<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="http://societyinforisk.org/page-8689/BlogPost/4052936/RSS" rel="self" type="application/rss+xml" />
    <title>Society of Information Risk Analysts SiRA Blog</title>
    <link>https://societyinforisk.org/</link>
    <description>Society of Information Risk Analysts blog posts</description>
    <dc:creator>Society of Information Risk Analysts</dc:creator>
    <generator>Wild Apricot - membership management software and more</generator>
    <language>en</language>
    <pubDate>Sat, 11 Apr 2026 20:45:58 GMT</pubDate>
    <lastBuildDate>Sat, 11 Apr 2026 20:45:58 GMT</lastBuildDate>
    <item>
      <pubDate>Thu, 09 Apr 2026 20:39:49 GMT</pubDate>
      <title>ROI of Security Investments: A Quantitative Approach</title>
      <description>&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;In the previous post, we looked at how Cyber Risk Quantification (CRQ) helps organizations right‑size cyber insurance by grounding coverage decisions in quantified loss scenarios. Once risks are expressed in financial terms, a natural follow‑on question emerges:&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;How do we know whether our security investments are actually worth it?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;Security leaders are constantly asked to justify spend. They need to present some way to measure the return on things like new tools, additional headcount, control improvements, etc., and without the right data, these answers tend to be qualitative. Investments are described as “necessary,” “best practice,” or “industry standard,” rather than evaluated as financial decisions. CRQ provides a way to change that. We can’t necessarily call it ROI, because unless the security spend can be marketed to customers as a selling point, there isn’t a real return. Spending money on cyber protections like tooling or headcounts does not provide a return, it provides a reduction in potential losses. In the same way we buy property insurance to prevent major financial losses on fires and storms, we invest in cyber programs to reduce financial losses on cyber events.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;By quantifying how controls affect loss exposure, organizations can evaluate security investments using the same economic logic applied elsewhere in the business.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Why security ROI is so hard to articula&lt;/FONT&gt;&lt;FONT color="#000000"&gt;te&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Security ROI is difficult not because value doesn’t exist, but because it is rarely measured in the right units.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;Most organizations evaluate security investments using proxies:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Number of vulnerabilities closed&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Control maturity scores&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Audit findings&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Benchmark comparisons&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;These measures can be useful for operational management, but they do not answer the question executives care about:&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;What is the financial impact? In dollars and cents, please!&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;How am I supposed to justify a $500,000 spend to move our company from G3 to G5 Microsoft licenses without looking at how the additional security capabilities will reduce exposure? At that point, the perceived benefit is nothing more than optics. This way of pitching the investment turns these conversations into subjective debates rather than financial trade-offs.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;CRQ reframes security spend as loss reduction&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;As we said above, security investment is about reducing expected loss. Controls do not create revenue; they reduce the likelihood or magnitude of adverse outcomes.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;CRQ makes financial outcomes tangible by tying controls directly to quantified loss scenarios in the risk register. Instead of asking whether a control is “good,” leaders can ask:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Which loss scenarios does this control affect?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;How does it change loss frequency or magnitude?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;How much expected loss does it reduce?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;This reframing turns security spend into a risk‑reduction investment, comparable to decisions made in insurance, safety, or operational resilience.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Establishing a baseline before investing&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Meaningful ROI analysis requires a baseline. CRQ provides that baseline by quantifying current loss exposure across defined scenarios. This establishes:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Expected annual loss&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Loss distributions across scenarios&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Key drivers of frequency and magnitude&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;Without this starting point, any claim about improvement is speculative. With it, control changes can be evaluated relative to a known exposure profile rather than an abstract notion of “better security.”&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Modeling control impact on loss exposure&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Once baseline exposure is quantified, proposed security investments can be modeled as changes to the underlying risk factors. For example, a control might:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Reduce the probability of successful phishing&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Lower the expected duration of a ransomware outage&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Limit the scope of data exfiltration&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Reduce regulatory response costs&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;CRQ allows these changes to be reflected directly in the loss model. The result is a revised loss distribution that can be compared to the baseline. The difference between the two distributions represents the expected risk reduction attributable to the control. From this perspective, security ROI becomes a straightforward comparison, dollar for dollar:&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;How much expected loss does this investment reduce relative to its cost?