← Back to list

From Heatmaps to Expected Loss: Why High/Medium/ Low Is Failing Boards

In my opinion, the most dangerous thing in cybersecurity isn’t a zero‑day vulnerability, it’s a heatmap….

Rafat Yazdani · 2026-02-06 20:12 · 0 claps · 4.9 min read
#cyber-risk-quantification #cybersecurity-strategy #cyber-risk-management #financial-modeling #cybersecurity-metrics
Open on Medium ↗
Wiki topics: BIZ · Business Strategy ECO · Economy · General 🔒 · Cybersecurity

From Heatmaps to Expected Loss: Why High/Medium/ Low Is Failing Boards

In my opinion, the most dangerous thing in cybersecurity isn’t a zero‑day vulnerability, it’s a heatmap….

That might sound exaggerated, but spend enough time in risk reviews and you start to believe it. For years, organizations out there have relied on cybersecurity risk heatmaps based on colors and severities.

Red, yellow, green. High, medium, low.

They look clean, and they feel structured. And they give the illusion that we understand risk by identifying the top ones, reporting on them, and then calling it a day in the life of risk management.

But when security leaders walk into a boardroom with these charts, they soon realize something uncomfortable.

These heatmaps don’t help in making real decisions and traditional risk scoring is failing at the exact moment organizations need clarity the most.

The Problem with High/Medium/Low

At first glance, ordinal risk scales feel reasonable. You assess likelihood, assess impact, combine the two, and prioritize.

In practice though, this calculation collapses useful information.

Here’s what that means in practice:

  • A “High” likelihood could be 10% or 70% — a 7x difference
  • A “High” impact could be $1M or $100M — a 100x difference
  • A “Medium” risk could be more dangerous than a “High” one depending on the combination

When you multiply undefined values, the math becomes meaningless.

But once you provide some basic variables, for example:

  • If “High likelihood” = 10% and “High impact” = $1M then expected loss = $100K.
  • If “High likelihood” = 70% and “High impact” = $100M then expected loss = $70M.

Both appear as the same red box on a heatmap — but the second one is 700x more severe.

We end up throwing wildly varied risks into the same bucket and then act surprised when prioritization breaks down.

This isn’t a theoretical issue by any means. It shows up immediately in real decision-making.

Why “High” Risks Quietly Get Ignored

Imagine a risk register with 25 “High” risks. Every one of them is urgent, they all need funding, and they all demand attention.

So leaders do what humans always do when overwhelmed, and end up tuning these out. After all, when everything is urgent, nothing is urgent.

So we then see decisions start getting made based on other subjective factors like recency, volume, and politics — but not exposure.

This is why boards sometimes look disengaged during security updates. Not because of apathy, but because they’re being handed information that doesn’t support real tradeoffs.

When Heatmaps Failed

If you want a case study in why High/Medium/Low collapses under pressure, look no further than Equifax.

Before the fateful breach, Equifax’s internal risk register flagged multiple issues as “High,” including patching delays and unscanned systems. But because everything serious was labeled “High,” nothing stood out.

Ordinal scoring flattened the landscape.

A vulnerability that would lead to a catastrophic, company‑defining breach sat in the same bucket as routine operational issues.

More specifically, Apache Struts vulnerability (one of many “High” risks) went unpatched.

And the result? One of the most costly breaches in history, including over $1.4B in total impact, multi-year regulatory scrutiny, and long-term reputational damage. Yikes.

The heatmap approach here didn’t fail because it was inaccurate; it failed because the truly fatal risks were indistinguishable.

When Quantification Worked

On the other end of the spectrum, one of the clearest success stories comes from Capital One, a company that has been transparent about how it approaches cloud‑native risk.

Capital One has spoken at AWS re:Invent, RSA, and other forums about how the organization has moved away from traditional heatmaps and toward quantitative, financially grounded risk modeling.

Instead of labeling risks as High/Medium/Low, Capital One began modeling the likelihood of cloud misconfigurations, the financial impact of identity failures, the expected loss associated with architectural weaknesses, and the ROI of specific security investments. They tied these models directly into their cloud governance and engineering workflows.

