Cyber Risk Assessment: Moving Past the ‘‘Heat Map Trap’’

Vince Dasta, Protiviti Associate Director

Given the limits on time, attention and resources with which every cyber team must contend, risk assessment plays a critical role in helping set priorities and decide between options. Unfortunately, most cybersecurity professionals rely on ‘‘pseudo-quantitative’’ methods, in which risks, benefits and other factors are given labels, colors or ratings. These approaches have the veneer of objectivity but are actually highly subjective.

In this article, Protiviti Associate Director Vince Dasta offers an alternative clear path to implementing a risk assessment program that is authentically quantitative and in which confidence is justified.

