Effective Cyber Risk Quantification

Effective Cyber Risk Quantification - presentation by Stern Security's Founder & CEO, Jon Sternstein. At the 2024 Triangle InfoSeCon event.

by | Nov 9, 2024 | Education, Publications

On November 8th, 2024, the Raleigh ISSA Chapter hosted the Triangle InfoSeCon event, the largest cybersecurity event in North Carolina. Stern Security‘s Founder & CEO, Jon Sternstein gave a presentation titled “Effective Cyber Risk Quantification”.

Cyber risk quantification (CRQ) is often described as the process assessing the likelihood and impact of cybersecurity risks and scoring vulnerabilities or tying risks to financials. In the presentation, Jon Sternstein made the case that CRQ really comes down to translating cyber risk into business terms. Furthermore, the most effective means of quantifying risk can vary drastically between industries, companies, and individual recipients of the message. There are many methods of cyber risk quantification with varying levels of difficulty including, but not limited to, using breach reports to understand likelihood and financial impact, reviewing data breach and data mis-use fines from regulatory bodies, and the FAIR methodology.

The presentation detailed three true cyber risk quantification stories that Jon Sternstein experienced in his career. The first story was about implementing security initiatives in a healthcare organization. While the initial strategy had great reasons for deploying the various initiatives, they gained the most traction when the risks were tied to financial terms that the executives connected with. The breach numbers from the Ponemon report were used as a basis for the cyber risk quantification.

The second story involved a manufacturing company where the executives were not as concerned with the cost of records lost, but they were very concerned with the amount of downtime that the manufacturing plant could have experienced with a cyber incident.

The Stern Security presentation discussed how cyber risk quantification often tends to be focused on the “confidentiality” of data as a basis. However, there are three pillars of cybersecurity: Confidentiality, Integrity, and Availability. Cyber Risk Quantification should focus on all three pillars and certain pillars may be more important for certain industries or companies.

The final story involved quantifying the risk of a romance scam where the victim lost thousands of dollars. Simply stating that it was a scam had minimal impact on the victim during the incident, but discussing the dollars lost over time and the personal information exposed had the most impact.

Cyber Risk Quantification (CRQ) is essential for getting cybersecurity initiatives deployed and for adding the most value to an organization. As The Stern Security presentation stated, Cyber Risk Quantification is really the process of translating cyber risk into language that the business understands. Cybersecurity leaders should understand the priorities of the individuals who they are presenting to in order to quantify cyber risk accordingly and get strategies and budgets approved.