Cyber Risk Quantification
Creating and analysing Risk Scenarios
The purpose of this article is to provide a step-by-step guide on how to create and analyse Risk Scenarios including but not limited to inputting data to create analyses, run simulations and interpreting results.
Setting up the Risk Quantification Analysis
The Risk Quantification module allows users to assign numerical values to potential risks to better understand, prioritise and prepare for risks in a data driven manner. This module supports executive communications by quantifying risks into costs and tangible actions.
- In the navigation menu select Assessment > Risk Quantification
- Select "Create Analysis" in the top right hand corner of the page
- Populate the name and description, then select "Initialise" in the bottom right hand corner to confirm
-
An Attack Tree will appear at the bottom of the page. Select the eye icon on each card to open the drawer and you are describing a range you are confident the real answer falls within, not making a single guess. If you are unsure what a particular card is asking for, see Understanding the Risk Quantification Model.
- Select the icon next to the Annual Loss Exposure Card to run the analysis
- A pop up will appear, select the "Run Analysis" button to confirm.
The Loss Event Frequency, Primary Loss, Secondary LEF and Secondary LM are mandatory for the Risk Quantification Analysis to run. Other details will increase the accuracy of the analysis
Your three numbers must be consistent with each other, or the analysis will not run. The minimum cannot exceed the most likely value, the most likely value must sit between the minimum and the maximum, and the maximum must be greater than the minimum. If a run is rejected, the error names the exact field to fix.
While your analysis is running
The calculation runs outside CyberHQ and results come back when it finishes rather than immediately. Three things are worth knowing while you wait:
-
Only the person who clicked Run is notified. If a colleague is looking at the same analysis, their screen will not update when it completes. They will see the results after a refresh.
-
A status of "Timed Out" does not always mean the analysis failed. CyberHQ stops waiting after three minutes and reports a timeout, but the calculation may still complete and write its results afterwards. If you see a timeout, refresh before re-running.
-
Results replace previous results. Re-running an analysis overwrites its stored loss figures. If you need to keep a result for comparison, create a simulation instead.
Creating a Risk Quantification Simulation
The Risk Quantification simulation allows users to visualise the inputted data and supports strategic planning and capital allocation.
- In the Risk Quantification section, select the edit icon next to the Risk Quantification Scenario that is to be simulated.
- Go to the "Simulate" tab and select "Create New Simulation".
- Similar to creating the Risk Quantification, select the eye icon in each card to open the drawer and insert relevant data.
- Select the icon next to the Annual Loss Exposure Card to run the analysis.
- Select the "Run Analysis" button to confirm.
Prior to running the simulation, the display will show "0" as minimum, average and maximum figures.
Removing an analysis
Delete archives rather than deletes. Selecting Delete on a saved analysis removes it from your list, but the record and its results are retained. Nothing is destroyed.
There is currently no way to restore an archived analysis from the interface, so treat Delete as final from a practical standpoint even though the data survives. If you archive something you need back, raise it with support.
Simulations behave differently from analyses. A simulation never appears in the main list. It is reached only through the results drawer of the analysis it was created from, so if a simulation seems to have disappeared, open its parent.