No More Guessing: How to Build Cyber Risk Scenarios for Actionable Business Insights
Context
No More Guessing: How to Build Cyber Risk Scenarios for Actionable Business Insights
Context
In Part 1 of this Cyber Risk Quantification (CRQ) blog series, we tackled the cultural and organizational objections that often derail efforts before they even begin.
With business sponsorship now secured, it’s time to shift focus: from getting buy-in to building scenarios that deliver meaningful insights which hold up under executive scrutiny.

Think of this blog as your “how-to” guide for designing risk scenarios that deliver value and not just numbers.
It’s not about being perfect. It’s about setting up your scenario for clarity, alignment, and actionable insight. The kind executives and security teams can both get behind.
Successful quantification depends on clarity, consistency, and a shared language between risk, security, and business teams. Before diving into formulas or models, it’s critical to ask the right questions.
So, how do you build a scenario that actually works?
Whether you’re focusing on ransomware, insider threats, or third-party risk, every good scenario starts by answering a few foundational questions.
These aren’t just checkboxes, they shape how credible, useful, and actionable your risk estimates will be.
Let’s walk through them.
- What threat are you focused on?
- Who are the threat actors?
- What’s the asset at risk and what happens if it’s hit (impact)?
- What are the key controls?
- What would the financial impact be ? What’s the range?
- What’s the likelihood of the attack succeeding?
- What kind of distribution fits your impact and likelihood estimates?
- How will you calibrate as you go?
These steps are summarized in the figure below.

Key steps to build Cyber risk scenarios for actionable business insights
When you can confidently answer the above questions, you are then in a place to start. You won’t get it perfect the first time (or maybe the second or third time), but the plan is to get you started so you can build the muscle for this exercise.
So, let’s start.
1. What Threat(s) Are You Focused On?
At this stage, you’re not modeling anything yet. You’re framing the threat in business terms so it can be scoped, prioritized, and quantified later.
Start by looking at the cyber threat landscape that’s specific to your industry, organization size, and maturity. Different industries face different threat profiles. Financial services may be more targeted by fraud and data theft, while healthcare often contends with ransomware due to high-value personal data and limited downtime tolerance.
Most organizations already have a short list of key cyber threats they worry about. These could include:
- Distributed Denial of Service (DDoS)
- Ransomware
- Insider threats (malicious or accidental)
But identifying the threat is only the beginning. You also need to consider its relevance and residual risk to your organization. For instance:
- DDoS might be a plausible threat, but your mitigation controls (e.g., cloud-based scrubbing, rate limiting) may reduce the residual risk to Medium.
- Ransomware, however, might remain a High residual risk due to insufficient backups, vulnerable endpoints, or legacy systems.
The most important step is to link the threat to your organization’s key objectives:
- A DDoS attack could take your website or APIs offline, disrupting customer access and eroding trust.
- A ransomware incident could compromise sensitive data, triggering legal, regulatory, and reputational fallout — potentially causing customer loss or downtime in core operations.

2. Who Are the Threat Actors?
Once you’ve identified the threat you’re focusing on, say ransomware the next step is to identify which type of threat actors are most likely to carry it out against your organization.
Start broad. Threat actors can generally be grouped into categories like below. Use the table below as your starting point and modify as you see fit.

