The risk register in most board decks is a grid of colored cells. Red, amber, green, arranged so the reds cluster in the top corner. It looks like rigor. Most of the time it is the opposite.
Here is the problem with the color. Two risks can sit in the same red cell and differ by three orders of magnitude. One is a bad quarter. The other ends the company. The grid gives the board no way to tell them apart, and no way to decide which one to fund first. A color is a category wearing the costume of a measurement.
Meanwhile the CFO on the other side of the table quantifies everything she owns. Currency exposure, expected credit loss, the cost of capital, the sensitivity of the plan to a rate move. She works in dollars and ranges. We hand her a heat map and ask her to allocate real budget against a shade of red. Then we act surprised when the security ask loses to the projects that showed up with a number.
I want to make the case for retiring the color and replacing it with a dollar figure and a range. Not because the number is precise. Because it is decidable. And the method to produce it has existed, in the open, for more than a decade.
A color is a category, not a measurement
The heat map's original sin is that it runs arithmetic on ordinal labels. You rate likelihood 1 to 5, rate impact 1 to 5, multiply, and shade the product. But a 4 on the likelihood axis is not twice a 2. Those numbers are ranks, not quantities, and multiplying ranks produces a figure that looks quantitative and means nothing. Two assessors, same facts, land in different cells, because "high" is a feeling with a border drawn around it.
The risk certifications I came up on teach this ordinal grid first, and for triage it is fine. It sorts a hundred findings into a rough order. What it cannot do is the one thing the board actually needs, which is tell you how much money is on the table and therefore how much is rational to spend defending it. You cannot subtract one shade of red from another. You cannot compare a red to a control's price tag. You cannot roll fifteen reds up into a portfolio exposure the CFO can reason about. The color is a dead end at exactly the moment a decision has to be made.
And the board feels the dead end even when it cannot name it. That is why so many cyber briefings end in courteous nodding and no decision. The directors are not being obtuse. We gave them a category and asked for an allocation.
Risk is frequency times magnitude, and both are estimable
The alternative is old enough to be boring, which is a compliment. Decompose risk into two things you can actually estimate: how often a loss event happens, and how much it costs when it does. Frequency times magnitude. That is the whole spine of it.
The most disciplined version of this is the FAIR model — Factor Analysis of Information Risk, standardized as Open FAIR by The Open Group. FAIR takes "how often" and breaks it down further into how frequently a threat makes contact and how often that contact succeeds, and it takes "how much" and splits it into primary loss — the response, the replacement, the productivity you lose during the outage — and secondary loss — the fines, the judgments, the customer churn, the reputational drag that arrives later. You do not have to adopt the full taxonomy to get the benefit. You have to adopt the discipline of naming the two factors and estimating each in dollars and in events per year.
The objection I hear immediately is that we do not have the data. We have more than we admit. The Verizon DBIR gives defensible base rates for how often given attack types actually occur. The annual breach-cost studies everyone cites give an industry starting point for magnitude — useful as a prior to adjust from, never a number to paste in, because your environment is not the average. Your own incident history, your claims history, and your control coverage all move the estimate off that prior. And where hard data runs out, calibrated estimation from the people who know the system is a legitimate input, not a cop-out. FAIR is built to reason under uncertainty. That is the point of it, not a hole in it.
If you learned the older annualized-loss-expectancy formula — single loss expectancy times annual rate of occurrence — this is its grown-up successor. The old version asked for single-point guesses and hid all the uncertainty inside them, which is how quantitative risk earned a reputation for false precision it never quite shook. The fix is not to abandon the dollars. It is to stop pretending you know them to the decimal.
Publish a range, not a point estimate
Which brings me to the most important discipline in the whole method, and the one that makes it honest: you do not report a number. You report a range, with a confidence attached to it.
Estimate frequency as a band — this event happens somewhere between once every fifteen years and once every three. Estimate magnitude as a band — if it lands, the loss falls somewhere between a manageable seven figures and a genuinely bad eight. Run those two distributions together, which a Monte Carlo simulation on a laptop does in seconds, and out comes not a point but a curve: a 90 percent chance the annual loss exposure from this one register line falls between here and there, with a long tail you can finally see and talk about.