&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Comparing investments, not just justifying them&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;One of the most powerful benefits of a quantitative approach is the ability to compare competing investments. Rather than evaluating controls in isolation, organizations can assess:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Which investment reduces the most risk per dollar?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Where do diminishing returns set in?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;Which controls address the largest drivers of loss?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;This often leads to unintuitive but valuable insights. In many cases, modest investments in detection, response, or resilience reduce expected loss more effectively than expensive preventive controls. CRQ makes these trade‑offs visible. We can ignore how “flashy” something might be, and choose based on dollar for dollar, what brings a company the most bang for their buck.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Avoiding the illusion of “high ROI” controls&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Quantification also helps avoid a common pitfall: overstating ROI based on worst‑case thinking. This is not to say that worst-case thinking isn’t important—it absolutely is. But in the case of justifying spending, we want to avoid using Fear, Uncertainty, and Doubt (FUD) as a way of getting a board to approve a budget increase.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;Why not…try? In theory, it is easy to justify almost any security investment by pointing to a catastrophic breach scenario. I’ll walk in and tell my board that a ransomware attack will shut our operations down for 6 months, and we will never financially recover. Easy! But not all extreme losses are equally likely, and not all controls meaningfully reduce those outcomes.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;By focusing on expected loss rather than anecdotes, CRQ keeps ROI analysis grounded. Controls that sound compelling but have little impact on modeled exposure are revealed as low‑return investments, regardless of how alarming the threat narrative may be.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Using ROI to inform, not replace, judgment&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;A quantitative approach does not eliminate judgment. It structures it. CRQ does not dictate which controls must be funded, but it provides a disciplined way to understand the economic implications of those choices. Leaders still weigh qualitative factors like regulatory expectations, strategic priorities, and risk appetite… but they do so with a clearer understanding of the financial stakes. Quantitative analysis does not eliminate the need for qualitative inputs; it enhances them. Critically, ROI analysis can help explain why some risks are intentionally accepted. Not every exposure is cost‑effective to mitigate, and CRQ provides a defensible rationale for those decisions.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Keeping ROI aligned as the environment changes&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Just as with insurance, security ROI is not static. As threat patterns evolve, new technologies are introduced, or the business changes, the effectiveness of controls shifts. CRQ allows ROI assumptions to be revisited as part of an ongoing risk management process rather than treated as one‑time justifications. Over time, this creates a feedback loop where investments are evaluated, adjusted, and prioritized based on observed changes in exposure.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Why this matters&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Security leaders are increasingly expected to operate as stewards of financial risk, not just technical defenses. Being able to explain how investments reduce loss and how much they reduce it changes the conversation.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;FONT color="#000000"&gt;CRQ allows security ROI to move from narrative to analysis. If done properly, decisions are explainable and comparable. All that time spent showing my work on my 5th grade math tests is now paying off. Forcing me to show my work set me up to make it in the CRQ big leagues! I learned that just presenting an answer without showing any work, even if it’s correct, raises concerns. Did I cheat and use a calculator? Did I just happen to make a really good guess? Successful budget requests backed by CRQ are defendable. The audience should be able to see what the inputs are, how they were used, and how they got to the final answer. This isn’t a magic trick.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 24px;"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;And for the moment we’ve all been waiting for…&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt;In my last few blogs, I’ve covered all the wonderful things that CRQ can do. And while it’s easy to get caught up in the adrenaline rush of monte carlo simulations and loss exceedance curves, we’re not just doing this for fun! All of this work is done so cyber teams earn their spot on the Avenger’s Squad (Enterprise Risk Management Teams). And in the next (final) blog in this series, I will walk through how that can be done successfully.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;BR&gt;&lt;/P&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13618945</link>
      <guid>https://societyinforisk.org/Blog-Posts/13618945</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Thu, 26 Mar 2026 16:35:12 GMT</pubDate>
      <title>Cyber Insurance: Using Quantification to Right-Size Coverage</title>
