The scene repeats itself in every security committee. Two risks come up red on the heat map. One of them, if it happens, costs around R$ 80,000 and a bad weekend. The other costs R$ 12 million and a notification to the ANPD. The matrix paints both the same colour — and the decision about where the year's budget goes ends up being made by whoever spoke loudest in the meeting.
That is not the fault of whoever filled the matrix in. It is what the tool does: it compresses a continuous quantity into five steps, and then compresses two five-step axes into a colour. Discarded information does not come back.
Three concrete problems with the ordinal scale
- It ties together things that are different. Inside the "impact 5" step sit losses that differ by two orders of magnitude. Once classified, R$ 1 million and R$ 100 million are the same thing to the process.
- It does not add up. Multiplying "likelihood 4" by "impact 5" and getting 20 looks like arithmetic, but it is not: these are labels, not quantities. Twenty is not twice ten, and the sum of thirty "medium" risks means nothing — which is precisely the question the board asks: what is our total exposure?
- It hides the uncertainty. Anyone classifying a risk as "likely" is making a guess with an enormous margin, and the classification erases that margin. The result looks firm and is not.
None of this makes the matrix useless. For initial triage, with many risks and little information, it works and it is cheap. The mistake is using it where the decision is about allocating capital.
What quantifying means
Quantifying cyber risk means answering in money and probability, not in colour. The canonical form of a quantified risk has three parts:
- Frequency. How many times a year the event is expected to happen — fractions included: once every four years is 0.25 per year.
- Magnitude. What each occurrence costs, as a range with a confidence interval, not as a single number. Incident response, downtime, fines, notification, legal fees, a lost contract.
- Distribution of the outcome. Combining the two by simulation produces a curve: the expected annual loss and, more important for a decision, the tail — the plausible worst case.
The most widely used open method for this is FAIR, which breaks frequency and magnitude down into factors that can be estimated separately. But the method matters less than the change of unit. Moving from "high/red" to "between R$ 3 and R$ 18 million a year, with 90% confidence" changes who is able to take part in the conversation.
The honest objection: "we do not have the data"
It is the first reaction, and it is legitimate. It is worth answering straight, because the sales version of quantification tends to sweep it under the rug.
Three things are true at the same time:
- You have more data than you think. Your own incident history, measured downtime, the cost of an hour of stoppage per process, contract value at risk, the cyber insurance policy — all of it already exists in house.
- A calibrated estimate is not a guess. An expert trained to give intervals with a stated confidence is wrong in a measurable, correctable way. The matrix is an estimate too — only without a stated margin and with no way to check it afterwards.
- A wide range still decides. If risk A sits between R$ 2 and R$ 9 million and risk B between R$ 40,000 and R$ 120,000, the overlap is zero. The decision is made, even with enormous uncertainty on both.
Quantification does not replace judgement. It organises judgement and makes it arguable. When someone disagrees with a number, the discussion becomes about which assumption is wrong — and that is progress compared with disagreeing about a colour.
Where to start without turning it into a project
Do not start by quantifying the whole register. The short path has four steps:
- Pick three risks that are already red and that compete for the same budget.
- Build the scenario for each one in the form ISO 27005 uses: from the initial cause to the consequence for the business, step by step.
- Estimate frequency and magnitude as ranges, with the people who know the process — not only with security.
- Take the three to the committee side by side with the old matrix. The difference between the two views is the argument.
The exercise usually takes two weeks and produces an uncomfortable finding: almost always, one of the red risks is worth less than the control proposed to treat it. Finding that out is money saved directly, and it is the kind of thing the heat map never reveals.
The final test
A simple way to know whether your risk management is ready for the board: when they ask "what does doing nothing cost?", do you have an answer with a number and a margin, or do you have a colour?
If the answer is the colour, the problem is not the maturity of the programme — it is the unit of measurement.
This article describes principles of risk quantification and does not recommend a specific tool. The figures quoted are illustrative. For the open method mentioned, consult the FAIR documentation published by The Open Group.