Overview of Threat Actors, Motivations and Skillset levels
The goal is to understand who you’re modeling the scenario around, and how capable and motivated they are.
Your Cyber Threat Intelligence (CTI) team is critical at this stage. They can help:
- Identify the most likely threat actors targeting your industry, geography, or organization
- Map out Tactics, Techniques & Procedures (TTPs) those actors are known to use
- Inform what controls are relevant and how those controls hold up against specific actor capabilities
Why does this matter?
Because who you think you’re defending against directly influences your assumptions about likelihood, control effectiveness, and impact.
In other words: If you’re modeling against a nation state, your control assumptions and potential impact will likely be different than if you’re modeling a lone insider or script kiddie.
3. Assets, Impact, and Timeframe
Now that you’ve identified the threat and the threat actor, it’s time to define the asset, the impact, and the timeframe, three essential building blocks of any useful risk scenario.
Assets
Start by identifying which asset is targeted in the scenario. What is the attacker going after?
Common examples include:
- A customer-facing web application
- A mail server
- A VPN concentrator or firewall
- An internal database or file share
- Public APIs exposed on the internet
Keep it simple. In early stages, it’s best to pick one primary asset so you can stay focused and reduce complexity.
Impacts
Next, think about what happens if that asset is compromised. What’s the business concern?
Is it:
- Confidentiality: Loss or exposure of sensitive data?
- Integrity: Unauthorized modification of critical data or systems?
- Availability: A disruption in service or downtime?
Again, you could explore all three, but it helps to focus on one impact dimension. That makes the scenario easier to explain, quantify, and refine.
Timeframe
Time matters a lot. Are you modeling the risk over the next:
- 12 months?
- 2 to 5 years?
- Or some other horizon?
The timeframe directly impacts your estimate of likelihood. A ransomware attack in the next year might feel plausible — but over five years, the same scenario might feel almost inevitable.
Be realistic. Start with a 12-month window unless there’s a compelling reason to go broader.
4. What Controls Exist, and Their Effectiveness?
Controls are where your scenario starts becoming real. Once you’ve picked the threat, actor, asset, and impact, the next question is: What’s stopping the attack from succeeding or helping you respond if it does?
Controls don’t just reduce risk, they shape how your risk scenario behaves. Think of them as levers that influence the likelihood and/or impact of an event.
Start by identifying key controls
You don’t need an exhaustive list. Focus on the key controls that relate to the specific threat scenario. Ask:
- What do we have in place to prevent the attack?
- What do we have to detect it if it happens?
- What do we have to respond and recover?
This simple classification: Prevent / Detect / Respond is incredibly useful. It helps bring structure to what can otherwise feel like a control soup. For example, if your scenario is ransomware hitting your file servers:
- Prevent: Endpoint protection, email filtering, MFA
- Detect: File integrity monitoring, unusual activity alerts
- Respond: Backups, incident response playbooks, immutable storage
Having a clear list of relevant controls also makes your scenario easier to explain to both security and business teams. It sets you up to later adjust likelihood or impact based on control strength, but you don’t need to solve for that now.
Controls are the bridge between theoretical risk and real-world readiness. Identify them early, and your scenario will feel grounded, not hypothetical.
What about measuring control effectiveness? Don’t worry about it too much (just yet)
At this stage, you don’t need to model every control’s maturity level or map them to some external benchmark. That can come later. For now, it’s enough to identify the controls and categorize them.
That said, if you want you can do a simple control assessment to move forward. But you do need to have a rough sense of how well the controls work.
At a minimum, consider:
- Is the control deployed across the right systems?
- Is it actively maintained and monitored?
- Do we have evidence that it’s working (e.g., alerting, blocking, testing)?
- Have attackers been known to bypass it?
You’re not trying to score every control. You’re trying to understand whether it’s strong enough to matter in this scenario. For example:
If ransomware is your concern, but your backups haven’t been tested in a year — that’s a red flag.
This rough assessment of effectiveness will help you later when estimating the likelihood of a successful attack. You don’t need perfect data. You just need enough insight to make a reasoned judgment.
Here are five places to start looking at making this reasoned judgment about your controls effectiveness.
- Security Experts in the Organization
Your internal security team is often your best source. They know the environment, understand the context, and can provide expert judgment based on real-world experience. Their professional view is essential — context is king.
2. Security Findings
Use results from existing security assessments, such as:
- Penetration tests
- Red Team exercises
- Vulnerability scans
- Source code reviews
Red Team and penetration testing findings are high-fidelity indicators as they often show clear evidence of control gaps. In contrast, raw vulnerability scan results usually need to be validated before drawing conclusions.
3. Incidents, Near Misses, and Risk Registers
Past incidents can highlight which controls failed (or succeeded). For example:
If your scenario involves insider threats, and you’ve had several such incidents in the last 12 months, that data should shape how you assess control effectiveness and scenario likelihood.
Don’t overlook risk registers or issue-tracking systems because they often contain valuable breadcrumbs about control weaknesses.
4. Automated Security Testing (If Available)
If your organization uses tools to simulate attacks (e.g. Breach & Attack Simulation tools), these can:
- Recreate real-world threats in a safe environment
- Run repeatable, automated tests
- Test control resilience under variations of the same attack
These tools aren’t cheap but if available, they’re gold for assessing how specific controls behave in the wild.
5. Pulling it Together
You’re not building a full audit, you’re assembling just enough evidence to inform your risk scenario. Look for consistency across sources. If different inputs all point to weak detection or prevention capabilities, that’s a strong signal.

