In a 2017 survey of almost 1,300 CEOs conducted by PwC, 63% of respondents said they were “extremely concerned” about cyber threats — up from just 8% in 2013.
For those who have been paying attention, this dramatic upward trend is hardly surprising. Data breaches are getting bigger, more damaging, and more expensive. It’s challenging to read the news without seeing a story about one massive cyber attack or another.
In many industries, the fear of cyber attacks has resulted in huge investments in cybersecurity personnel, services, and technology. Unfortunately, because cybersecurity effectiveness is only demonstrated by a lack of negative results (i.e., zero data breaches), understanding the returns on these investments has been extremely difficult.
For this reason, quantifying cybersecurity risk is a top priority for business leaders who want greater security without inflating their budgets.
Why Do I Need to Quantify Cyber Risk?
The problem with unchecked investment in cybersecurity initiatives is that an increase in resources does not necessarily lead to a decrease in risk. For example, an organization might spend millions on their firewall, SIEM, and other network controls, only to fall victim to a supply chain attack.
Cybersecurity is complex. New technologies, new attack vectors, and new business decisions all have direct effects on a business’s cybersecurity program. In order to maximize the efficiency of the program, resources must be allocated in such a way that the most effective tools and strategies are used to protect the most sensitive systems and data.
However, proper resource allocation requires the ability to put a number on cybersecurity effectiveness. It’s not enough to say “we didn’t experience a data breach this quarter, therefore the investments are working.” After all, two businesses who have both gone one quarter without a data breach might have vastly different levels of cybersecurity risk.
Once an organization has a system in place to quantify cyber risk, however, a range of important benefits become available, including goal-setting, benchmarking, data-driven decision making, and improved resource allocation.
How Can I Quantify Cyber Risk?
Businesses have many options for getting a handle on the effectiveness of their cybersecurity program. Internal assessments, third-party audits, and penetration tests are all popular choices. However, these methods all share four common downsides: