Skip to content

About the book

A beginner’s guide to cyber risk quantification that you can follow with nothing more than a spreadsheet.


From Heatmaps to Histograms is a beginner’s guide to cyber risk quantification, written for the practitioner who has been asked to put a number on risk and has no idea where to start.

Most risk programs still run on a five-by-five matrix. Two risks can land in the same red cell even when one could cost $200,000 and the other $20 million. The book takes the reader from that matrix to a loss distribution built from ranges, expert estimates, and a Monte Carlo simulation, using the data a security team already has.

Data is where most analysts say they get stuck, so the book gives it a whole part: six chapters and more than 130 pages on finding data, vetting it, and blending external research, internal records, and expert judgment into one estimate. The last part covers what happens after the first assessment, and how to build a program that lasts.

What you’ll learn

  • How to turn a vague worry into a scenario specific enough to measure.
  • How to find, vet, and combine data when you think you don’t have any.
  • How to estimate frequency and loss as calibrated ranges.
  • How to run a Monte Carlo simulation in Excel and read what comes out of it.
  • How to build and explain a loss exceedance curve.
  • How to present results to executives so the conversation ends in a decision.
  • How to keep a quantification program going after the first assessment.

Who it’s for

It’s for risk analysts and GRC professionals who’ve been handed the measurement problem, security leaders who have to defend a budget with something better than a color, and consultants who want a method they can teach. You don’t need a statistics background, and you don’t need any tool beyond a spreadsheet.

How to use it

Most chapters have companion material: custom GPTs for scoping and estimating, browser simulators for the concepts that are easier to see than to read about, and Excel workbooks with the exercises already built. Everything on the Tools & Downloads page is free, and the chapter list shows which tools go with each chapter.

Corrections to the first printing are on the errata page, and every figure in the book is on the figures page in full color.

Questions readers ask

What is cyber risk quantification?

Cyber risk quantification, or CRQ, measures cybersecurity risk in probabilities and dollars instead of colors. A typical analysis estimates how often a loss event could happen in a year and what each event could cost, expressed as ranges to capture uncertainty, then runs a Monte Carlo simulation to show the full range of possible annual losses.

What’s wrong with a risk heat map?

A heat map gives the same color to risks that can differ enormously. Two risks in the same red square might cost $200,000 or $20 million, and nothing on the chart tells them apart. You can’t add risks together or weigh a control’s cost against the risk it reduces, and two analysts can put the same scenario in different squares. There’s also no way to tell whether a rating was ever wrong. If a red risk never happens, nobody can say whether it was overrated or the company got lucky. A probability can be checked: across many forecasts, the risks you called 10% should happen about one time in ten.

Where do I get data for cyber risk quantification?

From three sources most organizations already have: published research, such as breach and incident studies; your own internal records; and the judgment of the people who run your systems. Part 3 of the book, six chapters and more than 130 pages, covers how to find each one, vet its quality, and blend them into a single estimate.

Do I need a statistics background?

No. The book assumes no statistics background and teaches every method in a spreadsheet, so if you’re comfortable with basic Excel formulas, you can follow every exercise.

Can I do cyber risk quantification in Excel?

Yes. Every technique in the book can be done in Excel or Google Sheets with no coding, including Monte Carlo simulation, and the free workbooks on the tools page have the exercises built in. For readers who want to go further, the Chapter 17 workbook runs a complete ransomware assessment from start to finish.

Is this a FAIR book?

It works with FAIR and goes well past it. The book uses FAIR’s terminology, and Chapter 16 shows how its techniques map onto the FAIR model. Beyond the model, it covers where to find data and how to vet it, the step most analysts say trips them up, in six chapters of its own, and how to make a quantification program stick after the first assessment.

What is a loss exceedance curve?

A loss exceedance curve shows the probability that losses from a risk will exceed a given dollar amount over a year. It answers questions like “what are the chances we lose more than $5 million?” Chapter 6 covers how to read one and explain it to executives, and there’s a free interactive version on the tools page.

What formats is the book available in?

Paperback from major retailers worldwide, ePub and PDF from Springer, NOOK from Barnes & Noble, and online reading through an O’Reilly subscription. Any bookstore can order the paperback with the ISBN 979-8-8688-2299-5.

Front cover of From Heatmaps to Histograms

Paperback and ebook
Apress, March 2026

From Heatmaps to HistogramsOrder now