Inside the book
Read it front to back, or start with the chapter that matches what you’re working on.
Prologue: Risky Business
Why traditional cyber risk reporting fails to support real executive decisions, and what led to a practitioner-first approach to risk quantification.
Part 1: Foundations
Chapter 1: Welcome to the Rebellion
Why modern cyber risk programs often reward activity that looks like progress while the risk itself goes unmeasured. Introduces uncertainty as a normal condition and frames quantitative risk as the practical alternative to heatmaps and compliance theater.
Chapter 2: Probability’s Plot Twist: After 300 Years, We Colored It Red
Traces risk analysis from probability theory to the modern risk matrix, clarifies the differences between qualitative and quantitative approaches, and explains how cybersecurity ended up on the wrong path.
Chapter 3: GenAI Needs Adult Supervision
How generative AI can support risk analysis without replacing human judgment, with simple rules for using it responsibly in research, modeling, and analysis.
Part 2: Getting Your Risk Muscles Working
Chapter 4: Foundations
Builds the mental models quantitative thinking runs on: ranges, uncertainty, frequency, and magnitude. Introduces the vocabulary and the “less wrong” mindset used throughout the book.
Can You Beat a CIA Officer? Calibration Trainer
Chapter 5: Your First Quantitative Risk Assessment
Builds a simple quantitative risk model with Monte Carlo simulation, step by step, and shows how to forecast frequency and magnitude and read the results.
Your First Monte Carlo Exercise 5-1: Monte Carlo Coin Flip Exercise 5-3: Mobile Phone Incident Frequency Exercise 5-5: Quantitative Risk Analysis
Chapter 6: Interpreting and Communicating Quantitative Results
Turns numerical output into a narrative a decision-maker can use, covering histograms, loss exceedance curves, and how to convey uncertainty without drowning the room.
How to Read a Loss Exceedance Curve The Board Translator
Chapter 7: From Risk Statements to Assessment Scope
Translates vague concerns into measurable scenarios, with structured methods for defining scope and building a data collection roadmap.
Cyber Risk Scenario Coach Roast My Risk Register
Chapter 8: Understanding Loss: The Six Forms
Breaks loss into six practical categories, with guidance on when to decompose, how to estimate magnitude, and how to avoid double counting.
Part 3: Solving the Data Problem
Data is where most analysts say they get stuck, so it gets a whole part of the book: six chapters on finding data, vetting it, and blending the sources into one estimate.
Chapter 9: Getting Unstuck with Data
Dismantles the myths about data availability in cyber risk and introduces the three sources you already have: external data, internal data, and expert judgment.
Chapter 10: How to Vet and Believe Your Data
A time-boxed method for evaluating data quality, and how to make defensible decisions when the data is incomplete.
Chapter 11: Finding and Using External Data
How to locate, evaluate, and apply external research, and the several ways it can support scenario building, modeling, and validation.
Chapter 12: Your Best Evidence: Finding and Using Internal Data
How to pull meaning out of operational, incident, and audit data, with practical methods for turning raw internal records into model inputs.
Chapter 13: Your Secret Weapon: Subject Matter Experts
How to work with SMEs who have never been calibrated, using structured elicitation techniques and workshop formats that hold up in practice.
Chapter 14: How to Blend Data
Bayesian thinking as a practical mental model for combining sources, walked through step by step with examples.
Part 4: Risk Assessment in Action
Chapter 15: Extending This to CRQ
How quantitative analysis supports what-if analysis, sensitivity testing, and return on security investment, connecting model output directly to decisions.
Chapter 16: Extending to FAIR
FAIR in plain language, applying only as much decomposition as the question needs, and how the techniques in this book map to the FAIR ontology.
Chapter 17: How to Run a Complete CRQ Assessment
An end-to-end walkthrough using a realistic ransomware scenario, bringing together scenario framing, data collection, modeling, and decision support.
Part 5: Making It Stick
Chapter 18: CRQ in the Org
Why programs succeed or fail inside real companies, the six levers that move risk over time, and how to keep momentum after the first assessment.
Chapter 19: Making Better Decisions with CRQ
Connects the analysis to the decisions it serves: investments, strategy, and board-level reporting.
Chapter 20: The Future of CRQ (And Yours Too)
How AI, the move from compliance-oriented analysts to quantitative thinkers, and organizational change are changing the field, and how to build a career in it.
Appendixes
Appendix A: Jargon-less Risk Glossary
Plain-language definitions organized by category, with chapter cross-references.
Appendix B: Six Forms of Loss, Detailed Reference Guide
Calculation frameworks, measurement proxies, and data sourcing guidance for each of the six loss categories.
Appendix C: Data Types Quick Reference
The data formats you meet while gathering evidence: counts, frequencies, probabilities, monetary values, time durations, and more.
Appendix D: Data Source Evaluation Framework
A checklist for assessing external data quality, covering bias, definitional drift, geographic mismatch, and stale sources.
Every tool above is free, and you’ll find the full collection on the Tools & Downloads page.

Paperback and ebook
Apress, March 2026