Those illustrative bands are exactly that — illustrative. The real values are yours to derive. But look at what the shape buys you. The tail is the part that ends companies, and the red cell hid it completely. A range shows the board the expected cost and the catastrophic cost in one picture. And it lets you say the single most credible sentence a security leader can offer a finance audience: here is our best estimate, here is how uncertain we are about it, and here is what would tighten the range. A confident fake number is worse than an honest wide one. The range is how you refuse to fake it.
The number pays for itself at two tables
A dollar figure earns its keep in two conversations the color could never enter.
The first is the controls roadmap. Once each top register line carries an annualized loss exposure, a proposed control stops being "best practice we really should do" and becomes a measurable reduction in that exposure. You model the line with the control and without it, take the difference, and set it against what the control costs to buy and to run. Now the roadmap ranks itself by dollars of exposure reduced per dollar spent, and the item that shrinks a large tail cheaply beats the item that polishes a risk that was never going to cost much. This is where security stops arguing from fear and starts arguing from return — which is the argument the budget is actually decided on. I have written before that a mature security program is a revenue asset. This is the same move pointed inward, at your own spend.
The second table is the cyber-insurance renewal, and in a regulated shop it is not optional. Here is the thing worth internalizing: the underwriter is already quantifying your risk in dollars. That is the entire business they are in. When you arrive with a heat map and they arrive with an actuarial model, you are negotiating the transfer of your own risk from a position of not having done the homework. Put your loss distribution next to the policy and the questions get sharp. Does the coverage limit actually reach into the tail, or does it stop short of the loss that would matter? Is the retention you are carrying a number you chose, or a number you accepted? Are you paying premium to transfer a loss you could comfortably absorb — which is money set on fire? The distribution turns the renewal from a form you fill out into a decision you make.
I am not your actuary or your controller, and the accounting for all of this — how retained cyber risk resembles a reserve, where the premium sits in the plan — belongs to the people who own the books. But the shape is not mysterious. Expected loss is a cost. Transferring it has a price. Reducing it has a price. Once all three are in the same unit, the board can do the thing boards exist to do, which is weigh them against each other instead of against a color.
What the dollar figure is not
Two honest cautions, because this method gets oversold and then dismissed on the backlash.
It is not a prediction. The curve does not promise what next year holds. It describes what you believe about a distribution given today's information, so you can act like an adult about uncertainty instead of burying it under a color. And it is not a data-science program. You do not need a modeling team or a platform. You need the top five lines of your register, defensible ranges, and a spreadsheet. Quantify the material few, leave the trivial many on the ordinal scale where they belong, and do not let a demand for perfect inputs stall a method whose entire purpose is to work without them.
The regulatory current is running toward the number regardless. The SEC's four-day rule requires disclosing a cyber incident once you have judged it material — and you do not judge materiality against a color, you judge it in dollars, which means the quantification you skipped in calm times is the quantification you are scrambling to do against a clock. Europe's DORA pushes financial entities toward demonstrable operational-risk management and tested resilience, not narrative assurance. And the FFIEC and GLBA expectations that examiners hold fintech to have always asked for a risk assessment that ranks and reasons, not a wall of reds. At a company that sits behind more than 1,500 financial institutions, I treat the examiner's view as the floor, not the ceiling. The dollar figure is not gold-plating. It is increasingly the expected form of the answer.
Start where the money is
If you do one thing to your risk register this quarter, do this.
- Retire the color for the top lines. Take the five risks at the top of the register and stop shading them. They are the ones worth the work.
- Estimate two factors, in ranges. For each, a frequency band and a magnitude band — events per year and dollars — sourced from your data where it exists and calibrated judgment where it does not.
- Report the curve, not a point. Give the board a 90 percent loss-exposure range with the tail visible, and say out loud how uncertain you are.
- Take the number to both tables. Rank the controls roadmap by exposure reduced per dollar, and bring the distribution to the insurance renewal instead of the questionnaire.
I would like to hear from the people who have actually tried to move an organization off the heat map, because it is as much a political change as a mathematical one. Where did it stick, and where did the reds win anyway? If you have run FAIR-style quantification in front of a board or an underwriter, tell me what landed and what got waved off. I will answer every reply.
