Cyber Risk and GRC Glossary

Definitions for the language of cyber risk quantification and cyber GRC, as the terms are used inside working enterprise risk and governance programs. Concepts span financial exposure modeling, control effectiveness, scenario analysis, and the regulatory frameworks that shape how cyber risk is measured and reported.

1:100 Annual Loss

The 1:100 annual loss is the loss magnitude at the 99th percentile of the annual loss distribution, meaning the level a cyber portfolio is statistically expected to exceed roughly once every hundred years.

Annualized Loss Expectancy (ALE)

Annualized Loss Expectancy (ALE) is a classical quantitative risk metric equal to the expected annual loss from a specific risk event, calculated as Single Loss Expectancy multiplied by Annual Rate of Occurrence.

Attack Surface

Attack surface is the total set of points where an unauthorized user could attempt to enter, extract data from, or otherwise affect an organization's information systems, spanning networks, applications, endpoints, identities, and third parties.

Average Annual Loss (AAL)

Average Annual Loss (AAL) is the mean of the annual loss distribution produced by cyber risk quantification, representing the loss an organization would expect to incur per year over a long time horizon.

BISO (Business Information Security Officer)

A Business Information Security Officer (BISO) is a security leader embedded within a specific business unit or line of business, responsible for translating enterprise security strategy into business-specific execution and vice versa.

Board Cyber Reporting

Board cyber reporting is the practice of translating an organization's cyber risk, program status, and control posture into information a board of directors can use for oversight, strategic guidance, and enterprise risk decisions.

Bottom-Up Risk Quantification

Bottom-up risk quantification is an approach that builds enterprise-level cyber exposure figures by starting from asset-level, control-level, and system-specific data, then aggregating detail into portfolio and enterprise views.

Business Email Compromise (BEC)

Business Email Compromise (BEC) is a fraud technique in which attackers impersonate a trusted party, typically an executive, vendor, or partner, using email to trick employees into transferring funds, changing payment details, or releasing sensitive information.

CIS Controls

The CIS Controls are a prioritized set of cybersecurity actions maintained by the Center for Internet Security, designed as an implementation-focused baseline for organizations building or benchmarking a cyber program.

CISO (Chief Information Security Officer)

The Chief Information Security Officer (CISO) is the executive responsible for an organization's information security strategy, program execution, risk reporting to leadership, and increasingly, cyber risk quantification and board-level communication.

COBIT

COBIT (Control Objectives for Information and Related Technologies) is ISACA's framework for enterprise governance and management of information and technology, used broadly by audit, risk, and GRC teams to structure IT and cybersecurity oversight.

Common Vulnerabilities and Exposures (CVE)

A Common Vulnerabilities and Exposures (CVE) identifier is a unique, publicly cataloged reference for a specific cybersecurity vulnerability, assigned by CVE Numbering Authorities and maintained by MITRE.

Compensating Controls

Compensating controls are alternative safeguards implemented when a required primary control cannot feasibly be used, providing equivalent risk reduction through different mechanisms and typically documented as a formal deviation.

Concentration Risk (ICT)

ICT concentration risk is the exposure created when many organizations depend on the same technology or cloud providers, so a single provider-side failure, outage, or compromise cascades across a large portion of the sector simultaneously.

Continuous Controls Monitoring (CCM)

Continuous Controls Monitoring (CCM) is the ongoing, automated verification that security controls are configured, deployed, and operating as intended, replacing point-in-time control assessment with near real-time visibility.

Control Effectiveness

Control effectiveness is the measured degree to which a security control actually reduces risk in practice, distinct from control coverage (whether the control is deployed) or control compliance (whether it satisfies a requirement).

Critical or Important Function (DORA)

Under DORA, a critical or important function (CIF) is one whose disruption would materially impair a financial entity's financial performance, operational continuity, or compliance with regulatory obligations, triggering enhanced ICT risk management requirements.

Cyber GRC

Cyber GRC is the discipline of governing cybersecurity, managing cyber risk, and demonstrating compliance across an organization, sitting inside broader enterprise GRC but with cyber-specific frameworks, controls, and reporting.

Cyber Insurance

Cyber insurance is an insurance product that covers financial losses arising from cyber events, typically spanning first-party losses (incident response, business interruption, extortion payments) and third-party liability (claims from affected customers or partners).

