Skip to content

Methodology

Cyber risk quantification: data and methodology.

Start with the data requirements, then inspect the assumptions, calculations, and limits behind the fictional sample memo and the loss assumption worksheet.

Prepared by ValtyUpdated

Practical input checklist

Start with one company, one business service, and one funding question. Record a source, owner, date, scope, and confidence basis for every input. A missing value is a gap to resolve, not a measured zero.

Scroll sideways for all columns.

Evidence to request before relying on a company-specific comparison
InputUseful evidenceIf it is missing
Decision and scopeCompany, critical service, scenario boundary, annual horizon, currency, budget cap, decision ownerAgree the question before calculating. Do not mix company and fund budgets.
Event frequencyIncident history with observation period and coverage; a documented external prior when local data is thinLabel a prior or estimate, explain relevance, and test sensitivity. No recorded incidents does not prove zero frequency.
Loss per eventService recovery time, contribution or outage-cost basis, response costs, contractual assumptions, and separately scoped secondary lossesKeep bounds and sources explicit. Do not treat revenue as loss or count downtime twice.
Control state and effectDated coverage exports, tests, findings and exceptions, plus the causal assumption connecting a change to frequency or severityKeep observed state separate from assumed financial effectiveness. Hold an option if its effect cannot be meaningfully scoped.
Cost and constraintsQuotes, internal labor, recurring and setup cost, required actions, capacity, and dependencies on other workRequest a quote or scope. Unknown cost is not zero; compare options over a matching cost horizon.
Reproducibility and reviewInput version, model version, scenario assumptions, reviewer decision, evidence cut-off and next review dateMark the result provisional and preserve the unresolved input. A reproducible estimate can still use poor assumptions.

Use three evidence labels

Observed: scoped evidence actually collected. Prior-backed: an external assumption with its relevance explained. Missing: unavailable or insufficient for the question. A policy document and an execution test answer different questions.

Test what could reverse the choice

Change the uncertain frequency, severity, effectiveness, or cost assumptions and compare again. If a plausible change reverses the recommendation, obtain the evidence or make approval conditional.

Apply the checklist to the sample decision memo, use the annual loss expectancy calculator for basic arithmetic, or read the investment-prioritization guide for a budget comparison.

Methods note

Simulation or simple arithmetic?

The sample decision memo simulates annual loss outcomes. The loss assumption worksheet multiplies annual frequency by mean loss per event. Both show gross loss before insurance.

Simulated sample

Simulate a range of annual outcomes.

The product engine simulates 50,000 years for fictional Example Manufacturing Co., using stated frequency and severity assumptions. It reports mean, median, and P95 annual loss. All inputs are invented for the demonstration, not observed customer rates.

Worksheet

Check one expected-loss calculation.

Enter annual frequency and mean loss per event to see their product. The worksheet performs no simulation and produces no percentiles, peer benchmarks, or uncertainty range.

Insurance

Keep loss, cost, and insurance separate.

Neither tool models insurance recovery or premium changes. Action costs and budgets are inputs, distinct from loss estimates. Application screenshots elsewhere on the site show separate illustrative scenarios; their figures do not feed this sample.

Statistical dictionary

Six distinctions the sample decision memo depends on.

These are the exact terms used on the sample decision memo, defined against the fictional Example Manufacturing Co. fixture so the definitions are checkable, not abstract.

Method vs. calibration

Reproducible arithmetic is not the same claim as a calibrated model.

The engine is deterministic: every recorded metric (mean, median, P95, zero-loss-year share) reproduces exactly on replay from the same seed and inputs. That proves the arithmetic is reproducible for the values this fixture actually records — it says nothing about unrecorded engine internals such as wall-clock timestamps, and it does not prove the input assumptions (frequency, severity) match any real company’s loss experience — that is a separate, unmade claim in this worked example.

Expected vs. median vs. tail

Mean, P50, and P95 are three different numbers.

The “no optional action” baseline has a mean annual loss of $791,066, a median (P50) of $124,681, and a P95 of $3,512,449. None of these is small in the context of a $100,000 annual budget decision; reporting only one of the three, or swapping one for another, changes what the number means.

Event vs. annual

A per-event severity is not an annual loss.

Each simulated year draws an independent event count (Poisson) and, independently, each event’s severity (lognormal), then sums them. An “average incident size” and an “average annual loss” answer different questions; the memo always labels which one it shows.

