Many companies continue to assess their technological risks using labels such as high, medium, or low, a useful way to classify threats but much less effective when a CIO or CISO needs to justify an investment of several hundred thousand euros to management. A new analysis from Info-Tech Research Group suggests moving toward assessments that translate primary risks into estimated financial losses, frequency, and annual exposure.
The keys to a financial evaluation of IT risk in 20 seconds
- Info-Tech questions the traditional matrices based solely on high, medium, or low risk.
- It proposes quantifying the prioritized risks economically, not necessarily all threat categories.
- The analysis combines impact of a loss, estimated frequency, and expected annual loss.
- NIST also recognizes that quantitative methods can improve prioritization and justify treatments before management.
- The goal is to compare the cost of reducing a risk with the actual economic exposure it represents.
The proposal comes at a time when technology leaders must explain very different risks within the same budget discussion. A ransomware attack, data center downtime, critical cloud provider dependency, data breach, or regulatory sanctions might all appear marked in red on a matrix, but that doesn’t automatically determine which should receive the available budget first.
This is the problem Info-Tech aims to solve with its Execute Data-Driven Risk Assessments methodology. The firm does not suggest abandoning qualitative assessments entirely but recommends using them as a first filter and reserving more detailed economic analysis for exposures that truly justify it.
The problem with simply calling a risk “high”
Risk matrices have an obvious advantage: they allow quick work with probability and impact, presenting results in an understandable way.
They also have limitations.
Declaring that a cyberattack has a “high” risk can serve to grab attention, but provides little information when management must decide whether to invest 300,000 euros in strengthening security, upgrading a critical platform, or funding another business project.
Info-Tech also highlights issues such as the subjectivity of scores, data dispersion across departments, and the difficulty of maintaining overly complex quantitative models.
The alternative isn’t simply replacing “high” with a 8 out of 10. An ordinal scale remains a classification even if it uses numbers.
The National Institute of Standards and Technology (NIST) specifically distinguishes qualitative and quantitative analyses. In its December 2025 review on integrating cybersecurity and enterprise risk management, it states that quantitative analysis can use probabilities and monetary valuations of losses, providing more justifiable evidence to prioritize treatments before management. It also warns that quality depends on the data and models used.
The nuance matters: assigning a monetary value to a risk does not automatically make that estimate certain.
Risk still pertains to future events and, therefore, involves uncertainty.
From risk traffic lights to calculating how much the company could lose
Info-Tech proposes a four-phase process.
First, build or review the risk register using a common taxonomy. Then, perform a qualitative evaluation of probability and impact, which helps distinguish priority risks from those that do not require detailed economic study.
In the third phase, the conversation shifts.
The methodology suggests estimating three elements: Single Loss Impact (SLI), representing the impact of an individual loss; Occurrence Frequency (OF), indicating how often the scenario could happen; and Annualized Loss Expectancy (ALE), the expected annual loss.
A simplified example helps illustrate this.
An organization might analyze how much it would cost if a specific service were interrupted, considering lost activity, recovery costs, staff hours, contractual commitments, or other justifiable costs. Next, it would estimate how often this scenario might occur.
The result ceases to be just:
“Availability risk: high”.
and instead becomes an economic estimate expressed through scenarios or ranges. This enables a more useful business question: how much does it cost to reduce exposure, and what economic risk remains afterward?
Finally, Info-Tech recommends communicating these results to business managers and leadership to decide on the next steps.
This approach is similar to FAIR (Factor Analysis of Information Risk), a quantitative model used to analyze information and operational risks based on the probable frequency and magnitude of losses. Its standard emphasizes that uncertainty should be explicitly incorporated into calculations through ranges or distributions rather than presenting a single figure as an exact prediction.
A tool for deciding where to spend, not for predicting the future
Practical value emerges when comparing different options.
Suppose a company identifies two “high” risks: a prolonged internal application outage and a ransomware incident.
Traditional matrices might place them at nearly the same level. Financial analysis aims to answer additional questions: what losses each scenario could cause, how often they might occur, how much a specific measure could reduce exposure, and how much it would cost to implement.
This allows comparing investments in backup, disaster recovery, redundancy, security, business continuity, training, or infrastructure using a language closer to that of financial management.
It also helps avoid the opposite problem: spending significant money on a technically appealing threat whose economic exposure is lower than less visible risks.
However, quantification does not eliminate the need for professional judgment.
NIST reminds us that quantitative methods require sufficiently reliable data, which is not always possible or appropriate. Even with incomplete data, structuring the analysis can improve understanding of variables, though results will still carry uncertainty.
Therefore, it’s more reasonable to work with ranges and probabilities rather than convincing the board that a specific incident will cost exactly €2,473,621.
FAIR aligns with this philosophy: it defines risk through probable frequency and magnitude of future losses and explicitly recommends modeling uncertainty.
For CIOs and CISOs, the implications are significant. Budget discussions can shift from “it needs to be done because the risk is red” to explaining the estimated exposure, the factors driving it, how much an investment can reduce it, and the residual risk the organization ultimately accepts.
Info-Tech supports its methodology with tools to develop assessments and communicate results to risk owners. Its approach does not require quantifying every threat from the start; instead, it suggests using qualitative analysis first to identify where efforts are most justified.
This hybrid approach is likely one of its most practical aspects. Color-coded matrices can still be useful for organizing dozens or hundreds of risks. Problems arise when the same system is expected to also guide investment decisions.
Frequently Asked Questions
What is a quantitative IT risk assessment?
It is an analysis that attempts to express exposure through measurable variables, such as probable frequency and monetary impact, rather than limiting results to categories like high, medium, or low risk.
Do all risks need to be financially calculated for a company?
Not necessarily. Info-Tech’s methodology proposes starting with qualitative assessments to prioritize and then applying a deeper financial analysis to the most significant risks.
What does ALE mean in risk management?
ALE stands for Annualized Loss Expectancy, representing the expected monetary loss over a year for a particular scenario.
Do risk matrices in high, medium, low categories become useless?
No. They can still serve as quick initial classification and prioritization tools. Their limitation appears when they are used alone to justify investments or to compare different risk reduction options economically.
via: prnewswire

