Cyber Risk Quantification (CRQ) Frequently Asked Questions


The Answers to All Things Related to Cyber Risk Quantification (CRQ)
Cyber risk quantification (CRQ) has become a cornerstone of many cyber risk management and cybersecurity GRC programs, and will continue to emerge as one as regulations and board expectations evolve. This FAQ answers the most common questions about CRQ, explaining everything you need to know about choosing the right provider. Whether you’re new to CRQ or refining an existing program, this resource is designed to help you make more informed decisions.
Does Kovrr's platform offer any cybersecurity prioritization recommendations?
Yes. With Kovrr's CRQ platform, organizations can input their specific cybersecurity maturity framework levels. With this information, the platform then offers targeted quantified insights regarding implementation levels and how much financial exposure could be reduced if specific controls were upgraded. Kovrr's CRQ also provides recommendations based on asset groups, revealing which upgrades will have the largest impact on reducing the risk of various business units.
How does cyber risk quantification aid the prioritization process?
Cyber risk quantification translates complex cyber metrics and outcomes into monetary terms, offering objective figures that can be used to compare the benefits of various initiatives. Especially as cybersecurity budgets are limited, it's crucial for CISOs to optimize their finances to make the largest impact on the organization, protecting crown jewels and minimizing potential loss.
Which factors do I account for when prioritizing my limited resources?
When deciding which initiatives and security control upgrades to invest limited resources in, it's paramount to understand their impact on the organization's cyber risk posture. You should ask questions such as, "By how much does this initiative reduce my financial exposure?" and "Does this initiative result in a positive ROI for the organization?" It's best also to consider factors such as compliance and broader business objectives.
Why is the prioritization of cyber investments important?
Given a near-total dependence on the cloud, organizations nowadays face a seemingly endless list of cyber risks. This digital reality demands that CISOs prioritize their efforts and limited resources according to those vulnerabilities that have the potential to cause the most significant damage. Prioritization ensures cyber resiliency in the wake of an attack, minimizing downtime and maximizing the ability to grow.
What are the controls and validation tests for the outputs and results pillar?
The outputs and results pillar confirms the correct operation of the model as a whole. We employ both a top-down and bottom-up validation approach for the CRQ assessment's output and results. Our experts review the results in direct comparison to historical events, industry reports, and client case studies, allowing us to prove that model outputs are accurate. We're also receiving continuous feedback from our clients who similarly remark upon the accuracy and preciseness of quantifications, allowing them to plan targeted cyber risk mitigation strategies.
What are the controls and validation tests for the model calculations pillar?
The model calculations concern the mathematics of the model and how it operates mechanically. When making changes, improvements, or adding new features to the model, we outline and review model-change specifications and implement change control management. Kovrr employs many modern coding standards to ensure the software acts appropriately and can be deployed quickly and without error. This includes the use of unit and integrity testing, as well as regression tests against prior results, so any changes to the model are well understood.
What are the controls and validation tests for the input and data pillar?
For the inputs and data pillar, Kovrr has undertaken a combination of data validation expert reviews and comparisons against independent sources to ensure that parameters are accurate and well supported. We also establish change controls and audit management, keeping track of everything that has changed, including when and why. Similarly, when parameters are changed, we follow up with even more validation testing to prove the reasonableness of these updates.
What are the main components used to maintain CRQ model quality?
Kovrr maintains the quality of its CRQ model by structuring risk controls around the three main components, or pillars, of "model risk."' The first of these pillars is the inputs and data fed to the models, where controls and checks are performed to ensure the model is calibrated on the correct data, used and interpreted appropriately. The second pillar is model calculations, which cover how the core mathematics of the simulation are implemented without error. Finally, the third pillar is the quantification outputs, which check that the overall simulation generates results that represent realistic scenarios.
Are my organization's executive stakeholders interested in third-party cyber risk?
Yes, very much so. Relationships with third-party service providers have the potential to leave your organization open to a slew of cyber-related vulnerabilities, which executives need to account for when developing strategies for the upcoming year. With cyber risk quantification platforms like Kovrr's, these stakeholders readily understand the company's financial exposure due to various third-party service provider connections and can invest in the necessary action plans to mitigate this risk.
Is it okay to report technically oriented metrics to key stakeholders?
