Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

How much risk do we have? A useful answer is not a single number presented as a forecast. It is a transparent estimate of what defined adverse scenarios could cost, how likely they are under stated assumptions, and how much a proposed security response may change that exposure. “Pricing your bad days” means assigning defensible economic ranges to plausible events while keeping uncertainty and hard-to-price consequences visible.

What does it mean to price a security risk?

Risk combines the likelihood of an adverse event with the impact if it occurs. NIST describes risk as the extent to which an entity is threatened by a circumstance or event, typically as a function of adverse impacts and likelihood. The concept can include effects on operations, assets, people, other organizations, and national interests—not just direct financial loss. See NIST SP 800-30 Rev. 1, published by the Joint Task Force Transformation Initiative in September 2012.

An economic model translates only the impacts that can be credibly valued into money. Downtime, restoration work, or contractual costs may be estimable from organizational records; mission disruption, safety, privacy, image, and reputation may be difficult or inappropriate to reduce to a dollar or pound figure. Keep those outcomes in the assessment as qualitative impacts rather than silently treating them as zero.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build the model around a decision and a scenario

Start with the choice the model is meant to inform: for example, whether to fund a control, choose between response options, or monitor an existing safeguard. Define the adverse event, affected service or asset, accountable owner, and time horizon. A scenario should be specific enough that the organization can estimate its likelihood and consequences, but not so narrow that it hides meaningful pathways to loss.

Risk assessments are decision aids, not permanent ratings. Their relevance is bounded by changes in systems, missions, threats, and operating environments. NIST’s risk-assessment guidance and Risk Management Framework emphasize reassessment and ongoing monitoring as conditions change.

Estimate baseline exposure without pretending it is a forecast

A simple conceptual calculation is:

  • Expected annual loss for a scenario = estimated event frequency per year × estimated loss per event.
  • Expected loss reduction = baseline expected loss − expected loss after treatment.
  • Net expected benefit over the selected period = expected loss reduction − response cost.

These are analytical quantities, not predictions that a specific loss will occur in the stated amount. If evidence is uncertain, use a range or a distribution for frequency and impact instead of presenting a point estimate as precise. Explain the data, assumptions, dependencies, and confidence behind each input. A wide range can be decision-useful because it shows uncertainty rather than hiding it.

The UK National Cyber Security Centre (NCSC) illustrates how to communicate a range: “Based on our current security controls, we are 90% confident this risk will occur at least once in the next year, and that it will cost between £5,000 and £25,000 if it occurs”. This is a hypothetical example in its guidance on quantifying risk, not an empirical incident-cost benchmark.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Estimate how a response changes the exposure

For each proposed control or response, estimate whether it changes event frequency, loss severity, or both. Use assurance activities, evaluations of control efficacy, and informed judgment about how the control integrates with the system. Record what supports the estimate and where judgment is doing the work. Do not assume a control eliminates risk: report the treated exposure as residual risk.

Include the cost of implementing and operating the response over the same period used for the loss comparison. NIST’s Prioritizing Cybersecurity Risk for Enterprise Risk Management notes that including anticipated cost enables comparison with risk exposure and supports cost-benefit analysis.

If a multiyear analysis warrants discounting or other finance conventions, state the rate, timing, and assumptions. Avoid adding financial complexity that the available evidence cannot support.

Compare options on more than the headline number

Use the same scenario definition and time horizon for each candidate. A decision table makes trade-offs visible:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Comparison factor What to record
Expected loss reduction Estimated change in frequency, impact, or both for the defined scenario.
Cost Implementation and continuing costs over the chosen period.
Evidence and uncertainty Input sources, confidence, ranges, and important assumptions.
Time to reduce risk When the response is expected to become effective.
Residual risk Exposure remaining after treatment and whether it fits the organization’s tolerance.
Constraints Operational, privacy, mission, or regulatory limits that affect the choice.
Dependencies and shared benefits Other scenarios affected by the response and dependencies that could change its effectiveness.

Do not rank options solely by a universal return-on-security ratio or threshold: no general benchmark is established here, and organizations have different risk tolerances, constraints, and evidence quality.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the model honest and useful

  • Prevent double counting. Make clear which loss category captures each consequence, and do not count one loss in several categories.
  • Handle dependencies explicitly. Do not treat correlated events as independent unless the model explains why that assumption is appropriate.
  • Separate valued and non-valued impacts. Preserve qualitative consequences such as safety, privacy, reputation, and mission effects in the decision record.
  • Expose subjective judgments. Quantification can support cost-benefit analysis, but hidden subjective determinations and substantial uncertainty limit how rigorous the resulting number can be, as NIST cautions in SP 800-30 Rev. 1.
  • Set a review trigger. Revisit estimates when systems, threats, operations, or the mission change, and monitor whether controls perform as assumed.

The result should let a decision-maker see the baseline exposure, the response’s cost, the estimated reduction, the uncertainty, and what remains outside the monetary calculation. That is more defensible than a seemingly exact loss figure detached from its assumptions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.