      <description>&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;In the previous post, we looked at how a cyber risk register with quantified loss magnitudes transforms cybersecurity from a list of concerns into a decision-support tool. One of the most immediate places that transformation shows up is cyber insurance.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Cyber insurance is often purchased in the dark. Organizations buy coverage limits based on benchmarks, broker recommendations, or what “feels reasonable,” rather than on a clear understanding of their actual financial exposure. The result is predictable: some firms are materially underinsured, while others overpay for coverage that provides little incremental value.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Cyber Risk Quantification (CRQ) changes this dynamic. By grounding insurance decisions in quantified loss scenarios, organizations can right-size coverage to match their true risk profile.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Why cyber insurance decisions are so often misaligned&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Many organizations approach cyber insurance as a compliance checkbox or a market norm. Questions tend to sound like:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;“What limit do companies our size usually buy?”&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;“What did we carry last year?”&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;“What does the broker recommend?”&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;While these inputs are not useless, they are indirect. None of them answer the core question insurance is meant to address:&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;What financial loss are we trying to transfer?&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Without quantified loss information, coverage limits are essentially guesses. Even worse, those guesses are rarely revisited as the business, threat landscape, or control environment changes.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Reframing insurance as loss transfer&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;At its core, cyber insurance is a financial instrument. Its purpose is not to “cover cyber risk” in the abstract, but to transfer specific loss outcomes from the organization to an insurer.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;CRQ makes this explicit by tying insurance decisions directly to loss scenarios already defined in the risk register. Instead of asking how much coverage to buy in general, leaders can ask:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Which loss scenarios are insurable?&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;How large could those losses reasonably be?&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Which portions of that loss do we want to retain versus transfer?&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;This reframing moves insurance out of the realm of guesswork and into the same financial logic used for other risk transfer decisions.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Using quantified loss distributions to set limits&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;One of the most powerful applications of CRQ is comparing insurance limits to quantified loss distributions.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Rather than relying on a single “worst-case” number, CRQ produces a range of potential losses with associated probabilities. This allows organizations to see, for example:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Losses they expect to absorb regularly&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Losses that are unlikely but plausible&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Extreme tail events that could threaten financial stability&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Insurance can then be aligned to specific parts of that distribution. For instance:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Retain frequent, low-severity losses through deductibles or self-insurance&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Transfer low-frequency, high-severity losses that would materially impact the business&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;This approach ensures that insurance is focused where it actually adds value.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Avoiding the trap of over-buying&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Over-buying cyber insurance is less visible than under-buying, but it is just as costly.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;When coverage limits significantly exceed plausible loss magnitudes, organizations pay premiums for protection they are unlikely to ever use. Quantification helps reveal when additional layers of coverage provide diminishing returns.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;CRQ enables questions like:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;How much incremental risk reduction does this additional layer actually provide?&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Are we insuring losses we would already tolerate?&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Would that premium be better spent reducing the underlying exposure instead?&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;In many cases, quantification shows that modest improvements in controls reduce expected loss more effectively than purchasing ever-higher limits.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Understanding gaps, exclusions, and sublimits&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Another benefit of a quantified approach is clarity around what insurance does&lt;/FONT&gt; &lt;EM&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;not&lt;/FONT&gt;&lt;/EM&gt; &lt;FONT style="font-size: 15px;" color="#000000"&gt;cover.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Policies often include exclusions, sublimits, and conditions that significantly constrain payouts. Without a quantified view of loss components, these limitations can go unnoticed.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;By mapping loss magnitude components (for example, business interruption, regulatory fines, or incident response) against policy terms, organizations can see:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Which losses are meaningfully transferred&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Which losses remain largely retained&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Where coverage appears adequate in name but not in practice&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;This analysis often leads to more productive discussions with brokers and underwriters, grounded in specifics rather than generalities.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Supporting negotiations with data, not anecdotes&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Insurance negotiations are more effective when buyers can articulate their risk profile clearly.