When communicating metrics, it's always important to consider the audience and their respective knowledge. Therefore, even impressive, technically oriented KPIs may not deliver the intended effect. If you still want to include these metrics in your board and stakeholder reports, make sure to demonstrate how they tangibly impact the business in financial terms, allowing your audience to understand in full. Kovrr provides a free, customizable board reporting template that was designed to help you present the metrics that matter in the boardroom.
How does cyber risk quantification enhance high-level reporting?
Although executives and other key business stakeholders typically have a limited background in cyber risk, they conversely have extensive experience in fiscal planning based on a company's potential financial loss. By translating this technical business risk into more familiar terms, board members and senior management are readily equipped to discuss these important cyber matters and, subsequently, utilize the information provided to create strategies that cost-effectively bolster business resiliency.
Why are color-coded risk matrices an ineffective way to communicate cyber risk?
In the early days of corporate-level cybersecurity, cyber risk managers used color-coded risk matrices to condense the more complex aspects of cyber risks into a more approachable framework for board members. However, nowadays, these colorful heat maps are entirely too simplified, not providing the data-driven insights boards required for budget planning and resource allocation. These stakeholders need tangible, outcome-driven metrics.
Do you provide any additional resources that can facilitate board reporting?
Yes! Kovrr offers a customizable board presentation template that offers the key information CISOs and cyber security risk managers should report to board members and other key stakeholders. Boards are interested in KPIs that are communicated in a broader business language, and our presentation tells you exactly how to achieve this. If you'd like access, reach out to us today.
Why do board members need to be informed about cyber risk?
As the cost of cyber events continues to rise and governments worldwide enact legislation mandating cybersecurity matters be raised to the highest organizational levels, it's apparent that cyber risk is a business – making it crucial for board members to understand. With boardroom involvement, businesses will be more responsive in the wake of an event, and cybersecurity prioritization can be embedded within the corporate culture.
What does Kovrr's CRQ platform offer in terms of metric reporting?
While Kovrr's CRQ platform offers numerous cyber risk metrics, some of the ones most often used by CISOs during boardroom presentations include average loss expectancies, both holistically and broken down according to event type. The platform also provides peer benchmarks, giving board members a greater contextual understanding of how the organization's cyber risk posture measures up to competitors. Check out our demo platform to explore all the metrics we offer.
How does cyber risk quantification help board members make decisions?
Cyber risk quantification translates complex cyber terms into event likelihoods and financial impacts. Board members readily understand these metrics and are, therefore, better equipped to factor them into high-level discussions. For example, knowing the average expected loss due to cyber activities can help board members more accurately calculate risk appetite levels – which is key for resiliency in the wake of an incident.
Does adopting a CRQ tool always have to be a long journey?
No. Although many CISOs and cyber risk managers have stumbled upon CRQ because of challenging or ineffective communication with non-technical executives and stakeholders, others have had a more straightforward journey with the tool. Sokolovskiy's relationship with cyber risk quantification is merely one CISO's experience. To learn more about quickly implementing this solution into your cyber risk program, reach out to one of our risk experts today.
Why did Sokolovskiy ultimately decide to quantify cyber risk with Kovrr?
After exploring several cyber risk quantification platforms and assessment approaches, the former Avid CISO discovered Kovrr. After learning that Kovrr's models incorporate real data from aggregated insurance claims and are continuously fed external global intelligence regarding cyber events, he understood that the results would ultimately be as objective as possible. Indeed, insurance industry claims come as close as one can get to the realistic numbers of the cost of a data breach.
What were the issues working solely with the CIS and NIST frameworks?
Sokolovskiy discovered that the CIS control framework was too technical for the Avid board members. The NIST framework, while more approachable for non-technical executives, was still very subjective, making it difficult to embed cybersecurity initiatives and outcomes within the broader business strategy. The CISO fundamentally understood that board members operated in financial implications, and he, therefore, needed a solution that allowed him to communicate in that language.
How did Dmitriy Sokolovskiy, ex-Avid CISO, begin his CRQ journey?
Dmitriy Sokolovskiy, former CISO at Avid Technology company, found himself in a position where he needed to justify budget requests and spending decisions, just like many other CISOs. While these circumstances first led him to adopt cybersecurity maturity model frameworks to facilitate this justification, he ultimately found he needed to supplement his explanations with a language the board was more familiar with, such as financial implications.
