Skip to content

Amazon #1 New Release in Computer Network Security

From Heatmaps to Histograms

The practical on-ramp to cyber risk quantification, for anyone who has wanted to measure risk in real numbers but never knew where to start.

Likelihood Impact $0 $50K $500K $5M $50M Annual loss, one scenario Probability

“Brilliantly written for those with little or no background in quantitative risk measurement, and valuable to those with years of experience. Required reading.”

Jack Jones, creator of FAIR

“He makes even quantitative concepts accessible to every reader, with case examples and step-by-step procedures. I highly recommend his book.”

Douglas Hubbard, author and measurement expert

“Where do I begin with measuring cyber risk? This is the definitive starting point for anyone serious about becoming a cybersecurity risk modeler.”

Richard Seiersen, author and Chief Risk Technology Officer, Qualys

“A recurring ‘Yeah, but how?’ dominates conversations on cyber risk quantification. Tony strikes the perfect balance of what you need to know and what you need to do.”

Wade Baker, Partner, Cyentia Institute

“This is the book I’ve been waiting for, a real A-to-Z guide to cybersecurity risk forecasting for both newcomers and seasoned professionals.”

Rick Howard, cybersecurity educator and author

“A stepping stone away from risk matrices and heatmaps. If you were wondering where to start your journey into quantified risk, this is it.”

Jay Jacobs, Co-founder and Chief Data Scientist, Empirical Security

“Complex ideas made approachable for readers at any experience level, packed with sage advice and hard-learned lessons. Highly recommended for all risk practitioners.”

Lisa R. Young, ISC2 Board of Directors, former President of SIRA

“Empowers new and experienced professionals to level up their risk communication to the board like no one else has. We can finally eliminate the stoplight technique.”

Patti Degnan, Operating Partner, Andreessen Horowitz

“Quantitative risk analysis isn’t the future of GRC engineering, it’s the foundation. This book is the baseline. Start here.”

Ayoub Fandi, GRC Engineer Newsletter

“You don’t just read this book; you do it. It belongs on every risk team’s onboarding list.”

Adrienne Allen, Security, Risk and Compliance Leader

What you’ll learn

It’s a beginner’s guide to cyber risk quantification that turns vague heatmaps into scenarios and numbers you can act on. Along the way, it takes apart the myths that keep most teams from starting.

Front cover of From Heatmaps to Histograms: A Practical Guide to Cyber Risk Quantification, by Tony Martin-Vegue

Apress, March 2026
449 pages. Paperback and ebook.

Myth

You need a mountain of data.

You need less than you think. Most analyses start from three sources you already have: published research, your own records, and the people who run the systems.

Solving the data problem

Data is where most analysts get stuck, so the book gives it six chapters: where to find it, how to vet it, and how to blend outside research, your own records, and expert judgment into one estimate.

External data base rates Internal data local evidence Expert input context from SMEs Data-driven context

Figure 14-2, Chapter 14. The three sources of data blend together to provide additional context. Tap to enlarge.

Myth

You need actuarial tables.

Base rates from published research and calibrated estimates from your own experts give you a defensible first answer, and you update it as data comes in.

Practical methods

Use Excel and Monte Carlo simulation to quantify cyber risk without advanced math. The workbooks are free.

Myth

You need an army of data scientists.

One analyst with a spreadsheet can run every method in the book, Monte Carlo simulation included, with basic Excel formulas and no code.

Executive communication

Learn to present risk results so executives can follow them and decide.

Myth

It has to be precise to be useful.

A range you can defend beats a single number you made up, and most decisions need less precision than people expect.

Skills that keep their value

More security and GRC teams expect quantitative skills every year, and the book gives you the methods and the practice to use them with confidence.

The lab

These tools are free, and each one maps to a chapter in the book. Use them to practice the methods.

Spreadsheets, custom GPTs, and browser apps, from the book plus extras that didn’t fit in it. New ones are added regularly.

Chapter

2

Chapter

4

Screenshot of Calibration Trainer

Calibration Trainer

Foundations
Web app

Chapter

5

Screenshot of Your First Monte Carlo: Watch the Law of Large Numbers in Action

Your First Monte Carlo: Watch the Law of Large Numbers in Action

Your First Quantitative Risk Assessment
Web app

Chapter

6

Custom GPT

The Board Translator

The Board Translator

Interpreting and Communicating Quantitative Results
Custom GPT

Chapter

13

Screenshot of Chips and Bins: Turn Expert Beliefs Into Probability Distributions

Chips and Bins: Turn Expert Beliefs Into Probability Distributions

Your Secret Weapon: Subject Matter Experts
Web app

Chapter

17

Ransomware Risk Assessment

How to Run a Complete CRQ Assessment
Excel workbook

The book, taught live

CRQ Bootcamp is the classroom version of the book: a belt-based path from understanding what cyber risk quantification is to leading a program, taught in live virtual sessions by Tony and Apolonio Garcia. Start with the free 90-minute session, Beyond Heatmaps, then work up the belts at your own pace.

crqbootcamp.com, with Apolonio Garcia of HealthGuard.

White belt

White belt

Awareness

Start here, free

Blue belt

Blue belt

Foundations

Purple belt

Purple belt

Practitioner

Brown belt

Brown belt

Senior Practitioner

Black belt

Black belt

Program Leader

Heatmaps to Histograms: Field Notes

It’s a free newsletter for risk and security professionals, and each issue brings a practical CRQ technique, a case study from the field, and a tool or prompt you can use the same day.

Your welcome email includes Chapter 5 of the book, Your First Quantitative Risk Assessment, where you build a Monte Carlo simulation in Excel and run a complete risk analysis, free.

Delivered by Substack. No spam, and you can leave with one click.

Tony Martin-Vegue speaking on a conference stage, gesturing with both hands

Tony Martin-Vegue

Tony Martin-Vegue is a cyber risk consultant, speaker, and author with more than 25 years in security and risk. He wrote From Heatmaps to Histograms and is an Executive Fellow at the Cyentia Institute. He’s built cyber risk quantification programs at Netflix and for some of the largest companies in the Fortune 100, and helped their leaders put dollar figures behind security decisions.

From Heatmaps to HistogramsOrder now