Cyber risk quantification involves the application of risk quantification techniques to an organization's cybersecurity risk. Cyber risk quantification is the process of evaluating the cyber risks that have been identified and then validating, measuring and analyzing the available cyber data using mathematical modeling techniques to accurately represent the organization's cybersecurity environment in a manner that can be used to make informed cybersecurity infrastructure investment and risk transfer decisions. Cyber risk quantification is a supporting activity to cybersecurity risk management; cybersecurity risk management is a component of enterprise risk management and is especially important in organizations and enterprises that are highly dependent upon their information technology networks and systems for their business operations. One method of quantifying cyber risk is the value-at-risk method that is discussed at the January 2015World Economic Forum meeting. At this meeting, VaR was studied and researched and deemed to be a viable method of quantifying cyber risk.
Tools
Cyber-Risk Quantification can be an automated or software supported process allowing Users to construct mathematical models to quantify Cyber-Security risks; examples are:
'Cyber-Confidence' is / are the actual executed tests which have passed. This value can be converted to a statistical probability & the associated Cyber-Risk calculated:
Example-1: 'A certain number' of tests have been executed & passed. Let's imagine that it yields a Defect-Free Confidence of 97.43%. Answer: Cyber-Risk = 2.57%.
Example-2: All 65,536 TCP ports & 65,536 UDP ports are confirmed to be dead or inactive on an asset; how resistant to penetration is it ? Answer: Cyber-Confidence = 99.83%, Cyber-Risk = 0.17%
Typically, this form of Cyber-Confidence &/or Cyber-Risk estimation is termed Testimation because:
It can be applied to estimate the number of tests required for any desired level of Cyber-Confidence
It can be applied to estimate the Cyber-Confidence based upon the number of tests which have actually been executed & passed