Cyber Loss Data / Actuarial Data

Cyber loss data, sometimes called cyber actuarial data, is the empirical record of past cyber events and their financial impacts, used as the foundation for probabilistic modeling of future cyber losses.

Cyber Resilience

Cyber resilience is the ability of an organization to prepare for, absorb, respond to, and recover from cyber events while maintaining essential business operations, extending traditional cybersecurity from prevention into continuity.

Cyber Risk

Cyber risk is the potential for loss or harm arising from cyber events, spanning security, operational, regulatory, reputational, and financial dimensions of enterprise exposure to malicious and accidental cyber-related incidents.

Cyber Risk Appetite Statement

A cyber risk appetite statement is a formal document expressing the level of cyber risk an organization is willing to accept in pursuit of its strategic objectives, quantified in financial terms where possible.

Cyber Risk Quantification (CRQ)

Cyber Risk Quantification (CRQ) is the practice of measuring cyber risk in financial terms, translating security events, controls, and exposure into probabilistic dollar-based loss distributions that boards, CFOs, and risk teams can act on.

Cybersecurity Controls

Cybersecurity controls are the measures used to reduce cyber risk, spanning technical safeguards (encryption, authentication, monitoring), administrative safeguards (policies, training, procedures), and physical safeguards (facility access, hardware security).

Cybersecurity Materiality Threshold

A cybersecurity materiality threshold is the level of impact at which a cyber event becomes material under SEC rules, triggering required public disclosure within four business days under Item 1.05 of Form 8-K.

Data Breach

A data breach is an incident in which sensitive, protected, or confidential information is accessed, disclosed, or acquired by unauthorized parties, typically triggering notification obligations under data protection law in most jurisdictions.

Digital Operational Resilience

Digital operational resilience is the ability of an entity to withstand, absorb, respond to, and recover from disruptions to information and communication technology, a framing used in DORA and adopted broadly in financial-sector regulation.

DORA (Digital Operational Resilience Act)

DORA (Regulation (EU) 2022/2554) is the EU's Digital Operational Resilience Act, imposing comprehensive ICT risk management, incident reporting, resilience testing, and third-party oversight obligations on financial entities operating in the EU.

Enterprise Risk Management (ERM)

Enterprise Risk Management (ERM) is the framework organizations use to identify, assess, prioritize, and manage risks across every business function in an integrated way, rather than treating risk categories in isolated silos.

FAIR (Factor Analysis of Information Risk)

FAIR (Factor Analysis of Information Risk) is a taxonomy and methodology for quantitative information risk analysis that decomposes risk into loss event frequency and probable loss magnitude, each broken into contributing factors.

Financial Exposure Modeling

Financial exposure modeling is the discipline of translating operational, technical, and security data into probabilistic estimates of financial loss, enabling risk decisions to be made in dollar terms rather than qualitative ratings.

Form 8-K Item 1.05

Form 8-K Item 1.05 is the specific SEC disclosure requirement for material cybersecurity incidents, requiring public registrants to file within four business days of determining that an incident is material.

Fourth-Party Risk

Fourth-party risk is the exposure an organization inherits from its vendors' vendors, one layer deeper in the supply chain than traditional third-party risk, becoming increasingly important as cloud and SaaS dependencies proliferate.

GDPR

GDPR (Regulation (EU) 2016/679) is the EU General Data Protection Regulation, governing the processing of personal data of individuals in the EU and imposing significant fines for violations, including data breach notification obligations.

Governance, Risk, and Compliance (GRC)

Governance, Risk, and Compliance (GRC) is the integrated approach to governing an organization, managing enterprise risk, and demonstrating compliance with regulatory and contractual obligations, unifying activities that historically ran as separate functions.

HIPAA

HIPAA (the Health Insurance Portability and Accountability Act) is the US federal law that imposes privacy and security requirements on protected health information (PHI) and the covered entities and business associates that handle it.

Incident Response

Incident response is the structured process an organization uses to detect, contain, investigate, and recover from cyber incidents, minimizing operational and financial impact while preserving evidence for legal, regulatory, and analytical purposes.