5. What is The Financial Impact of This Scenario?
Once you’ve defined the threat, actor, asset, and timeframe, and controls it’s time to tackle a critical question:
If this scenario happens, how bad is it financially?
To answer that, you’ll need to bring in perspectives beyond security. Here’s how to get started.
Talk to the Business
Start by engaging the part of the business that would feel the impact most — they’re best placed to articulate what disruption would cost them.
- Security teams can provide context and examples from similar incidents.
- Business understands value (customer loss, lost sales, downtime costs, etc.).
Consult Your Cyber Insurer (If You Have One)
Cyber insurers often have access to a wealth of breach and incident data across industries and organizations of similar size. They can:
- Suggest financial impact ranges based on real-world cases
- Provide insight into areas organizations typically underestimate (e.g. legal fallout, PR costs)
Look at Historical Data (Yours and Others’)
Work with your security or risk teams to collect examples of similar past incidents, ideally:
- From your own organization
- Or from peers in the same industry and of similar size
- Verizon’s Data Breach Investigations Reports (DBIR) are a great starting point
This adds realism and anchors your assumptions in actual data.
Model Impact as a Range, Not a Single Number
Avoid single point estimates. I cannot stress this enough. Avoid single point estimates. They create a false sense of precision. What you want is to be accurate as opposed to precise. Instead, provide a range. This allows for uncertainty and builds trust in the scenario.
Additionally, a more structured approach is to break down the types of loss, for example:


6. What’s The likelihood of This Scenario Happening?
Now we can move on to the likelihood of the chosen scenario happening.
How likely is it that this will happen in the timeframe you’re considering?
This is often the hardest part, and where people guess too conservatively. You don’t need perfect data. But you do need informed judgment, based on input from multiple sources.
Use Expert Judgement
- Security Operations (SOC), Threat Intel (CTI), and IR teams know what’s happening in real-time.
- Risk and Compliance teams can weigh in on how likely a threat actor is to succeed, based on known control gaps.
Then add external views:
- Cyber insurers and industry ISACs often provide threat likelihood ratings based on observed data.
- Red team and penetration testing results give high-fidelity evidence of how easily certain attack paths could be exploited.
Review Real-World Intelligence and Incident Data
Use open-source threat intelligence and historical incidents to gauge how common your scenario is:
- How many similar organizations have experienced this type of attack in the past year?
- How often do attackers with similar motives and capability target assets like yours?
CTI teams or services like Mandiant, Microsoft DART, or industry-specific ISACs can help here.
Factor in Control Effectiveness
You’ve already assessed controls. Use that to adjust your likelihood:
- If controls are effective, downgrade the likelihood.
- If controls are weak or bypassed in testing, upgrade the likelihood.
For example: You rated ransomware as a threat, and red teamers were able to easily access shared drives without triggering alerts → Likelihood increases.