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;A quantified risk register provides:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Documented assumptions&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Transparent methodology&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;"&gt;Clear links between controls and reduced loss&lt;/FONT&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;This positions the organization as a disciplined risk buyer rather than a passive purchaser. Over time, this can support better pricing, more appropriate limits, and more tailored coverage structures.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Keeping insurance aligned as risk evolves&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Cyber risk is not static, and neither should insurance be.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;As organizations implement new controls, migrate systems, acquire companies, or change operating models, their loss distributions shift. CRQ allows insurance decisions to evolve alongside those changes.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Instead of renewing last year’s policy by default, leaders can revisit coverage based on updated exposure, ensuring continued alignment between retained risk, transferred risk, and overall risk appetite.&lt;/FONT&gt;&lt;/P&gt;

&lt;H3 style="line-height: 33px;"&gt;&lt;FONT style="font-size: 17px;" color="#000000"&gt;&lt;STRONG&gt;Why this matters&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Right-sizing cyber insurance is not about minimizing premiums or maximizing limits. It is about making intentional, financially grounded decisions about which losses the organization is willing to bear and which it is not.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;By using quantified loss information, cyber insurance becomes a strategic tool rather than a blunt instrument. Coverage decisions are explainable, defensible, and aligned with the broader risk management strategy.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;In the next post, we’ll turn to another common question leaders ask once risks are quantified: how to evaluate the return on security investments, and how CRQ enables a more rigorous, financially grounded view of cybersecurity ROI.&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;BR&gt;&lt;/P&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13614008</link>
      <guid>https://societyinforisk.org/Blog-Posts/13614008</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Fri, 06 Mar 2026 18:09:48 GMT</pubDate>
      <title>Building a Cyber Risk Register with Quantified Loss Magnitudes</title>
      <description>&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;In the previous post, we explored why Cyber Risk Quantification (CRQ) matters to the business: it translates cyber risk into financial terms that leaders can actually use. But translation alone isn’t enough. That insight needs a place to live, evolve, and inform decisions over time.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;For most organizations, that place is the&lt;/font&gt; &lt;font color="#000000" face="Arial, sans-serif"&gt;risk register&lt;/font&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;. Making decisions without a quantified risk register is like a lender assessing credit using color-coded impressions instead of financial statements.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Traditionally, cyber risk registers have been lists of technical concerns scored using qualitative labels or heat maps. CRQ doesn’t replace the risk register; it redefines its purpose. Instead of being a static catalog of issues, the register becomes a living view of the organization’s financial cyber risk exposure.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Why traditional cyber risk registers fall short&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A typical cyber risk register might include entries like “Ransomware,” “Third‑party risk,” or “Data breach,” each scored as high, medium, or low. While this format can be useful for tracking issues, it often breaks down when the register reaches executive or board audiences.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A “high” risk label doesn’t answer the questions leaders actually have:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;How much financial exposure does this represent?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Is this risk material to the organization?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;How does it compare to other enterprise risks?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;What would reducing it actually buy us?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Without quantified loss information, the risk register becomes descriptive rather than decision‑supportive. It tells leaders&lt;/font&gt; &lt;em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;what exists&lt;/font&gt;&lt;/em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;, but not&lt;/font&gt; &lt;em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;what matters most&lt;/font&gt;&lt;/em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Reframing the register around loss scenarios&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A CRQ‑enabled risk register starts with a shift in how risks are defined. Instead of listing abstract categories or control gaps, each entry is framed as a loss scenario.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A loss scenario describes:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;What happens (the event)&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Why it happens (the threat or failure)&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;What the business loses as a result&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;For example, rather than “Cloud misconfiguration,” a quantified risk register might describe:&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A cloud access control failure leads to unauthorized access to sensitive customer data, resulting in regulatory fines, incident response costs, and customer churn.&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;This framing matters because businesses don’t experience “risks”, they experience losses. The clearer the loss scenario, the easier it is to reason about impact.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Introducing quantified loss magnitudes&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Once risks are framed as loss scenarios, CRQ adds the missing dimension: financial magnitude.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Loss magnitude represents the range of financial impact that could reasonably result if the scenario occurs. Importantly, this is not a single number. It reflects uncertainty and variability, acknowledging that no two incidents unfold the same way.