IT Security Blog | Rivial Security

Is a Quantified Cyber Risk Number Defensible? The Inputs

Written by Randy Lindberg | 09 Sep 2026

The most common objection to cyber risk quantification does not come from boards. It comes from security leaders, and it goes like this: the number is only as good as the inputs, the inputs are guesses, so the dollar figure is just a guess wearing a suit. I have met CISOs who own a quantification tool and refuse to use it for exactly this reason. It is a fair objection, and it deserves a real answer instead of a slogan. This post walks through where the inputs in a quantified risk model actually come from, and what separates a defensible number from a decorated guess.


First, the double standard


Before defending the dollar figure, look at what it replaces. A high, medium, low rating is also built on inputs. Someone chose the likelihood, someone chose the impact, and someone decided where medium ends and high begins. Every objection you can raise against a quantified number applies with more force to a color, because the color hides its inputs and the number exposes them.


That is the whole game. Defensibility does not mean the number is certain. It means you can show your work. A rating cannot show its work, structurally. A quantified model can, if it is built on the right sources.

 

An Examiner Approved Cyber Risk Model

Check out the Cyber Risk Management Model that examiners reference below

 



Input one: published breach data, not self-populated guesses


The objection is right about one thing: a tool where you type in your own likelihood estimates produces your own opinions, formatted. That is the Microsoft Excel approach to risk, whatever software it runs in, and I would not take it to a board either.


The alternative is to anchor frequency and impact in published, independent data that exists whether or not it flatters you. In our model that means sources like the Verizon Data Breach Investigations Report for how incidents actually happen and to whom, and the Ponemon and IBM cost-of-a-breach research for what incidents actually cost, reviewed annually as new editions land. When an examiner asks why the model says a data breach on your core carries the probability it does, the answer starts with industry-wide incident data, not with "our IT manager felt like a 3."


Your own environment enters where it should: your systems, your data types, your record counts, your controls. The public data sets the baseline; your specifics adjust it. Both halves are documented, which is what makes the final number auditable.


Input two: MITRE ATT&CK for how attacks actually work


Likelihood is not one number; it is a chain. An attacker has to get in, move, and reach something worth taking. MITRE ATT&CK gives you a public, evidence-based catalog of the techniques adversaries actually use at each link in that chain. Building threat scenarios on ATT&CK does two things. It grounds the likelihood side of the model in observed adversary behavior. And it hands you a reference the examiner already respects. I have watched skepticism dissolve at that name more than once, because it signals that the threat model is not something we invented in a conference room.


Input three: Monte Carlo simulation, and why the curve matters


Here is where the math earns its keep. A naive model multiplies one likelihood by one impact and calls it expected loss. The real world does not work that way. Losses are not a bell curve with most outcomes near the average. They follow a lognormal shape: lots of small events, a meaningful tail of catastrophic ones. The average day is quiet, and the bad day is very bad. Anyone who has lived through an incident knows this in their bones.


Monte Carlo simulation handles that honestly. Instead of one multiplication, the model runs thousands of simulated years against your systems, drawing from the frequency and impact distributions, and produces a full loss curve: the expected annual loss, and the tail scenarios your board should know exist. This is the same technique your finance team already accepts in other domains, which matters when you present it. You are not asking the board to trust a security invention. You are showing them a standard tool pointed at a new problem. The lineage here runs through published work on measuring exactly these supposedly unmeasurable things, and none of it is proprietary magic.


The interview problem, and how validation closes it


There is one more attack on the number, and it is the sharpest one: if the model's control inputs come from interviews, the number rests on self-reported answers. A board member put it to one of our prospects plainly: an interview-only assessment is not something I can take to the board.

 

She was right. The fix is validation, and there are three practical paths. Roll control testing into the assessment itself, so key answers get verified rather than recorded. Tie the model to your compliance evidence, so a control marked effective points at the artifact proving it. Or connect your IT general controls audit results into the risk model. Any of the three moves the inputs from "what we said" to "what we showed." A quantified model with validated inputs is the strongest risk statement a financial institution can make. A quantified model with interviewed inputs is still better than colors, but you should know which one you are buying.

 

This validation loop is what the Rivial platform automates. Assessment answers link to evidence, control test results flow into the model, the Monte Carlo runs on top, and every system's risk lands in a board report as dollars against your board-approved tolerance. When someone asks where a number came from, the answer is a click, not a scramble. Our methodology has been through NCUA and FDIC examiner review at institutions from $20 million to $20 billion in assets, and transparent math is the reason it holds up.

 

An Examiner Approved Cyber Risk Model

Check out the Cyber Risk Management Model that examiners reference below

 



What defensible actually means


So, is a quantified cyber risk number defensible? It is when four things are true. The frequency and impact inputs trace to published data. The threat scenarios trace to a public framework. The control inputs trace to evidence, not just interviews. And the math from inputs to output is a standard statistical method anyone can inspect. Miss those and the critics are right. Hit them and the dollar figure becomes the most defensible thing in your exam binder, because it is the only artifact in there that can show exactly how it was made.


And there is a payoff beyond the exam. The CISO who walks into the boardroom with a defensible dollar figure stops playing defense about methodology and starts allocating capital: this risk exceeds our tolerance, this control removes $500,000 of it for $50,000, here is my recommendation. That is the language of business, and speaking it is what turns a security officer into a strategic partner.


Test the number against your own skepticism


The honest way to evaluate all this is on your own systems. Our free cyber risk assessment runs the full model, with the sources above, on five of your critical systems, and we guarantee it identifies at least $100,000 in risk reduction. You will see exactly where every number comes from, which makes it a fair test of everything this post claims. About two hours of your team's time, the report is yours, and no sales call is required.

Here are the key takeaways from this blog:

  • Colors hide their inputs; numbers expose them: every objection to quantification applies more strongly to high, medium, low, which cannot show its work at all.
  • Defensible inputs are external: published breach data and MITRE ATT&CK anchor the model in evidence that exists independent of your opinions.
  • Monte Carlo respects reality: losses follow a lognormal curve, not a bell curve, and simulation captures both the expected year and the catastrophic tail.
  • Validation beats interviews: tie control answers to testing and evidence, and the number moves from "what we said" to "what we showed."

An Examiner Approved Cyber Risk Model

Check out the Cyber Risk Management Model that examiners reference below