7. What Probability Distribution Fits Your Impact and Likelihood Estimates?
When assessing Cyber risks, it’s crucial to model both the potential impact of incidents and the likelihood of their occurrence. Probability distributions help represent the uncertainty in these estimates. Here’s how to approach selecting appropriate distributions for each aspect.
Modeling Impact
Cyber incidents can lead to a wide range of financial losses. To capture this variability, consider the following distributions:

- Triangular Distribution: This simple model uses three estimates which are: minimum, most likely, and maximum values to define a range of possible outcomes. It’s useful when data is scarce, and expert judgment is the primary source of information.
- PERT (Program Evaluation and Review Technique) Distribution: Similar to the triangular distribution but gives more weight to the most likely estimate, resulting in a smoother curve. It’s beneficial when you have a reasonable level of confidence in your estimates and want to reduce the influence of extreme values.
- Lognormal Distribution: This distribution is appropriate when losses are strictly positive and can vary widely, with a small chance of very large losses. It’s commonly used in financial modeling to represent scenarios where most losses are moderate, but there’s a possibility of significant outliers.
Modeling Likelihood
Understanding how often cyber incidents might occur is equally important. Depending on the nature of the events, different distributions can be applied:

- Bernoulli Distribution: Ideal for modeling binary outcomes, whether a specific event happens or not within a set timeframe. For example, assessing the chance of a successful phishing attack in a given month.
- Binomial Distribution: Useful when evaluating the number of times an event occurs over multiple independent trials. For instance, determining how many employees might click on a phishing link out of a group of 100.
- Poisson Distribution: Applicable for modeling the number of events happening over a continuous interval, such as the number of intrusion attempts per week. It’s particularly useful when events occur independently and at a constant average rate.
Practical Tips to Choose Distribution:
- Start Simple: If you’re new to this, begin with the triangular or PERT distribution for impact and the Bernoulli distribution for likelihood. These are straightforward and require minimal data.
- Use Expert Judgment: In the absence of extensive data, rely on the insights of experienced professionals within your organization to estimate parameters.
- Iterate and Refine: As you gather more data and experience, consider transitioning to more complex distributions like the lognormal or Poisson to better capture the nuances of your risk landscape.
Remember, the goal is to create a model that reflects the realities of your organization’s Cyber risk profile as accurately as possible. By selecting appropriate distributions, you can better inform risk management decisions and resource allocation.
The exact manner in which you can create and sample these probability distributions is beyond the scope of this blog and will be discussed in another one in more detail.
8. How Will You Calibrate As You Go?
Why is Model Calibration Required?
Model calibration ensures that the probabilities and loss estimates produced by your cyber CRQ models align with real-world observations and historical data as much as possible.
Without it, your model outputs might be consistently over- or underestimating risk, leading to poor decision-making. Essentially, it makes your model’s predictions more trustworthy and reliable.
How to do Model Calibration in CRQ?
Calibrating estimates from different experts can feel like a diplomatic negotiation. ‘Your 10% is too high!’ ‘No, your 50% is insane!’ But hey, at least it’s not boring’.
But seriously, here are some ways you can deal with it.
- Calibrated Expert Elicitation Techniques:
- Structured Interviews: Conduct structured interviews with cybersecurity experts and business stakeholders. Use open-ended questions initially to gather broad perspectives, then progressively narrow the focus to elicit min and max ranges for specific loss scenarios or likelihoods.
- Equivalent Bet Method: Present experts with a choice between their estimated range and a hypothetical bet with known probabilities. This helps them reflect on their confidence level in their range. For example, “Are you at least 90% confident that the actual loss will fall within your $X to $Y range? If not, would you prefer a 90% chance of winning a prize if the actual loss is outside that range?”
2. Feedback and Tools:
