Risk Quantification

A beginner's guide to Monte Carlo simulation for security teams

You don't need a maths degree to run a Monte Carlo model. Here's how to build your first probabilistic risk model in a spreadsheet.

February 2026 6 min read
Board Reporting

Five things your board actually wants to know about cyber risk

Most CISO board presentations answer questions nobody asked. Here are the five questions non-technical directors actually have — and how to answer them.

January 2026 5 min read
Open FAIR

Open FAIR explained: from factors to financial loss in plain English

A plain-English walkthrough of the FAIR ontology — what the factors are, how they chain together, and why the model produces a range rather than a single number.

December 2025 10 min read
Strategy

How to build a security business case your CFO will approve

Security investment requests fail when they speak security language to a finance audience. Here's the framework I use to translate risk into ROI.

November 2025 7 min read
Board Reporting

The CISO's guide to communicating with audit committees

Audit committees want assurance, not detail. Here's how to structure a 10-minute board presentation that actually changes decisions.

October 2025 5 min read
Risk Quantification

What insurance underwriters know about cyber risk that security teams don't

Insurers have been pricing cyber risk for years. Their approach — loss distributions, actuarial models, tail risk — has a lot to teach the security profession.

September 2025 9 min read