Outcome variability vs. parameter uncertainty vs. simulation error

Three different things, each easy to mistake for one of the others.

(1) Modeled year-to-year outcome variability is real: some simulated years genuinely have zero events, others several, so the mean-to-P95 spread describes actual variation in the modeled distribution, not an error to be reduced. (2) Parameter uncertainty is whether the entered frequency and severity assumptions themselves are realistic; this fixture does not attempt to quantify that, and states it as a separate, unaddressed limitation rather than comparing its size to anything else. (3) Finite-sample (Monte Carlo) simulation error is how closely the empirical mean and zero-loss-year share, specifically, track their closed-form theoretical values at 50,000 trials — the sample’s published analytic checks measure exactly those two quantities (not every percentile) and confirmed they were within a few percent at generation time.

Numerical comparability, not causal evidence

Shared random streams make scenarios comparable; they don’t prove an action works.

The sample’s scenarios share paired random streams so they can be compared on the same footing (a variance-reduction technique). That is a numerical convenience, not empirical evidence that any modeled action would produce that effect on a real company. Every “modeled effect” in the sample is a stated assumption for this demonstration, not a measured causal result.

Joint recomputation, not summed deltas

Combining two actions means a new engine run, not addition.

The sample’s combined-action scenario is a fresh engine run at both actions’ assumptions together, not the sum of each action’s independent effect. Summing independently modeled quantile deltas is a common but unsound shortcut this page deliberately avoids.

One specific shape effect worth naming directly: the modeled recovery-capability action ($650,000 mean severity, 0.6 log-sigma, vs. $1,000,000 / 1.2 at baseline) lowers the mean and P95 while it actually raises the median (P50 goes from $124,681 to $275,501). A narrower lognormal shape concentrates outcomes closer to the mean, which lifts the middle of the distribution even as it compresses the tail — an assumption about distribution shape, not a claim that the action is measured to help in every outcome.

Scope: the mechanics above are demonstrated using the product’s pinned-revision Monte Carlo engine (vendored byte-identical; hash recorded on the sample page). That shows the engine mechanics work as described. It does not independently validate any deployed customer profile, does not constitute production/GA status for the broader platform, and does not substitute for a qualified actuarial or model-risk review of any specific company’s inputs.

The assumption worksheet

One multiplication, shown in full.

The free tools at /calculator, /start-executive, /board-brief, and /risk-assessment share one worksheet: you enter an annual event frequency and a mean per-event loss, and the tool computes expected annual loss = frequency × mean per-event loss. That is the entire calculation. There is no percentile, no peer comparison, no control-effectiveness assumption, and no valuation output. A blank or invalid input produces no result — it is never silently treated as zero.

Claim boundary

What this page does not claim.

Stated plainly, scoped to this fixture and worksheet, because trust is built by making the limits visible, not by omitting them.

Not a warranty

These figures are decision-support estimates, not contractual guarantees.

The mean, median, and P95 figures are model outputs from stated assumptions. They are inputs to a decision, not a financial commitment, an insurance valuation, or a promise that a funded action will produce the modeled reduction.

Not independently validated

This synthetic fixture has not been externally calibrated.

No third-party actuarial or model-risk reviewer has checked these specific input assumptions against observed loss history. That is a known, stated limitation of this illustrative example, not a claim about any other engagement.

Not production status for the platform

A pinned engine revision proves this mechanism works, not that every deployed profile is production-ready.

The Monte Carlo engine used here is vendored byte-identical from one pinned product source revision (hash recorded on the sample page). That demonstrates the arithmetic mechanism. It does not certify general availability, a specific customer deployment, or every configuration of the broader product.

Gross loss is not EBITDA impact

A modeled annual loss figure is not the same object as an EBITDA adjustment.

The mean, median, and P95 figures on the sample, and the expected-annual-loss figure the worksheet computes, are modeled or computed gross annual loss (no insurance recovery assumed). None of them are netted against EBITDA, a valuation opinion, or a capitalized contingent loss at an exit multiple. Cost and budget figures on either page are plain input assumptions, not modeled loss, and turning any loss estimate into an earnings or valuation claim would be a separate, unmade analytical step.

Next step

Read the sample, then try the worksheet on your own numbers.

The sample shows one full worked decision. The worksheet lets you run the same simple arithmetic on your own frequency and severity assumptions.