For most of its history, cyber risk was somebody else’s problem – at least, that’s how the boardroom saw it. It lived in IT, spoke in acronyms, and was measured in things boards neither understood nor needed to. Firewalls. Patch cycles. Vulnerability scores. Important, certainly, but not the kind of thing that kept a CFO awake.
That era is over. Cyber risk now sits alongside credit, liquidity and operational risk as a driver of enterprise value. It shapes valuations, influences M&A decisions, and moves shareholder confidence in ways that are very visible and very fast. When something goes seriously wrong, it isn’t logged as an IT incident; it lands in the boardroom as a business crisis with a price tag.
The problem is that most organisations are still trying to govern a 2025 risk with 2005 tools.
How we got here – and why the approach most organisations use isn’t fit for purpose
The discipline has evolved considerably over the past two decades. But that evolution has been uneven, and the methods many organisations still rely on were designed for an earlier set of problems.
Stage one: heat maps and gut feel
For the better part of two decades, cyber risk management was essentially a technical exercise dressed up as governance. Risks were mapped onto colour-coded grids based on control assessments and vulnerability scans. Teams asked whether the firewall was configured correctly, whether patches were current, whether access rights matched the policy.
There was nothing wrong with this, as far as it went. It gave security teams a shared framework. It helped prioritise remediation. But it told you almost nothing that a board could act on. What does “high” actually mean? High compared to what? What would it cost? The heat map couldn’t say. A risk rated red in one business unit and amber in another might represent wildly different financial exposures. Or identical ones. There was no way to tell, and no common unit of account to compare them.
The board got a dashboard. What it needed was an answer.
Stage two: financial quantification, built from the bottom up
The next wave addressed the most glaring gap: it put numbers on risk. Frameworks like FAIR gave analysts a structured way to estimate monetary losses, drawing on probability distributions and loss modelling. For the first time, cyber risk could be expressed in terms that the rest of the business understood. That matters, because when you can denominate risk in money, you can compare it to other risks, weigh it against the cost of controls, and start making defensible decisions.
But the bottom-up approach carried its own limitations, and they’re serious ones. It works at the asset level (individual systems, individual threats, individual control failures) and tries to work upward toward an enterprise view. In practice, this requires granular technical data that is often incomplete, unreliable, or simply unavailable. Building a single quantification can consume months. And the further you zoom out, the more the analysis starts to wobble: aggregating dozens of system-level assessments into a coherent company-level picture is an exercise in compounding assumptions.
The result is analysis that can feel rigorous in its detail while being strategically useless at the level where decisions actually get made. You end up knowing a great deal about the risk inside individual rooms while remaining largely ignorant about the building.
Stage three: start with the business, not the systems
The most recent evolution flips the logic entirely, and it’s the one that finally produces something boards can use.
Instead of starting with IT assets and working up, a top-down approach starts with the business: how does this organisation make money, what would a serious cyber event actually disrupt, and how exposed are those critical functions right now? It calibrates against real-world loss data drawn from insurance markets and large-scale incident histories, rather than from internal workshops and expert estimates. That means it captures what analysts might miss: unknown vulnerabilities, systemic exposures, and the full chain of second-order consequences that bottom-up models routinely undercount.
The outputs look different too. Risk expressed as a potential financial loss at the company or group level, broken down by business unit, tracked over time, and stress-tested against different investment scenarios, is something a board can actually govern. It fits into the same mental model as every other material risk on the register. It enables comparison, accountability, and decisions that can be explained and defended after the fact.
For groups operating across subsidiaries or jurisdictions, this matters even more. A consistent, top-down model makes it possible to compare entities on the same basis, set improvement targets proportionate to actual exposure, and track whether the aggregate risk position is moving in the right direction. Bottom-up methods, stitched together from incompatible local assessments, simply can’t do that.
What this demands of leadership
The shift creates clear obligations, and they run in both directions.
CISOs and CIOs need to stop thinking of financial fluency as someone else’s job. The ability to explain how a specific control investment reduces a measurable financial exposure (not just improves a risk rating) is now a core part of the role. Boards are increasingly asking for it, and those who can’t provide it are increasingly losing the argument for budget. Boards, for their part, should be asking harder questions. Not about the technical detail – that’s management’s job – but about the quality of the evidence behind the numbers. Does the reporting show how exposure has moved over time? Does it flag concentrations of risk? Are the assumptions visible and defensible? A report that can’t answer those questions isn’t risk governance; it’s risk theatre.
The standard has shifted
The principle that risk has to be measurable to be manageable isn’t new. It underpins how serious organisations have governed credit, liquidity and operational risk for decades. Entire disciplines were built on it: stress testing, capital modelling, scenario analysis. The assumption was always that if you can’t quantify an exposure, you can’t really manage it; you’re just hoping.
Cyber is now being held to that same standard. Regulators are demanding it. Insurers are pricing for it. And boards that have watched enough crises unfold in public are no longer willing to accept dashboards as a substitute for answers.
Cyber risk has earned its place at the table. The question is whether the people presenting it are ready to speak the language of everyone else in the room.
Learn more at squalify.com
- Cybersecurity
- Digital Strategy