Quantitative risk analysis translates cybersecurity risks into measurable dollar amounts, giving organizations a clear, comparable basis for evaluating and prioritizing threats. This approach moves beyond subjective high-medium-low ratings by factoring in probability, full financial impact, and annualized loss expectations for recurring risks.
Quantitative Risk Analysis
A great way to compare the different risks that we have to a company is using quantitative risk analysis. It's a way that we can render down our information into some sort of quantity — in this case, into a dollar amount, a dollar amount associated with that risk.
In our example here we're taking a probability, a percent, times the impact, to create a dollar amount, versus something like a likelihood and impact where we're just selecting high, medium and low from a list. So we're getting to the actual dollar amount. What's great about this is it really drives home the point of what the risk is of our specific risks. It's a great way to do risk comparison.
To be able to calculate our risk, we really have to understand what the impact is. Let's use the example of, let's say we have a few servers — there are three servers here — and those servers were stolen. In the scenario we have a 100% loss of these assets.
So now the question is, do we use the asset value, or do we use a total cost of ownership? Asset value being the assets that these servers have right there, either on the books or what we purchased them for; and the total cost of ownership would be, what is all that went into setting these up and getting them back up and running.
I'm going to say that the impact is neither of those, because the asset value is really just the purchase price or the depreciated value there, and those aren't really representative of what the impact is going to be. Because if we buy all new servers to replace them, we have deployment costs there. The operation cost really isn't a factor here, so we can ignore that one — it does play into total cost of ownership, but it's not really going to affect the new servers, we'd be paying for it whether we have the old servers or the new servers. Same thing with ongoing maintenance: we're going to have that ongoing maintenance whether they're new servers or old servers, so the impact doesn't change those. We don't need new training, new processes. So there's going to be some extra costs here for things like deployment, but total cost of ownership isn't representative of it either. So we have to kind of choose what is going to be actually impactful if these servers were to be stolen.
The impact goes beyond just the loss of those assets. We have the loss of asset, which is one consideration here, but there are other considerations as well. These are all of what could happen with a cyber security incident.
For instance, those servers are now gone, they were stolen, so they're not operating during that time. If we were an e-commerce business, we're losing revenue at that point in time. Or maybe we were caught, then we had to admit that we didn't encrypt the drives, and that was against laws and regulations, so now there's some judgment and fines. Not to mention now we have to notify the customers, so we have got to go out and notify the customers. Now we have a reputation loss, and because of that our brand is not as powerful as it used to be, and because of that maybe now we're going to actually lose some customers. So it could be very devastating beyond just the value of these servers that were stolen.
When we analyze impact we really have to look at all of the considerations that go into both the assets themselves and what the loss means to the company as a whole. What is the full impact?
Once we understand what the impact is going to be by understanding these, what we have to do is just figure out what the probability is that these servers are going to get stolen, and now that's going to equate to some sort of dollar amount associated with risk.
There is one other consideration that I'm just going to throw out there, which is what happens to things that are reoccurring risks. There are some risks that are just associated with maybe a project that you have, and how are you going to deal with that risk. But there are some ongoing risks that need to be considered as well.
For instance, in this case right here, let's say we have scams that are actively being carried out on our employees, and we have employees now and then that fall for that. This is a reality of doing business today: we're going to probably lose some money to scams. If we've got a big enough workforce, it's probably just a matter of time until that's going to happen.
So what we need to figure out in this case is what our annualized loss expectancy is for this. What this essentially means is that on an annual basis there's going to be a certain amount of employees that are going to fall for this every single year, and there's an average expected loss for each one of those, and so then we'll find out what our annualized loss expectancy is.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →