SlideShare a Scribd company logo
Building the
blocks to
quantify
cyber risks
Prof. Hernan Huwyler, MBA CPA
#STRONGER2021
01
Data to
performance
Business impact
assessments
Statistical
analysis
02
03
04
05
06
Risk modeling
Quantification
Communication
Data to Performance
You need to obtain
good data to quantify
your cyber security
risks
Good data will help you
to decide priorities and
investments today to
maximize the
performance tomorrow
Business impact assessment
You need to assess the financial
impact on the confidentiality,
integrity and availability
objectives if a cyber risk
materializes
The financial impact should be
broken down into number of
records, affected parties and
downtime hours
Business impact assessment
Confidentiality Integrity Availability
IT Asset
IT Process
IT Service
Record
.
Cost
Record
.
Cost
Downtime
.
Cost
You can model multiple scenarios with their own distribution
Triangular Lognormal Discrete
Uniform Paretto
Normal
Business impact assessment
Profitability losses of potential
and current clients
Regulatory fines
IP and competitive losses
Cost of changing the CISO
Secondary
impact
Downtime costs
Notification and response
costs
Damage on IT assets
Contractual penalties
Fraud losses
Primary
impact
Statistical analysis
You can use external data
by adjusting significant
variances between
industries, geographies,
organization sizes, and
business models for your
organization
Statistical analysis
Threat attacks statistics
• Budget vs. actual by project
• Incident database
• Fraud and social engineering
• Penetration testing findings
• Discovered security
vulnerabilities
• Malware logs
Statistical analysis
Threat attacks statistics
• KPIs for SLAs and outsourcing
contracts
• Ongoing due diligence results
• Lost and early disposed IT
assets
• Maintenance analysis
Stadistical analysis
Threat attacks statistics
• Data loss prevention logs
• Help desk analysis on IT
issues
• API gateway protection logs
Model backtesting
You can measure the
impact of risk
incidents and compare
plans against actual
outcomes to improve
your risk data and use
regression‐based
methods
Quantification
Risk modeling
Prevent data
coctaiks
Objective
centric
Template in
native MS Excel
Simple
Address
multiple
scenerarios
Uncertainty
Compare with cyber
insurance,
investments and
control costs
Decision-
centric
Scoring and data cocktails
If you assess cyber risks using
scores or data cocktails with
useless formulas for inherent risks,
general data and control efficiency
scores disconnected from the
concrete objectives for the IT
assets, you are just wasting time
and inciting wrong decision making
Monte Carlo Simulation
Min Max
Confidence Interval
Loss USD
Nr
Cases
Monte Carlo Simulation
Confidence Interval Standard Error
80% 2.56
90% 3.29
95% 3.92
99% 5.15
z*-value*2
2
Ln (Max) + Ln (Min)
Standard Error
P(A), μ = , σ =
Ln
Single
Loss USD
=
Ln (Max) - Ln (Min)
=LOGNORM.INV(RAND(),(LN(Max)+LN(Min))/2,(LN( Max)-LN(Min))/standard error),0)
Monte Carlo Simulation
Single Loss
Estimation Tool
https://shorturl.at/iCFHI
Communicating
Heat maps and risk matrices
If you assess and
communicate your
cyber risks with
colors and
adjectives, you are
just committing
malpractice and
creating liabilities for
your organization
Loss exceedance curve
Loss USD
0.001 0.1 10
0%
25%
50%
75%
100%
Loss
chance
5%
95%
.001 .01 .1 1 10 100
Tornado chart
Expected cost USD
Error in use
Ransomware
Misconfiguration
Phishing
-50 0 50 100
Histogram
Expected cost USD
0
10%
20%
Density
0 50 100 200 300
Let´s connect
@hewyler
/hernanwyler
mydailyexecutive.blogspot.com

More Related Content

PPTX
Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA
PDF
Prof- Hernan Huwyler - AML Forum 2021
PDF
RiskAllay - Digital Compliance - Prof- Hernan Huwyler MBA CPA
PDF
Tips for IT Risk Management Prof. Hernan Huwyler Information Security Institute
PDF
IFCA Congress How the post-pandemic will shape the compliance agenda
PDF
Metric stream elevating your compliance program with technology
PPTX
International Standard on Assurance Engagements ISAE 3000 Audits
PDF
Tips for IT Risk Management Prof. Hernan Huwyler Information Security Institute
Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA
Prof- Hernan Huwyler - AML Forum 2021
RiskAllay - Digital Compliance - Prof- Hernan Huwyler MBA CPA
Tips for IT Risk Management Prof. Hernan Huwyler Information Security Institute
IFCA Congress How the post-pandemic will shape the compliance agenda
Metric stream elevating your compliance program with technology
International Standard on Assurance Engagements ISAE 3000 Audits
Tips for IT Risk Management Prof. Hernan Huwyler Information Security Institute

What's hot (20)

PDF
SAP insider GDPR compendium Hernan Huwyler
PDF
Information Risk Management - Cyber Risk Management - IT Risks
PPTX
IDA DTU RiskLab How to validate your risk data
PDF
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
PPTX
Hernan Huwyler - 10 risk concepts to throw on the bonfire
PDF
IT Security and Risk Management - Visionet Systems
PDF
Let me guess covid will be in all top risk studies this year
PDF
Master Class Cyber Compliance IE Law School IE Busines School
PDF
Hernan Huwyler 10 Compliance Risk Assessment Mistakes
PDF
Hernan Huwyler - CIO and CISO Nordics
PDF
Hernan Huwyler MetricStream German Law idw ps 340
PDF
Qa Financials - 10 Smart Controls for Software Development
PDF
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
PDF
Strategy Insights - How to Quantify IT Risks
PPT
Regulatory Risk
PDF
Managing Contract Risks during Coronavirus Crisis
PPTX
The challenges for the internal auditor
PDF
Enterprise Information Technology Risk Assessment Form
DOCX
Generic_Sample_INFOSECPolicy_and_Procedures
PDF
Hernan Huwyler - Boards in a Digitalized World
SAP insider GDPR compendium Hernan Huwyler
Information Risk Management - Cyber Risk Management - IT Risks
IDA DTU RiskLab How to validate your risk data
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
Hernan Huwyler - 10 risk concepts to throw on the bonfire
IT Security and Risk Management - Visionet Systems
Let me guess covid will be in all top risk studies this year
Master Class Cyber Compliance IE Law School IE Busines School
Hernan Huwyler 10 Compliance Risk Assessment Mistakes
Hernan Huwyler - CIO and CISO Nordics
Hernan Huwyler MetricStream German Law idw ps 340
Qa Financials - 10 Smart Controls for Software Development
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
Strategy Insights - How to Quantify IT Risks
Regulatory Risk
Managing Contract Risks during Coronavirus Crisis
The challenges for the internal auditor
Enterprise Information Technology Risk Assessment Form
Generic_Sample_INFOSECPolicy_and_Procedures
Hernan Huwyler - Boards in a Digitalized World
Ad

Similar to Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler (20)

PPTX
Cybersecurity_Risk_Management presentation.pptx
PDF
w-cyber-risk-modeling Owasp cyber risk quantification 2018
PDF
Cybersecurity risk assessments help organizations identify.pdf
PDF
Quantifying Cyber Risk, Insurance and The Value of Personal Data
PDF
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
PDF
FORUM 2013 Cyber Risks - not just a domain for IT
PDF
Quantifying Cyber Risk
PDF
Cyber Risks - Maligec and Eskins
PPTX
1234567RISK-MANAGEMENT-FOR-SECURITY.pptx
PPTX
Cyber Security # Lec 3
PDF
Cyber Risk Quantification | Safe Security
PPTX
Risk assessment
PDF
How close is your organization to being breached | Safe Security
PPTX
BDQCRM Cyber Risk Management Intelligence Top 12 Final 080216
PDF
2023 ITM Short Course - Week 1.pdf
PDF
How To Handle Cybersecurity Risk Powerpoint Presentation Slides
PPTX
Stay Ahead of Threats with Advanced Security Protection - Fortinet
PDF
How To Handle Cybersecurity Risk PowerPoint Presentation Slides
PDF
Risk bridges business and security
Cybersecurity_Risk_Management presentation.pptx
w-cyber-risk-modeling Owasp cyber risk quantification 2018
Cybersecurity risk assessments help organizations identify.pdf
Quantifying Cyber Risk, Insurance and The Value of Personal Data
Lightweight Cybersecurity Risk Assessment Tools for Cyberinfrastructure
FORUM 2013 Cyber Risks - not just a domain for IT
Quantifying Cyber Risk
Cyber Risks - Maligec and Eskins
1234567RISK-MANAGEMENT-FOR-SECURITY.pptx
Cyber Security # Lec 3
Cyber Risk Quantification | Safe Security
Risk assessment
How close is your organization to being breached | Safe Security
BDQCRM Cyber Risk Management Intelligence Top 12 Final 080216
2023 ITM Short Course - Week 1.pdf
How To Handle Cybersecurity Risk Powerpoint Presentation Slides
Stay Ahead of Threats with Advanced Security Protection - Fortinet
How To Handle Cybersecurity Risk PowerPoint Presentation Slides
Risk bridges business and security
Ad

More from Hernan Huwyler, MBA CPA (20)

PDF
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
PDF
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
PDF
Model to Quantify Compliance Risks.pdf
PDF
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
PDF
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
PDF
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
PDF
The Behavioral Science of Compliance CUMPLEN.pdf
PDF
R is for Risk 2 Risk Management using R
PDF
Compliance and the russian invasion - Prof Hernan Huwyler
PDF
DPO Day Conference - Minimizing Privacy Risks
PDF
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
PPTX
Cyber Laundering and the AML Directives
PDF
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
PDF
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
PDF
10 Mistakes in Implementing the ISO 37301
PDF
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
PDF
AReNA - Debate Is Machine Learning Mature Enough
PDF
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
PDF
Master Class Compliance as a Service Hernan Huwyler
PDF
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Model to Quantify Compliance Risks.pdf
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
The Behavioral Science of Compliance CUMPLEN.pdf
R is for Risk 2 Risk Management using R
Compliance and the russian invasion - Prof Hernan Huwyler
DPO Day Conference - Minimizing Privacy Risks
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Cyber Laundering and the AML Directives
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
10 Mistakes in Implementing the ISO 37301
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
AReNA - Debate Is Machine Learning Mature Enough
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
Master Class Compliance as a Service Hernan Huwyler
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap

Recently uploaded (20)

PPT
Data mining for business intelligence ch04 sharda
PDF
COST SHEET- Tender and Quotation unit 2.pdf
PPTX
HR Introduction Slide (1).pptx on hr intro
PDF
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
PDF
Training And Development of Employee .pdf
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
PDF
Types of control:Qualitative vs Quantitative
PPTX
Belch_12e_PPT_Ch18_Accessible_university.pptx
PPTX
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
PDF
Laughter Yoga Basic Learning Workshop Manual
DOCX
Business Management - unit 1 and 2
PDF
Unit 1 Cost Accounting - Cost sheet
PDF
A Brief Introduction About Julia Allison
PPT
Chapter four Project-Preparation material
PDF
Ôn tập tiếng anh trong kinh doanh nâng cao
PDF
How to Get Funding for Your Trucking Business
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PDF
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
PDF
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
DOCX
Euro SEO Services 1st 3 General Updates.docx
Data mining for business intelligence ch04 sharda
COST SHEET- Tender and Quotation unit 2.pdf
HR Introduction Slide (1).pptx on hr intro
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
Training And Development of Employee .pdf
New Microsoft PowerPoint Presentation - Copy.pptx
Types of control:Qualitative vs Quantitative
Belch_12e_PPT_Ch18_Accessible_university.pptx
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
Laughter Yoga Basic Learning Workshop Manual
Business Management - unit 1 and 2
Unit 1 Cost Accounting - Cost sheet
A Brief Introduction About Julia Allison
Chapter four Project-Preparation material
Ôn tập tiếng anh trong kinh doanh nâng cao
How to Get Funding for Your Trucking Business
ICG2025_ICG 6th steering committee 30-8-24.pptx
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
Euro SEO Services 1st 3 General Updates.docx

Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler