Most organizations still describe cyber risk in colors and maturity levels. That is not good enough for a decision that involves real money.
These methods are explored further in Risk Horizon and in ongoing notes shared on LinkedIn.
Cyber Risk Quantification
A quantitative cyber risk management methodology and Monte Carlo simulation express cyber exposure as an expected loss range, with Return on Control to prioritize which mitigation is worth funding.
Regulatory & Resilience Readiness
Bringing ICT risk programs into line with DORA, NIS2, and ISO 27001, connected to an actual quantified risk picture rather than a checklist.
AI-Driven GRC Automation
Applying automation to continuous risk monitoring, evidence handling, and reporting, so exposure stays current instead of resetting after each audit cycle.
Executive Risk Communication
Turning a technical finding into a number and a question a board or an investment committee can act on, calibrated like any other financial estimate.
Two outputs from the same underlying model.
A Monte Carlo run across a single loss scenario: thousands of simulated years compressed into one distribution, so the conversation is about a realistic case and a severe case, not one number pretending to be certain.
The same logic rolled up to an annualized loss exposure curve, with value-at-risk thresholds marked, the form an exposure figure needs to take before it can sit next to any other line in a risk appetite statement.
Why expert judgment still matters
Cybersecurity is part engineering and part inference, and both depend on measurement. Most organizations struggle here not for lack of tools but for lack of a person who can hold the analytical line: define the risk register properly, keep evidence and assumption clearly separated, and communicate exposure and mitigation cost in relation to a stated risk tolerance. That is what turns a quantification exercise into a decision an executive team can actually act on, not a report that sits unread once the audit closes.
DORA Third-Party Rules: A Governance Checklist, Not a Risk Number
The EU’s Digital Operational Resilience Act tells financial entities exactly what to do about vendor risk. It does not tell them what that risk is worth, and that gap is where most third-party risk programs quietly stall.