All insights

Risk Quantification

Your Risk Program Is Running on Yesterday's Weather

Most cyber risk programs produce reports. The ones that matter produce decisions. Here's the difference, and why it's getting harder to ignore.

Jason Walker

.6 min read

Imagine you are a ship captain who gets a weather report every quarter. The report is thorough, professionally formatted, and delivered on time. It tells you exactly what conditions looked like when the data was collected. You read it, file it, and make navigation decisions based on it for the next ninety days.

That is most enterprise cyber risk programs right now.

The report is not wrong. The methodology is not broken. The problem is the gap between when the information was true and when you are trying to use it. Risk is not a quarterly phenomenon. The environment your report described no longer exists. You are navigating live water with a map drawn months ago.

This is the specific failure mode that the cyber risk profession has not fully reckoned with yet. We spent the last decade solving a different problem: getting risk out of technical jargon and into business language. That work was real and necessary. Boards could not act on "we have a critical finding in the vulnerability scanner." They could act on "this exposure carries a quantified expected loss that exceeds our risk tolerance." Cyber Risk Quantification, FAIR methodology, the whole push toward economic framing: all of it was aimed at translation. And the translation problem is largely solved.

The new problem is velocity.

The environment now changes faster than a quarterly cycle can capture. A new threat actor campaign, a third-party vendor compromise, a regulatory interpretation shift, a generative AI tool that half your workforce started using without IT involvement: none of these wait for your next risk committee meeting. By the time your well-crafted report lands on the board agenda, some of the assumptions baked into it have already expired.

I run enterprise cybersecurity across a large state government. Dozens of agencies. Hundreds of thousands of devices. The threat environment is not theoretical for me. It is a live operational environment where the conditions that define risk change week to week. If my team produced a quarterly risk report and called it done, I would be governing a fiction. The report would be accurate as of its creation date and increasingly wrong about everything after that.

The question I started asking is: what does it actually take to turn a risk program into something that informs decisions in real time rather than documenting conditions that already changed?

The answer is not more data. That is the trap. The instinct when information feels stale is to collect more of it, faster, from more sources. You end up with dashboards that scroll past anyone's ability to interpret them. Data volume is not the same as risk intelligence. Intelligence means the data has been processed, contextualized, and connected to a decision that someone actually needs to make.

Weather forecasting is instructive here. The National Weather Service does not give you raw atmospheric pressure readings and ask you to draw your own conclusions. It processes sensor data continuously, runs models, and outputs a forecast specifically designed to answer the question you are actually asking: do I need an umbrella, should I reschedule the outdoor event, is the flight going to be delayed. The analysis exists to support a decision. The decision determines what the analysis needs to answer.

Most risk programs are stuck producing the equivalent of raw atmospheric pressure readings. The data exists. The methodology is sound. But the output is not connected to a decision. It is connected to a reporting cycle.

The organizations getting this right have made a structural shift. They treat risk intelligence as an operational function, not a compliance function. The difference is in what the output is designed to do. Compliance output goes into a report. Operational output goes into a decision. Who gets briefed, what investment is approved, what control gets prioritized, which third-party relationship gets re-evaluated: these are decisions, not findings.

AI makes this both more urgent and more tractable. More urgent because AI adoption inside organizations is happening at a pace that makes traditional risk assessment look like continental drift. By the time a risk assessment of an AI deployment is complete, the deployment has often already changed. More tractable because AI tooling genuinely helps with the analytical workload: correlating threat intelligence, modeling exposure changes, surfacing decision-relevant signals from the noise. The same technology creating new risk categories is also part of what makes continuous risk intelligence feasible at scale.

The governance problem around AI specifically is real. I am watching organizations deploy AI tools with enthusiasm and appropriate ambition, and struggle to answer basic questions about where the risk actually sits. Traditional cyber risk categories do not map cleanly onto AI risk. Model behavior, training data provenance, third-party inference dependencies, regulatory obligations that are still being written: the taxonomy is incomplete, which means the quantification is incomplete, which means the governance is operating on instinct more than intelligence.

This is where the "one enterprise risk language" idea becomes more than a conference theme. The organizations that govern AI well will not treat AI risk as a separate discipline managed by a separate team with separate reporting. They will apply the same quantitative framework they use for cyber risk broadly, extended and adapted for AI-specific factors. One language, one methodology, one way of expressing risk in business terms that allows the CFO and the CISO and the CRO to look at the same number and make a shared decision.

The practical implication for anyone running a risk program: stop optimizing the report and start optimizing the decision.

Ask what decisions your risk output is actually supposed to inform. Ask whether those decisions are being made on the schedule your reporting cycle supports, or on the schedule the business actually operates at. Ask whether the people making decisions are getting information that reflects current conditions or conditions from last quarter.

If the answer to that last question is "last quarter," you are not running a risk program. You are running a history project.

The profession has done the hard work of earning credibility at the executive table. The next job is staying relevant once you are there. That means building the capability to answer the question that actually matters in any given week: given what is happening right now, where does the risk sit, and what should we do about it?

That is a harder problem than quantification. It is also the only problem left worth solving.

Keep reading

Weekly writing from inside the work.

Practitioner-researcher essays four times a week. No spam, unsubscribe in one click.

Subscribe

Weekly writing from inside the work.

Field observations and framework critiques from a practitioner-researcher running cybersecurity at scale. AI in operations, FAIR risk research, and the leadership patterns that hold both together. No spam. Unsubscribe in one click.