced with a cyber incident.

The Stern Security presentation discussed how cyber risk quantification often tends to be focused on the “confidentiality” of data as a basis. However, there are three pillars of cybersecurity: Confidentiality, Integrity, and Availability. Cyber Risk Quantification should focus on all three pillars and certain pillars may be more important for certain industries or companies.

The final story involved quantifying the risk of a romance scam where the victim lost thousands of dollars. Simply stating that it was a scam had minimal impact on the victim during the incident, but discussing the dollars lost over time and the personal information exposed had the most impact.

Cyber Risk Quantification (CRQ) is essential for getting cybersecurity initiatives deployed and for adding the most value to an organization. As The Stern Security presentation stated, Cyber Risk Quantification is really the process of translating cyber risk into language that the business understands. Cybersecurity leaders should understand the priorities of the individuals who they are presenting to in order to quantify cyber risk accordingly and get strategies and budgets approved.

2024 Velocity Healthcare Data Breach Report

2024 Velocity Healthcare Data Breach Report

In its third annual healthcare data breach report, Stern Security has critically analyzed over 5,900 data breaches since the Department of Health and Human Services (HHS) began tracking the information in 2009. Stern Security utilized data from their HealthcareBreaches.com website as well as published information from HHS to create this comprehensive 2024 Velocity Healthcare Data Breach Report. Stern Security augmented the HHS data by investigating every breach in 2023 to fully understand the cause of the incident.

This report shows critical insights into healthcare breach trends over the past 14 years. It covers everything from the number of breaches attributed to ransomware to the number attributed to third-parties (business associates). This year, Stern Security has added a new breach categorization – the number of breaches due to the MOVEit file transfer software vulnerability. Review the report to see the significant impact that the MOVEit 0-day had on the healthcare industry. Once again, multiple breach milestones were set with more healthcare breaches occurring and more records exposed in 2023 than any previous year. This report puts forth the detailed analysis.

We sincerely thank our sponsors, Trend Micro and the Raleigh ISSA Chapter, whose contributions enable the ongoing pursuit of this important research and the free sharing of our findings.

Report

The full 2024 Velocity Healthcare Data Breach Report can be downloaded below.

Stay in the Loop

If you enjoy the report below and would like to be informed of future reports and research, please fill out the mailing list info below. Don’t worry – we don’t send many emails.

2023 Velocity Healthcare Data Breach Report

2023 Velocity Healthcare Data Breach Report

In its second annual Velocity healthcare data breach report, Stern Security has critically analyzed over 5,000 data breaches since the Department of Health and Human Services (HHS) began tracking the information in 2009. Stern Security utilized data from their HealthcareBreaches.com website as well as published information from HHS to create this comprehensive study. Stern Security augmented the HHS data by investigating each breach in 2022 to fully understand the cause of the incident.

This report shows critical insights into healthcare breach trends over the past 13 years. It covers everything from the number of breaches attributed to ransomware to the number attributed to third-parties (business associates). This year, Stern Security has added a new breach categorization – the number of breaches due to analytics software including Meta (Facebook) Pixel. Once again, a new breach record was established with more healthcare breaches occurring in 2022 than any previous year. This report puts forth a detailed analysis.

Mailing List

If you enjoyed our 2023 Velocity Healthcare Breach Report and would like to join our mailing list to stay informed, please complete the form below.

Break Down Silos & Secure the Planet

Break Down Silos & Secure the Planet

The 2022 Triangle InfoSeCon event hosted by Raleigh’s ISSA was on September 9th, 2022. To a full crowd, Stern Security‘s Founder & CEO, Jon Sternstein, gave a presentation titled: “Break Down Silos & Secure the Planet”.

The presentation abstract was the following:

People tend to cluster in their own silos and tribes in both society and within companies.  We have seen the dangers of lack of communication between individuals with different viewpoints play out between nations, states, politics, and more.  This siloed mindset also occurs within companies and industries and can lead to massive cybersecurity issues. 
 
This presentation will discuss the importance of breaking down silos.  Technical stories will be shared of large security vulnerabilities that we have discovered that would have been prevented if the company’s employees and contractors did not operate in silos.  We’ll also discuss some hacks to break out of your own silos, hack impostor syndrome, infiltrate executive ranks, and secure the planet.

Jon Sternstein’s presentation was an important lesson on working together to secure companies and to have a stronger society. Secure the Planet!

2022 Velocity Healthcare Data Breach Report

2022 Velocity Healthcare Data Breach Report

In its first annual healthcare data breach report, Stern Security has critically analyzed over 4,000 data breaches since the Department of Health and Human Services began tracking the information in 2009. Stern Security utilized data from their HealthcareBreaches.com website as well as published information from Health and Human Services to create this comprehensive report.

This report shows thought-provoking insights into healthcare breach trends over the past 12 years. It covers everything from the number of breaches attributed to ransomware to third-party (business associate) breaches. More healthcare breaches occurred in 2021 than any other year and this report illustrates the detailed analysis.

If you enjoyed the report and want to stay in the loop, please join our mailing list: