Risk management

Quantifying cyber risk: Monte Carlo vs heat maps

Red, amber and green persuade nobody with a budget. A loss range in currency does. Here is how quantification works and how to start without a data science team.
Certifyi compliance team · Updated September 2026
Short answer. Cyber risk quantification expresses risk as a probable loss in currency rather than a colour or a score. The common method, described by the FAIR standard, decomposes each risk into how often a loss event is likely to occur and how much it would cost, expressed as ranges. A Monte Carlo simulation runs those ranges thousands of times to produce a distribution, from which you read the median (P50) and a bad-year figure (P90). Boards can weigh a P90 of $4.6M against the cost of a control; they cannot weigh a red square.

What is wrong with heat maps

A five-by-five heat map compresses likelihood and impact into ordinal buckets, then multiplies them as if they were numbers. The result has three problems: two very different risks land in the same cell, the ranking flips depending on how the buckets are drawn, and “high” has no unit, so it cannot be compared with the cost of fixing it. Research on risk matrices has shown they can rank risks worse than random in some configurations. They persist because they are easy, not because they are informative.

The FAIR decomposition

Reading the output

FigureMeaningUse in the boardroom
P50 (median)Half of simulated years lose less than thisExpected annual loss for budgeting
P90Nine in ten simulated years lose less than thisBad-year planning, insurance limits
Tail (P99)One-in-a-hundred yearExistential exposure, board risk appetite
Change quarter on quarterMovement after controls or scope changesWhether spend is working

Starting without perfect data

The objection is always “we do not have the data”. You have more than you think: incident tickets, vendor breach notifications, contract values, cost of downtime from past outages, insurer questionnaires. Public breach reports give industry-level frequency and cost ranges. Start with five scenarios that matter most, use wide ranges, and narrow them each quarter. A wide range honestly stated is more useful than a precise colour.

How Certifyi does it

The risk register in Certifyi carries the FAIR-style factors for each risk, runs Monte Carlo simulation over the register, and reports exposure as P50 and P90 in currency alongside the top drivers. Because the register is linked to controls and evidence, a board can see which control reduces which exposure and by how much, and the figures trace to hashed evidence when a director asks.

Risk quantification, answered

Yes. Factor Analysis of Information Risk is an Open Group standard (O-RA and O-RT) and the most widely used model for quantifying information risk.

Yes. ISO 27001 requires a risk assessment with defined criteria; it does not prescribe qualitative or quantitative. Auditors care that the method is documented, repeatable and drives treatment.

Ten thousand runs per scenario is typical and computationally trivial. More runs smooth the tail but rarely change the P50 or P90 materially.

You can show both, but present the currency range first. Once directors see exposure in money, the heat map becomes a legend, not the decision tool.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top