Pricing your bad days and how to build an economic model for security decisions

Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions. He suggests starting with a few loss scenarios, then working down to the assets that drive them.

He covers how to rank fixes by value at risk, what CFOs expect to see, and how to show the worth of incidents that never happened. He also looks at how one model can serve both the board and cyber insurance underwriters.

cyber risk quantification

Most security teams can tell a board how many vulnerabilities they closed last quarter, but very few can say what that work was worth in money. When a CISO sits down to build an economic model for the first time, where do they usually go wrong?

An economic model exists to support a decision about value. Most security models I’ve seen never get that far. They start with a score and end with it: is this OK, and should we fix the red ones first? We congratulate ourselves on the effort, and the board learns nothing about what the effort was worth.

Credit is a useful comparison. A lender’s score sits on top of a question about money: what’s the chance this borrower won’t repay this amount, or won’t repay on time? There’s plenty of clever modelling around that question, but at its heart is a value function. The maths is principled, and the score means something because it’s anchored to a potential loss.

Most security scoring has no such anchor. We’ve spent years measuring how complex the technology is and how hard it is to keep up, but we’ve spent very little time costing what those issues do to the business over time. That’s where first-time models go wrong: they start with ten thousand findings and try to work their way up to money.

I suggest CISOs reverse the order, and name the handful of scenarios that would genuinely hurt: the payment platform down for three days, a regulator’s letter about customer data, ransomware across a region, or whatever is applicable to your organisation. Put a loss range on each of these scenarios, then work down to the assets and exposures that drive those losses.

The first version will be wrong. Early credit models were wrong too, and they improved because people kept feeding them real outcomes. Yours will improve the same way, provided the inputs come straight from the systems. My rule from my CISO years still applies: if the number has been touched by a human, I don’t believe it.

With thousands of findings competing for attention, deciding what to fix first becomes political. How should an economic model adjudicate between a severe flaw on a low-value asset and a moderate one sitting on a revenue system?

It turns political because the evidence on the table is technical, and technical arguments rarely settle a budget fight. Every security team has known situations around what was “right” to do, and lacked the budget or people to do it. When that happens, it’s tempting to blame the business for not listening. The better question is, what did we give the board to decide with, and why did it not convince them?

The model should adjudicate on value at risk, or more simply, what do you stand to lose? How much would this particular exposure add to plausible future loss? A severe flaw on a test server nobody uses adds almost nothing. A moderate flaw on an internet-facing revenue system can add a lot, especially if attackers are already exploiting it. I once worked with a business unit ranked the worst in its group for exactly this reason. A pile of servers disconnected from revenue, heavy with CVEs, was scored the same as the payment gateway, and the team was spending its hours patching the wrong machines.

The maths for modelling all this exists, although it runs on forecasts. What you need is a lightweight model that gives a fast, defensible view of two things: the potential loss from a risk, and the upside of acting on it, including what the fix enables commercially. A CEO uses that kind of information for every other decision in the company.

It’s also worth looking at how much detail you provide. Asset-level and vulnerability-level context has to feed the model, because that’s where the test server gets separated from the payment gateway in terms of priority and business impact. The board shouldn’t be arguing about individual CVEs, though. Their question is whether our controls are scaling across the enterprise relative to what we stand to lose. That question is getting harder to answer due to the effect that AI has had on vulnerability discovery. One frontier model alone surfaced more than 6,000 candidate high- or critical-severity flaws across over 1,000 open-source projects. Nobody fixes all of that. The response now is to say which issues matter, and to put a signature next to the issues you’ve judged to leave.

You are constantly proving the value of incidents that never occurred. How do you make “nothing went wrong” legible as a return that a finance team will respect?

The CFO does this all day: they own insurance and capital reserves, and they plan for bad days. Cyber losses are only one kind of loss they have to consider. Their question around any risk is simple: given our exposure, could a loss overrun our limits and hit the cash we have on hand?

