The Calculus of Cyber Risk

From Risk to Resilience: A Modern Approach to Cybersecurity Leadership

Build Your Strategy on Solid Foundations

Elevate Your Leadership: Make smarter security decisions, influence business strategy, and drive meaningful change.

Move beyond gatekeeping. Align security with business goals to drive growth, resilience, and trust.

Security should empower, not hinder. Learn how to build resilience while driving speed and innovation.

Thrive in uncertainty. Master cyber risk navigation, strategic decision-making, and build resilience in a complex threat landscape.

Go beyond the fundamentals. Explore cutting-edge strategies to lead security at the highest level.

Latest Insights

View all posts ยป
A Backlog Is an Inventory,

A Backlog Is an Inventory, Not a Debt.

A security leader invests in better detection. Next quarter, the open-findings count is up, the reported risk number is up, and the board asks why the number got worse right after the team paid for it to get better. Nothing in the environment deteriorated: the instrument got better. This post names the trap, draws the line between a belief correction and a world change, and replaces the metrics (findings discovered, findings closed, mean-time-to-remediate, backlog size) that reward a security program for looking away.

The Probability Behind the Finding:

The Probability Behind the Finding: Calibrated Exploit Estimates Beyond CVEs

CVSS severity is not exploit probability. EPSS proved that prioritizing by real-world abuse probability delivers 12x better prioritization precision than chasing CVSS 9.8 scores. But EPSS has a fatal structural limit: it only works on CVEs. Secrets in code, over-permissioned service accounts, and dependencies without published advisories sit in the dark with zero math behind them. Here is the principled 3-layer framework to calculate calibrated exploit probabilities for every non-CVE weakness on your risk register.

Security Investment as Board Strategy:

Security Investment as Board Strategy: Pricing Protection on Both Sides of the Boom.

Beyond the Boom gave every security control two scores: TMP for preventing loss events, LMAP for limiting the damage when they happen. This sequel prices them, scenario by scenario: two closed-form Bayesian updates - one for how often loss events happen, one for what they cost - feeding a per-control return calculation, credited across every scenario a control covers, that a board risk committee can follow line by line. The board conversation shifts from whether security spend is justified to which priced option gets funded first - with the board owning the loss threshold, the price of tail risk, and the review cadence. An interactive calculator runs the method on your own numbers.