- Feedback Mechanisms: If possible, provide experts with feedback on the accuracy of their past estimates (if historical data becomes available). This helps them learn and improve their calibration over time.
- Use Calibration Tools: Utilize freely available calibration training tools (e.g., the Open Philanthropy Project’s calibration tool) to help experts practice and understand their own biases.
3. Structured Scenario Analysis:
- Consider Different Levels of Severity: For each scenario, explore different levels of severity to inform the min and max of the loss magnitude. For example, a ransomware attack could have a minimum impact of recovery costs and a maximum impact including business interruption, reputational damage, and regulatory fines.
- Factor in Controls: Explicitly consider the impact of existing and planned security controls when estimating the likelihood and potential impact within the scenarios. This helps to make the ranges more realistic given the organization’s security posture.
4. Documenting Assumptions and Rationale:
- Transparency is Key: Clearly document the assumptions and the reasoning behind the min and max ranges provided by experts. This ensures that the estimates are auditable and can be revisited as new information emerges.
- Identify Key Drivers: Understand and document the key factors that could push the outcome towards the minimum or the maximum of the range.
5. Iterative Refinement:
- Review and Challenge: Subject the initial min and max ranges to review and challenge by other experts or stakeholders with different perspectives. This can help identify overly narrow or wide ranges.
- Update Regularly: Cyber risks evolve, so it’s crucial to revisit and update the calibrated ranges periodically based on new threat intelligence, vulnerability disclosures, and changes in the organization’s environment.
Example of Calibrated Ranges:
Instead of a vague range like “$1 million to $5 million” for a data breach, a calibrated approach might yield:
- Minimum Loss ($1 million): Represents a scenario where the breach is quickly contained, affects a small number of non-sensitive records, and incurs minimal regulatory fines and legal fees due to proactive disclosure and strong incident response. (Confidence: 80% that the loss will be at least this much).
- Maximum Loss ($7 million): Represents a scenario where the breach persists for an extended period, involves a large number of highly sensitive records, leads to significant business disruption, substantial regulatory fines, protracted legal battles, and a significant loss of customer trust and reputational damage. (Confidence: 85% that the loss will not exceed this amount).
By employing these methods, CRQ can move beyond simple guesswork and provide more reliable and actionable insights for decision-making.
9. Call To Action
If you’ve made it this far, you’re already ahead of the curve. CRQ doesn’t have to be overwhelming, Start with baby steps and you’ll get there. Your next steps are:
- Select a Threat and associated Threat actors: For example, the threat could be DDOS or ransomware. You get to choose and then the threat actors: are they nation states , hacktivists? And what is their capability?
- Select a Pilot Asset: Choose a critical asset . e.g., a web application or database.
- Define Impact and Timeframe Scenarios: Determine potential consequences of Cyber incidents affecting this asset, focusing on confidentiality, integrity, and availability. Don’t forget to set a timeframe in which the attack could happen.
- Assess Control Effectiveness: Evaluate existing security measures using data from past incidents, audits, and expert insights. It doesn’t need to be perfect.
- Estimate Likelihood and Impact: Use appropriate probability distributions to model potential risks quantitatively. Note. If you don’t know how to do the “modelling” part, no problem I’ve got a blog for that too! ;)
- Make Informed Decisions: Leverage your findings to prioritize risk mitigation strategies and communicate risks to stakeholders
The goal isn’t perfection but progress. Each step you take enhances your organization’s resilience and decision-making capabilities.

메타데이터
- post_id
- cf3c63ea4a20
- slug
- no-more-guessing-how-to-build-cyber-risk-scenarios-for-actionable-business-insights-cf3c63ea4a20
- url
- https://medium.com/@mpmab1/no-more-guessing-how-to-build-cyber-risk-scenarios-for-actionable-business-insights-cf3c63ea4a20
- canonical_url
- https://medium.com/@mpmab1/no-more-guessing-how-to-build-cyber-risk-scenarios-for-actionable-business-insights-cf3c63ea4a20
- author_url
- https://medium.com/@mpmab1
- status
- ok
- fetched_at
- 2026-08-18 13:38:23