Insurance and treasury use the same kind of modelling to set limits and reserves, and the actuaries behind your broker are already running it on your IT organisation as well. The difference is that they know less about your residual cyber risk than you do. From a financial perspective, your job is to buy down plausible future loss using your team, your security controls and your investments until the chance of breaching those financial backstops sits inside the limits the business has set.

“Nothing happened” will never stand as evidence on its own, and it shouldn’t. You aren’t doing nothing either, so those controls should be – pardon the pun – accounted for. Finance respects measurable change, so report what moved:

  • How long critical exposure survived on the systems behind your loss scenarios, this quarter against last.
  • How much plausible loss sits in exposures that are past their remediation deadline.
  • Whether controls held when tested: for example a restore that worked, or a red-team exercise stopped at a segmentation boundary.
  • What the market thinks. Underwriters now price on cyber controls in finer detail, so better terms at renewal are an outside valuation of your programme.

None of these signals is perfect on its own. What you should look at is performance over time, so your signals need to be consistent, sourced from systems, and refined every quarter, the same way finance refines its own forecasts. That’s how security earns a seat in the conversations where money gets allocated.

What does a CFO want from a security leader that the security leader almost always forgets to bring?

CFOs want a number they can put in a spreadsheet, with a range around it, and a decision attached.

Security leaders talk in security words: vulnerabilities, threats, mean time to respond, and so on. Underneath that vocabulary sits a binary, where something is either secure or it isn’t. The CFO works in money, percentages and likelihoods, where very little is black and white, and that gap frustrates a lot of CISOs.

It helps to remember that we aren’t the only risk experts in the building. The CFO, the CRO and the treasurer have been pricing uncertainty for their entire careers, so learn their language and bring it with you. Boards and CFOs are far more tech-literate than they were ten years ago, but translation is still your job.

In practice, bring four things to every CFO conversation:

  • The loss scenario, in money, as a range.
  • How likely the loss is over the next twelve months, and what that estimate rests on.
  • What you propose to spend, and how far the range moves if you spend it.
  • What happens if you don’t, including who has to sign for leaving that issue as it is.

The last one is what CISOs forget most often. A CFO can’t approve or reject a risk that nobody owns. Once the person whose budget absorbs the loss has to sign the acceptance, the conversation changes quickly. You can track those scenarios quarter by quarter, so the CFO can see the trend.

Cyber insurance underwriting and risk quantification are converging on the same questions. Does a model that satisfies the board also satisfy an underwriter, or are you preparing two different stories?

You might have one model, but you have to report to two audiences. If the board hears one story and the underwriter another, you have a bigger problem than presentation. Anything you tell an underwriter has to hold up on the day you make a claim.

What changes is what each audience sees: boards don’t need to sit through cyber risk quantification discussions, they need information to make decisions or understand why a decision was made based on that financial information. They’re usually pre-socialised to capital decisions before you walk into the room, so your job is to bring a grounded rationale for what you decided. Underwriters want the evidence underneath: control maturity, exposure windows, how fast you expect to recover. Carriers are underwriting more granularly on controls, privacy exposure and emerging AI risk, so the same data that drives your model should go into your submission.

Here’s what a board update might sound like:

“Frontier AI models are finding vulnerabilities at a scale we haven’t seen before, and our backlog grew 200% in Q2. We’re investing in AI-assisted remediation and expect to be back to pre-Mythos levels by the end of next quarter. We’ve reviewed our limits with risk management under the CFO, and we’re meeting our brokers next month to increase them. The timing helps: the market is soft, so we expect to add cover for a modest premium increase.”

Look at what’s in there: a cause, a number, a decision, a date, and a link to the CFO’s own instruments.

The timing point deserves attention. UK cyber pricing stayed soft through Q2 2026, with better terms for buyers who can evidence strong controls. Specialist underwriters are already warning of an inflection point this year. The organisations with an honest model will get the best terms while they last.

Don't miss