Skip to content

Inside the book

Read it front to back, or start with the chapter that matches what you’re working on.


Prologue: Risky Business

Why traditional cyber risk reporting fails to support real executive decisions, and what led to a practitioner-first approach to risk quantification.

Part 1: Foundations

Chapter 1: Welcome to the Rebellion
Why modern cyber risk programs often reward activity that looks like progress while the risk itself goes unmeasured. Introduces uncertainty as a normal condition and frames quantitative risk as the practical alternative to heatmaps and compliance theater.

Chapter 2: Probability’s Plot Twist: After 300 Years, We Colored It Red
Traces risk analysis from probability theory to the modern risk matrix, clarifies the differences between qualitative and quantitative approaches, and explains how cybersecurity ended up on the wrong path.

Heat Map → Histogram

Chapter 3: GenAI Needs Adult Supervision
How generative AI can support risk analysis without replacing human judgment, with simple rules for using it responsibly in research, modeling, and analysis.

Part 2: Getting Your Risk Muscles Working

Chapter 4: Foundations
Builds the mental models quantitative thinking runs on: ranges, uncertainty, frequency, and magnitude. Introduces the vocabulary and the “less wrong” mindset used throughout the book.

Can You Beat a CIA Officer? Calibration Trainer

Chapter 5: Your First Quantitative Risk Assessment
Builds a simple quantitative risk model with Monte Carlo simulation, step by step, and shows how to forecast frequency and magnitude and read the results.

Your First Monte Carlo Exercise 5-1: Monte Carlo Coin Flip Exercise 5-3: Mobile Phone Incident Frequency Exercise 5-5: Quantitative Risk Analysis

Chapter 6: Interpreting and Communicating Quantitative Results
Turns numerical output into a narrative a decision-maker can use, covering histograms, loss exceedance curves, and how to convey uncertainty without drowning the room.

How to Read a Loss Exceedance Curve The Board Translator

Chapter 7: From Risk Statements to Assessment Scope
Translates vague concerns into measurable scenarios, with structured methods for defining scope and building a data collection roadmap.

Cyber Risk Scenario Coach Roast My Risk Register

Chapter 8: Understanding Loss: The Six Forms
Breaks loss into six practical categories, with guidance on when to decompose, how to estimate magnitude, and how to avoid double counting.

The Loss Estimator

Part 3: Solving the Data Problem

Data is where most analysts say they get stuck, so it gets a whole part of the book: six chapters on finding data, vetting it, and blending the sources into one estimate.

Chapter 9: Getting Unstuck with Data
Dismantles the myths about data availability in cyber risk and introduces the three sources you already have: external data, internal data, and expert judgment.

The Data Detective

Chapter 10: How to Vet and Believe Your Data
A time-boxed method for evaluating data quality, and how to make defensible decisions when the data is incomplete.

Cyber Risk Data Vetter

Chapter 11: Finding and Using External Data
How to locate, evaluate, and apply external research, and the several ways it can support scenario building, modeling, and validation.

Chapter 12: Your Best Evidence: Finding and Using Internal Data
How to pull meaning out of operational, incident, and audit data, with practical methods for turning raw internal records into model inputs.

AI-Generated Incident Data

Chapter 13: Your Secret Weapon: Subject Matter Experts
How to work with SMEs who have never been calibrated, using structured elicitation techniques and workshop formats that hold up in practice.

Chips and Bins

Chapter 14: How to Blend Data
Bayesian thinking as a practical mental model for combining sources, walked through step by step with examples.

Part 4: Risk Assessment in Action

Chapter 15: Extending This to CRQ
How quantitative analysis supports what-if analysis, sensitivity testing, and return on security investment, connecting model output directly to decisions.

Chapter 16: Extending to FAIR
FAIR in plain language, applying only as much decomposition as the question needs, and how the techniques in this book map to the FAIR ontology.

FAIR Model Study Tool

Chapter 17: How to Run a Complete CRQ Assessment
An end-to-end walkthrough using a realistic ransomware scenario, bringing together scenario framing, data collection, modeling, and decision support.

Ransomware Risk Assessment

Part 5: Making It Stick

Chapter 18: CRQ in the Org
Why programs succeed or fail inside real companies, the six levers that move risk over time, and how to keep momentum after the first assessment.

Chapter 19: Making Better Decisions with CRQ
Connects the analysis to the decisions it serves: investments, strategy, and board-level reporting.

Chapter 20: The Future of CRQ (And Yours Too)
How AI, the move from compliance-oriented analysts to quantitative thinkers, and organizational change are changing the field, and how to build a career in it.

Appendixes

Appendix A: Jargon-less Risk Glossary
Plain-language definitions organized by category, with chapter cross-references.

Appendix B: Six Forms of Loss, Detailed Reference Guide
Calculation frameworks, measurement proxies, and data sourcing guidance for each of the six loss categories.

Appendix C: Data Types Quick Reference
The data formats you meet while gathering evidence: counts, frequencies, probabilities, monetary values, time durations, and more.

Appendix D: Data Source Evaluation Framework
A checklist for assessing external data quality, covering bias, definitional drift, geographic mismatch, and stale sources.

Every tool above is free, and you’ll find the full collection on the Tools & Downloads page.

Front cover of From Heatmaps to Histograms

Paperback and ebook
Apress, March 2026

From Heatmaps to HistogramsOrder now