Bottom-Up Risk Quantification

Bottom-up risk quantification is an approach that builds enterprise-level cyber exposure figures by starting from asset-level, control-level, and system-specific data, then aggregating detail into portfolio and enterprise views.

How Bottom-Up Works

A bottom-up model begins with the individual components of the environment: specific assets, applications, business processes, and the controls protecting each. Loss scenarios are modeled at that granular level. Aggregation produces the portfolio and enterprise views used for reporting.

The strength of the approach is precision. Because scenarios are grounded in specific assets and controls, the resulting exposure figures respond meaningfully to real changes: adding an MFA control, retiring a system, onboarding a new vendor.

Bottom-Up vs. Top-Down

Top-down risk quantification starts from enterprise-level scenarios and works downward. Bottom-up starts from asset detail and works upward. Neither is inherently better. They answer different questions and are typically used together.

Top-down is better for board-level portfolio conversations. Bottom-up is better for prioritizing specific control investments and defending them with numbers grounded in the actual environment.

When Bottom-Up Is Required

Certain use cases require the granularity only bottom-up provides. Justifying investment in a specific control, comparing security posture across business units, or answering "what would change if we implemented X" are all difficult without the asset-level model.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.