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Loss magnitude typically considers multiple cost components, such as:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Incident response and recovery&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Business interruption&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Legal, regulatory, and compliance costs&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Downstream impacts like reputational harm or customer loss&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;By capturing these components, the risk register begins to show&lt;/font&gt; &lt;em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;why&lt;/font&gt;&lt;/em&gt; &lt;font color="#000000" face="Arial, sans-serif"&gt;certain risks are more significant than others, not just that they feel concerning.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Separating frequency from severity&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;One of the most valuable conceptual shifts in a quantified risk register is the separation of how often something might happen from how severe it could be.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Traditional registers often blur these concepts together. A risk might be rated “high” because it’s frequent, severe, or both - but the distinction matters for decision‑making.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;CRQ forces clarity:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Some risks occur often but have relatively limited financial impact.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Others occur rarely but carry the potential for outsized losses.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A register that captures quantified loss magnitudes allows organizations to see these differences clearly and avoid prioritizing the wrong problems simply because they are more visible or familiar.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;From ranking risks to comparing exposure&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;When risks are expressed in financial terms, the risk register evolves from a ranking exercise into a portfolio view of exposure.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;This enables new, more productive conversations:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Which scenarios contribute most to our expected annual loss?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Where are we most exposed to tail risk or extreme outcomes?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Are multiple risks driven by the same underlying weaknesses?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Which risks are already well within our risk appetite?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Instead of asking which risks are “red,” leaders can ask which risks are material.This can even support the SEC’s reporting requirements around material cyber events, because they can define “material” in financial terms before an incident occurs..&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Embracing uncertainty without losing credibility&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A common concern with quantified risk registers is accuracy. Estimating future cyber losses can feel uncomfortable, especially to technical teams accustomed to precision.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;CRQ addresses this by being explicit about uncertainty:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Estimates are ranges, not point values&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Assumptions are documented and revisited&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Outputs are probabilistic, not deterministic&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;This approach mirrors how other enterprise risks are managed. Forecasts, reserves, and capital models are never perfect, but they are still essential for disciplined decision‑making. Cyber risk is no different.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Keeping the register actionable&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A quantified cyber risk register is only valuable if it remains connected to action. To do that, organizations should ensure the register:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Reflects real business processes and assets&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Is updated as controls, technology, and threats change&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Links risk reduction efforts to expected loss reduction&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Feeds directly into budgeting, insurance, and ERM discussions&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;When a proposed control can be evaluated in terms of how much financial exposure it reduces, prioritization becomes far more rational, and far easier to explain.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Why this matters&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A cyber risk register with quantified loss magnitudes changes the role of cybersecurity in the organization. It moves the function from reporting concerns to supporting decisions through explainable records that can be easily analyzed.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Instead of asking leaders to trust subjective scores or intuition, it provides a structured, transparent view of cyber risk as a business problem. One that can be compared, debated, and managed alongside every other risk the organization faces.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;In the next post, we’ll look at how this same quantified approach helps organizations right‑size cyber insurance coverage: avoiding both under- and over‑buying by grounding decisions in actual exposure.&lt;/font&gt;&lt;/p&gt;&lt;br&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13606680</link>
      <guid>https://societyinforisk.org/Blog-Posts/13606680</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Thu, 12 Feb 2026 17:07:21 GMT</pubDate>
      <title>Why Cyber Risk Quantification Matters to the Business</title>