Once they quantified risk in dollars instead of colors, several things became immediately clear:

  • Some “High” risks were actually low‑exposure issues
  • Some “Medium” risks carried outsized financial impact
  • Identity‑related misconfigurations had far higher expected loss than previously assumed
  • Certain controls delivered dramatically better risk‑reduction‑per‑dollar than others

Capital One has publicly stated that quantification helped them prioritize cloud misconfiguration risks based on expected loss, justify major IAM investments with clear financial ROI, communicate exposure to executives in a language the business already uses, and allocate budget to the highest‑impact issues instead of the loudest ones.

In other words, quantification didn’t just change the numbers - it changed the decisions.

Risk Is Not A Color. It’s money over time

Executives don’t think in red or yellow. They think in dollars — and how much of those dollars might leave the company!

Instead of asking, “Is this risk High or Medium?”

They’re asking, “What is the expected financial loss if we do nothing?”

Expected loss combines two things executives already understand:

  • How often something might occur
  • How costly it would be if it does

Not with perfect precision, but at least there is some defensible estimation.

Even rough estimates are better than abstract labels.

A Simple Example

Consider two risks:

a) Risk A: critical identity provider outage that happens once every 10 years, causes $10M in damage

b) Risk B: A recurring cloud misconfiguration that exposes non-sensitive data that happens every year, causes $1M in damage

On a heatmap, both show up as “High impact.”

But mathematically, they’re identical:

  • Risk A: $10M loss × 0.1 annual probability = $1M expected loss per year
  • Risk B: $1M loss × 1.0 annual probability = $1M expected loss per year

Same expected loss but as you can assume, very different risk profiles. Now you can ask more meaningfully:

  • Which risk is cheaper to reduce?
  • Which investment lowers expected loss more efficiently?
  • Where do we get the most reduction per dollar spent?

Not guesswork — now we’re working towards thoughtful prioritization.

Why Boards Respond Differently When You Talk This Way

Boards already make decisions like these when they evaluate insurance exposure, capital investments, operational risk, and market volatility.

And yet, cybersecurity is one of the last areas where we still rely on vague scoring and hope it’s somehow persuasive.

When cybersecurity risk is re-framed as financial exposure, a lot can change.

Cybersecurity stops sounding abstract, tradeoffs become explicit, and budget conversations become rational instead of emotional.

You’re no longer asking for money because the risk is “high.”

You’re showing what happens financially if nothing changes and what improves if it improves.

Heatmaps Aren’t Pointless But They’re Simply Not Enough

Sure, heatmaps can be fine as a visual aid and for reporting. And yet, they’re poor decision engines.

As environments become more complex with cloud-native architectures, AI-driven systems, third-party dependencies and even more future changes, the cost of vague prioritization will exponentially grow as well.

Security leaders don’t need more colors or charts. They need better signal.

Expected loss won’t eliminate uncertainty, but it gives leaders a more objective way to rationalize security decisions.

Frameworks like FAIR have already rejected High/Medium/Low scales for years in favor of quantitative models. Even regulators are pushing for more defensible, financially grounded disclosures.

The industry is moving fast without a doubt. The real question is whether security teams will keep up or keep reporting colors while the business absorbs the losses.

After all, colors are great for dashboards. Dollars are better for decisions.


메타데이터
post_id
4ef2dcdfb2dd
slug
from-heatmaps-to-expected-loss-why-high-medium-low-is-failing-boards-4ef2dcdfb2dd
url
https://medium.com/@rafat.yazdani/from-heatmaps-to-expected-loss-why-high-medium-low-is-failing-boards-4ef2dcdfb2dd
canonical_url
https://medium.com/@rafat.yazdani/from-heatmaps-to-expected-loss-why-high-medium-low-is-failing-boards-4ef2dcdfb2dd
author_url
https://medium.com/@rafat.yazdani
status
ok
fetched_at
2026-07-23 18:37:56