...
Skip to content

Perspectives: Why probabilities should guide cyber risk decisions

As we begin a new year and people look toward the future, we tend to see predictions about all kinds of things, including cybersecurity.

Predictions can be useful, especially if they’re based on actionable intelligence and possess a high degree of certainty. However, when it comes to prioritization of cyber risk management actions, where predictions fall short, measured forecasts – a range of possibilities with corresponding probabilities, or probabilities for shorthand – provide much more effective information. More than predictions, probability is better suited to making business decisions about cyber risks.

To illustrate this, consider recent pronouncements by Forrester Research that “cybercrime is expected to cost $12 trillion in 2025” and “regulators will take a more active role in protecting consumer data.” Those are interesting predictions, to be sure: Both are precise but don’t offer any actionable advice.

Cybercrime was forecast to cost $9.5 trillion in 2024. Whether the cost in 2025 reaches $10.5 trillion or even more is beside the point, which is that cybercrime is a tremendous and growing financial burden on businesses and society. Likewise, increased data privacy regulations will force organizations to enhance their cybersecurity. Those kinds of predictions serve as directional signals.

Knowing the direction of a trend is helpful, but more insight is needed to act on it. Therefore, if organizations assigned probabilities to the predictions on cybercrime and privacy regulation, they could use that information to develop cybersecurity and risk mitigation strategies.

Combating fear

Many prognostications about risks, particularly cyber risk, tend to stoke fear, uncertainty and doubt. This stems from the insurance focus on predicting catastrophic loss and the impact of loss aggregation. Regarding cyber exposures, hyperbolic assertions about loss aggregation are good for grabbing attention but aren’t necessarily actionable.

Much historical data is available to support predictive modeling for natural catastrophes. It’s possible to estimate the damage from a specific type of disaster within a narrowly defined geography with greater accuracy than ever. Cyber risk is different. It has a much shorter history, and the insurance industry frequently reminds us that cyber events are inherently difficult to predict. Nevertheless, tools and data are available for businesses to improve their cyber risk decision-making. Instead of letting fears of cyber losses run wild, businesses can take steps to control cyber risk.

Choice or chance?

Ransomware remains the leading cause of cyber loss, and the probability of experiencing an attack is high. Coveware’s analysis of ransomware trends in the second quarter of 2024 found that ransomware attacks hit 14 industry sectors. The incidents were relatively evenly distributed by industry, with the most attacks experienced by professional services, health care and financial services. The top confirmed attack vectors in the period were remote access compromise, phishing and software vulnerability, Coveware found. These vectors emphasize the importance of multifactor authentication and robust password hygiene practices.

The overall frequency of ransomware attacks is alarmingly high, and the likelihood of an attack varies for different industries. Regardless of probability, experiencing an attack need not be a matter purely of chance. Organizations can significantly mitigate their exposure to ransomware through effective cybersecurity controls and practices. Deciding on and prioritizing which controls to implement against the probabilities of financial loss is the pathway to efficient investment. Thus, loss prevention and reduction can become more of a choice than relying on luck.

To fortify networks and systems against cyber risks, organizations need to quantify threats regarding business impact. Assessing cyber threats by the probability of occurrence and effect is the clearest way for decision-makers to prioritize their investments in cybersecurity and insurance and chart a path to cyber resilience.

Here’s an example. A company in the distribution industry depends on several critical software-as-a-service suppliers in its daily operations. The company recognized that if a cyberattack disrupted one of its vendors – even if the incident had a low probability of occurring – the effect would be devastating financially, creating material loss for the business. The company was able to identify the several pathways by which disruption could occur. By assigning probabilities to these pathways and then assessing the costs to mitigate the vulnerabilities, the company could prioritize the order of its controls consistent with the context of its organization.

Traditional measures, such as peer benchmarks and breach calculators, could not accurately quantify the company’s cyber exposure due to its complex risk profile. Using a risk modeling approach that quantified loss values and the expected value of mitigation strategies, the company could choose a strategy that would provide incremental value and ease its cyber risk transfer budget. At the same time, the company improved its resilience by focusing on what mattered most in a manner that represented sound financial stewardship.

Focusing on probabilities in cyber, rather than predictions, is a more effective way to protect against material loss, align resources where they will have the greatest return, and achieve organizational resilience.

Vishaal “V8” Hariprasad is the San Francisco-based CEO of Resilience Cyber Solutions.