Risk management
Quantifying cyber risk: Monte Carlo vs heat maps
Red, amber and green persuade nobody with a budget. A loss range in currency does. Here is how quantification works and how to start without a data science team.
Certifyi compliance team · Updated September 2026
Short answer. Cyber risk quantification expresses risk as a probable loss in currency rather than a colour or a score. The common method, described by the FAIR standard, decomposes each risk into how often a loss event is likely to occur and how much it would cost, expressed as ranges. A Monte Carlo simulation runs those ranges thousands of times to produce a distribution, from which you read the median (P50) and a bad-year figure (P90). Boards can weigh a P90 of $4.6M against the cost of a control; they cannot weigh a red square.
What is wrong with heat maps
A five-by-five heat map compresses likelihood and impact into ordinal buckets, then multiplies them as if they were numbers. The result has three problems: two very different risks land in the same cell, the ranking flips depending on how the buckets are drawn, and “high” has no unit, so it cannot be compared with the cost of fixing it. Research on risk matrices has shown they can rank risks worse than random in some configurations. They persist because they are easy, not because they are informative.
The FAIR decomposition
- Loss event frequency: how often a threat acts against the asset (contact frequency and probability of action) and how often that succeeds (vulnerability).
- Loss magnitude: primary losses (response, replacement, productivity) plus secondary losses (fines, legal, customer churn, reputation).
- Ranges, not points: each factor is estimated as a minimum, most likely and maximum, calibrated against whatever data exists: incident history, industry breach reports, insurer data, your own contracts.
- Simulation: the model samples each range thousands of times to produce a loss distribution for the scenario, then aggregates across scenarios.
Reading the output
| Figure | Meaning | Use in the boardroom |
|---|---|---|
| P50 (median) | Half of simulated years lose less than this | Expected annual loss for budgeting |
| P90 | Nine in ten simulated years lose less than this | Bad-year planning, insurance limits |
| Tail (P99) | One-in-a-hundred year | Existential exposure, board risk appetite |
| Change quarter on quarter | Movement after controls or scope changes | Whether spend is working |
Starting without perfect data
The objection is always “we do not have the data”. You have more than you think: incident tickets, vendor breach notifications, contract values, cost of downtime from past outages, insurer questionnaires. Public breach reports give industry-level frequency and cost ranges. Start with five scenarios that matter most, use wide ranges, and narrow them each quarter. A wide range honestly stated is more useful than a precise colour.
How Certifyi does it
The risk register in Certifyi carries the FAIR-style factors for each risk, runs Monte Carlo simulation over the register, and reports exposure as P50 and P90 in currency alongside the top drivers. Because the register is linked to controls and evidence, a board can see which control reduces which exposure and by how much, and the figures trace to hashed evidence when a director asks.
Risk quantification, answered
Is FAIR a standard?
Yes. Factor Analysis of Information Risk is an Open Group standard (O-RA and O-RT) and the most widely used model for quantifying information risk.
Do auditors accept quantified risk assessments?
Yes. ISO 27001 requires a risk assessment with defined criteria; it does not prescribe qualitative or quantitative. Auditors care that the method is documented, repeatable and drives treatment.
How many simulations are enough?
Ten thousand runs per scenario is typical and computationally trivial. More runs smooth the tail but rarely change the P50 or P90 materially.
Can we keep the heat map for the board?
You can show both, but present the currency range first. Once directors see exposure in money, the heat map becomes a legend, not the decision tool.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.