Pricing your bad days and how to build an economic model for security decisions

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/10/08/ivan-milenkovic-qualys-cyber-risk-quantification/

ONE SENTENCE SUMMARY:

Security leaders should quantify cyber risk in money via loss-scenario models, prioritize remediation by value-at-risk, and report consistently to boards, CFOs, and underwriters.

MAIN POINTS:

  1. Many security metrics lack a financial anchor, leaving boards unable to assess value delivered.
  2. Effective models start with business loss scenarios, then map down to driving assets.
  3. Assign a loss range to each scenario, improving estimates with real outcomes over time.
  4. Prefer system-sourced inputs; distrust numbers manually adjusted or curated by humans.
  5. Prioritization should reflect value at risk, not technical severity scores alone.
  6. Compare exposures on revenue-impacting systems versus low-value assets like unused test servers.
  7. Board reporting should stay above CVE detail, focusing on enterprise control scaling and residual loss.
  8. Demonstrate “nothing happened” value through measurable changes: exposure windows, overdue risk, tested controls.
  9. CFOs expect spreadsheet-ready ranges, likelihoods, spend options, and consequences of inaction with an owner.
  10. A single underlying model can serve board decisions and insurance underwriting with different evidence depth.

TAKEAWAYS:

  1. Reverse the usual approach: model losses first, then trace vulnerabilities to business impact.
  2. Use value-at-risk to depoliticize remediation decisions and justify resource allocation.
  3. Prove prevention by tracking consistent, time-series indicators tied to key scenarios.
  4. Translate security into finance language: ranges, probabilities, and decision-linked investment outcomes.
  5. Align board narratives and underwriting submissions so claims-time scrutiny matches reported reality.