Inherent Risk

Inherent risk is the level of risk that exists in the absence of controls, before any mitigations are applied, providing a baseline against which control effectiveness and residual risk can be measured.

ISO 27001

ISO/IEC 27001 is the international standard for information security management systems (ISMS), providing certifiable requirements for how organizations govern, operate, and continually improve their information security programs.

ISO 27005

ISO/IEC 27005 is the international standard providing guidance on information security risk management, supporting implementation of ISO 27001's risk-based requirements and aligning with the general risk management principles in ISO 31000.

Loss Exceedance Curve (LEC)

A Loss Exceedance Curve (LEC) plots the probability that annual losses will exceed each dollar amount, providing a view of the full shape of an organization's cyber exposure including expected losses and tail risk.

Materiality Determination

Materiality determination is the process of deciding whether a cyber incident is material under SEC rules, triggering required Form 8-K Item 1.05 disclosure within four business days of the determination.

Mean Time to Detect (MTTD)

Mean Time to Detect (MTTD) is the average time elapsed between the start of a cyber incident and its detection by the security team, serving as a key operational indicator of detection capability and program effectiveness.

Mean Time to Respond (MTTR)

Mean Time to Respond (MTTR) is the average time between detection of a cyber incident and the completion of defined response actions, serving as an operational indicator of response capability and playbook effectiveness.

MITRE ATT&CK

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics, techniques, and procedures observed in real-world attacks, used broadly by security teams as a shared reference for threat modeling, detection engineering, and program assessment.

Monte Carlo Simulation

Monte Carlo simulation is a computational technique that runs many synthetic scenarios drawn from probability distributions, producing a full distribution of possible outcomes, foundational to modern cyber risk quantification.

NIS2 Directive

The NIS2 Directive (Directive (EU) 2022/2555) is the European Union's updated cybersecurity directive, expanding the scope of covered entities and strengthening cybersecurity risk management, incident reporting, and supervisory obligations across essential and important sectors.

NIST 800-30

NIST Special Publication 800-30 is the US federal guide for conducting information security risk assessments, providing a structured methodology that has been adapted broadly for use in both federal and enterprise environments.

NIST 800-53

NIST Special Publication 800-53 is the US federal catalog of security and privacy controls for information systems and organizations, referenced widely beyond federal use as a comprehensive control library.

NIST CSF 2.0

NIST Cybersecurity Framework 2.0 is the second major version of the NIST Cybersecurity Framework, published in 2024, adding the Govern function and expanding the framework's scope beyond critical infrastructure to organizations of any type and size.

NIST CSF Govern Function

The Govern function is the sixth NIST CSF 2.0 function, establishing the organizational culture, policies, oversight structures, and accountability that underpin the operational cybersecurity functions of Identify, Protect, Detect, Respond, and Recover.

NIST CSF Implementation Tiers

NIST CSF Implementation Tiers describe the sophistication of an organization's cybersecurity risk management practices, ranging from Tier 1 (Partial) through Tier 4 (Adaptive), providing a maturity vocabulary for describing program state.

PCI DSS

PCI DSS (the Payment Card Industry Data Security Standard) is a contractually mandated standard for organizations that store, process, or transmit payment card data, requiring specific technical and organizational controls maintained by the PCI Security Standards Council.

Preventive vs. Detective Controls

Preventive controls aim to stop incidents before they happen, while detective controls identify incidents that occur despite prevention, and both are essential components of a defense-in-depth cyber program.

Ransomware

Ransomware is malicious software that encrypts data or systems and demands payment for restoration, often combined with data theft and extortion threats (double extortion) or additional pressure tactics (triple extortion).

Register of Information (DORA)

The Register of Information under DORA is the mandated catalog of ICT third-party service arrangements that financial entities must maintain and submit to competent authorities, providing sector-wide visibility into ICT dependencies.

Regulation S-K Item 106

Regulation S-K Item 106 requires SEC registrants to disclose their cybersecurity risk management, strategy, and governance in annual filings, including how the board oversees cyber risk and how management assesses and manages material cyber risks.

Residual Risk

Residual risk is the level of risk that remains after all applied controls, mitigations, and treatments have been accounted for, representing the actual exposure an organization carries after its risk management program takes effect.

