“Brilliantly written for those with little or no background in quantitative risk measurement, and valuable to those with years of experience. Required reading.”
Jack Jones, creator of FAIR
“He makes even quantitative concepts accessible to every reader, with case examples and step-by-step procedures. I highly recommend his book.”
Douglas Hubbard, author and measurement expert
“Where do I begin with measuring cyber risk? This is the definitive starting point for anyone serious about becoming a cybersecurity risk modeler.”
Richard Seiersen, author and Chief Risk Technology Officer, Qualys
“A recurring ‘Yeah, but how?’ dominates conversations on cyber risk quantification. Tony strikes the perfect balance of what you need to know and what you need to do.”
Wade Baker, Partner, Cyentia Institute
“This is the book I’ve been waiting for, a real A-to-Z guide to cybersecurity risk forecasting for both newcomers and seasoned professionals.”
Rick Howard, cybersecurity educator and author
“A stepping stone away from risk matrices and heatmaps. If you were wondering where to start your journey into quantified risk, this is it.”
Jay Jacobs, Co-founder and Chief Data Scientist, Empirical Security
“Complex ideas made approachable for readers at any experience level, packed with sage advice and hard-learned lessons. Highly recommended for all risk practitioners.”
Lisa R. Young, ISC2 Board of Directors, former President of SIRA
“Empowers new and experienced professionals to level up their risk communication to the board like no one else has. We can finally eliminate the stoplight technique.”
Patti Degnan, Operating Partner, Andreessen Horowitz
“Quantitative risk analysis isn’t the future of GRC engineering, it’s the foundation. This book is the baseline. Start here.”
Ayoub Fandi, GRC Engineer Newsletter
“You don’t just read this book; you do it. It belongs on every risk team’s onboarding list.”
Adrienne Allen, Security, Risk and Compliance Leader
What you’ll learn
It’s a beginner’s guide to cyber risk quantification that turns vague heatmaps into scenarios and numbers you can act on. Along the way, it takes apart the myths that keep most teams from starting.

Apress, March 2026
449 pages. Paperback and ebook.
Figure 7-1, Chapter 7. The progression of a vague worry into a quantified assessment. Tap to enlarge.
From vague to credible
Turn a vague worry into a scenario specific enough to measure, then into dollar ranges a decision-maker can use.
Myth
You need a mountain of data.
You need less than you think. Most analyses start from three sources you already have: published research, your own records, and the people who run the systems.
Solving the data problem
Data is where most analysts get stuck, so the book gives it six chapters: where to find it, how to vet it, and how to blend outside research, your own records, and expert judgment into one estimate.
Myth
You need actuarial tables.
Base rates from published research and calibrated estimates from your own experts give you a defensible first answer, and you update it as data comes in.
Practical methods
Use Excel and Monte Carlo simulation to quantify cyber risk without advanced math. The workbooks are free.
Myth
You need an army of data scientists.
One analyst with a spreadsheet can run every method in the book, Monte Carlo simulation included, with basic Excel formulas and no code.
Executive communication
Learn to present risk results so executives can follow them and decide.
Myth
It has to be precise to be useful.
A range you can defend beats a single number you made up, and most decisions need less precision than people expect.
The lab
These tools are free, and each one maps to a chapter in the book. Use them to practice the methods.
Spreadsheets, custom GPTs, and browser apps, from the book plus extras that didn’t fit in it. New ones are added regularly.
The book, taught live
CRQ Bootcamp is the classroom version of the book: a belt-based path from understanding what cyber risk quantification is to leading a program, taught in live virtual sessions by Tony and Apolonio Garcia. Start with the free 90-minute session, Beyond Heatmaps, then work up the belts at your own pace.
crqbootcamp.com, with Apolonio Garcia of HealthGuard.

White belt
Awareness
Start here, free

Blue belt
Foundations

Purple belt
Practitioner

Brown belt
Senior Practitioner

Black belt
Program Leader
Heatmaps to Histograms: Field Notes
It’s a free newsletter for risk and security professionals, and each issue brings a practical CRQ technique, a case study from the field, and a tool or prompt you can use the same day.
Your welcome email includes Chapter 5 of the book, Your First Quantitative Risk Assessment, where you build a Monte Carlo simulation in Excel and run a complete risk analysis, free.
Delivered by Substack. No spam, and you can leave with one click.

Tony Martin-Vegue
Tony Martin-Vegue is a cyber risk consultant, speaker, and author with more than 25 years in security and risk. He wrote From Heatmaps to Histograms and is an Executive Fellow at the Cyentia Institute. He’s built cyber risk quantification programs at Netflix and for some of the largest companies in the Fortune 100, and helped their leaders put dollar figures behind security decisions.
Read Tony’s story Get in touch Consulting and workshops go through 95 Risk Advisory, and talks are booked through Tony’s Speaking page.



