What a Cyber Risk Number Cannot Tell You
Arguments for quantifying cyber risk are abundant and mostly sound. What gets published far less often is a plain account of what a modeled figure does not tell you, which is unfortunate, because stating the limits is more persuasive to a skeptical audience than another argument for the method. We build these models. What follows is what they cannot do, written plainly, followed by what remains useful once those limits are accepted.