Return on Security Investment (ROSI)

Return on Security Investment (ROSI) is a metric expressing the financial return generated by security spending, calculated as the quantified risk reduction produced by an investment divided by the cost of that investment.

Risk Appetite

Risk appetite is the amount and type of risk an organization is willing to take in pursuit of its strategic objectives, set by leadership and expressed at the enterprise level as a strategic anchor for risk management decisions.

Risk Assessment

A risk assessment is the structured process of identifying, analyzing, and evaluating risks in an organization or system, producing prioritized information that informs treatment decisions and risk management strategy.

Risk Management Framework

A risk management framework is the structured approach an organization uses to identify, assess, treat, monitor, and communicate risks, providing the process backbone for enterprise and cyber risk management activities.

Risk Register

A risk register is the documented catalog of identified risks, their assessment (likelihood, impact, or quantified exposure), treatment status, ownership, and monitoring information, serving as the operational backbone of enterprise risk management.

Risk Tolerance

Risk tolerance is the operational-level threshold that translates strategic risk appetite into specific quantitative or qualitative limits that management can monitor exposure against and use to trigger escalation.

Scenario Analysis

Scenario analysis in cyber risk is the practice of modeling specific loss events end-to-end, capturing event frequency, severity distribution, and interaction with controls, so exposure can be understood and reported at both scenario and enterprise levels.

SEC Cyber Disclosure Rule

The SEC Cyber Disclosure Rule (adopted July 2023) requires public registrants to disclose material cybersecurity incidents within four business days of determining materiality and to describe cyber risk management and governance in annual filings.

Security Posture

Security posture is the overall state of an organization's cybersecurity defenses at any given moment, reflecting deployed controls, their measured effectiveness, and the resulting current risk exposure.

Security Program Maturity

Security program maturity describes how established, consistent, documented, and effective an organization's cybersecurity program is, typically measured against defined maturity models like NIST CSF Implementation Tiers.

Single Loss Expectancy (SLE)

Single Loss Expectancy (SLE) is the expected financial loss from a single occurrence of a specific risk event, calculated as asset value multiplied by exposure factor, serving as a component of the classical Annualized Loss Expectancy calculation.

SOC 2

SOC 2 is an AICPA reporting framework for service organizations, evaluating controls relevant to security, availability, processing integrity, confidentiality, and privacy, widely used by SaaS and technology vendors as customer-facing assurance.

Supply Chain Attack

A supply chain attack is one in which an adversary compromises an organization indirectly by first attacking a trusted vendor, service provider, or software dependency, then using that access to reach the ultimate target.

Tabletop Exercise

A tabletop exercise is a discussion-based simulation of a cyber incident, walking key stakeholders through a scenario to test response plans, decision-making, and cross-functional coordination without actually affecting live systems.

Third-Party Risk Management (TPRM)

Third-Party Risk Management (TPRM) is the discipline of identifying, assessing, monitoring, and managing risk introduced by vendors, service providers, contractors, and other external parties across the vendor lifecycle.

Threat-Led Penetration Testing (TLPT)

Threat-Led Penetration Testing (TLPT) is intelligence-driven adversarial testing that mimics real threat actor behavior against critical or important functions, required under DORA on a defined cadence for larger financial entities.

Threat Modeling

Threat modeling is the structured practice of identifying threats, attack paths, and appropriate mitigations for a specific system, application, or business process, typically performed during design and updated as systems evolve.

Top-Down Risk Quantification

Top-down risk quantification is an approach that models enterprise cyber exposure by starting from industry-level and portfolio-level loss scenarios, then attributing exposure across the enterprise, complementing bottom-up asset-level analysis.

Value at Risk (VaR)

Value at Risk (VaR) is a financial risk metric expressing the maximum loss expected at a given confidence level over a defined time horizon, originally developed in financial risk management and increasingly applied to cyber through CRQ.

Vendor Risk Assessment

A vendor risk assessment is the structured evaluation of a specific vendor's security, privacy, operational, and compliance posture, producing input for engagement decisions, ongoing monitoring, and contract renewals.

Zero-Day Vulnerability

A zero-day vulnerability is a security flaw unknown to the vendor at the time of exploitation, giving defenders no available patch or public defensive guidance when attacks occur, so exploitation typically precedes coordinated response.

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.