      <description>&lt;h1 style="line-height: 51px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Why Cyber Risk Quantification Matters to the Business&lt;/font&gt;&lt;/h1&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;As cyber risk has become more visible, more costly, and more central to business operations, organizations are under increasing pressure to explain it clearly and manage it deliberately. Yet despite widespread agreement that cyber risk matters, many leaders still struggle to compare it to other enterprise risks or use it to inform real decisions. This post is part of a broader exploration of Cyber Risk Quantification (CRQ). Not as a technical exercise, but as a way to translate cyber risk into decision-ready business insight.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Most executives already agree on one thing: cyber risk is important.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;What’s far less clear is how important it is, how it compares to other risks the organization faces, and what they should do differently as a result. That uncertainty isn’t a failure of awareness; it’s a failure of translation. It’s the difference between knowing there’s a pretty bad storm somewhere ahead and having the coordinates to steer around it.&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Cybersecurity has traditionally been discussed in technical language: vulnerabilities, controls, maturity levels, threat actors, etc. While this concepts matter operationally, they rarely align with how business leaders are trained to think and decide. Boards and executives don’t manage risks in red, yellow, and green. They manage them in terms of financial exposure, trade-offs, and opportunit cost.&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;This is where Cyber Risk Quantification (CRQ) becomes essential.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;CRQ translates cyber risk into financial terms that business leaders already use every day. Instead of asking leaders to interpret abstract scores or heat maps, it frames cyber risk in the same language as market risk, operational risk, and legal risk: potential loss, probability, and uncertainty. When cyber risk is expressed this way, it stops being a mysterious technical concern and starts behaving like a normal business problem. It’s one that can be discussed, compared, and managed.&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;h2 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;The limits of traditional cyber risk conversations&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;For many organizations, cyber risk reporting still centers on compliance status, control maturity, or qualitative risk ratings. These approaches are not inherently wrong, but they tend to break down at the executive level.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A heat map might tell a board that ransomware risk is “high,” but it doesn’t explain what that actually means for the business. Does “high” imply a minor operational disruption or a material earnings event? Is it more significant than a supply‑chain interruption or a regulatory fine? And perhaps most importantly, is the organization already spending too much, or too little, to manage it?&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Without financial context, these questions are almost impossible to answer. As a result, cyber risk discussions often become reactive. Funding decisions are driven by the latest incident in the news, a regulatory finding, or a sense of unease rather than a clear understanding of exposure and trade‑offs.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;CRQ exists to close that gap.&lt;/font&gt;&lt;/p&gt;

&lt;h2 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;What changes when cyber risk is quantified&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;At its core, CRQ reframes cyber risk as a question of&lt;/font&gt; &lt;font color="#000000" face="Arial, sans-serif"&gt;economic impact under uncertainty&lt;/font&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;. Rather than assigning a label to a risk, it estimates how often a loss event might occur and what the financial consequences could reasonably look like. Importantly, this is done using ranges and probabilities, not single “magic numbers.”&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;The difference may sound subtle, but it fundamentally changes the conversation.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Instead of hearing that a risk is “high,” executives hear that there is a realistic chance of a multi‑million‑dollar loss in a given year, with identifiable drivers that influence both likelihood and severity. Suddenly, cyber risk becomes comparable to other enterprise risks. It can be discussed in risk committees, weighed against strategic initiatives, and aligned with the organization’s risk appetite.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;This doesn’t make cyber risk predictable, but it does make it intelligible.&lt;/font&gt;&lt;/p&gt;

&lt;h2 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Why executives and boards care&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;From a leadership perspective, the value of CRQ is not in mathematical elegance; it’s in decision support.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Executives are constantly making resource allocation decisions under uncertainty. They decide how much to invest in resilience, insurance, compliance, and growth without perfect information. CRQ gives them a clearer basis for those decisions by showing how cybersecurity investments influence potential financial outcomes.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;It also helps answer one of the most persistent and uncomfortable questions in cybersecurity:&lt;/font&gt; &lt;em&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Are we spending the right amount?&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Without quantification, security budgets are difficult to defend. Spending increases can feel arbitrary, and reductions can feel reckless. CRQ provides a way to link investment levels to expected risk reduction, allowing leaders to see not just what they are spending, but what they are buying in terms of reduced exposure.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;For boards, this clarity is increasingly critical. Regulatory expectations and fiduciary scrutiny around cyber oversight are rising, and boards are expected to demonstrate informed judgment, not just awareness. CRQ helps boards show that cyber risk is being evaluated with the same rigor applied to other material risks.&lt;/font&gt;&lt;/p&gt;

&lt;h2 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;CRQ and enterprise risk management&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Another reason CRQ matters to the business is that it enables cyber risk to be fully integrated into enterprise risk management (ERM).&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Most ERM programs already rely on financial modeling and loss estimates to evaluate risks like litigation, credit exposure, or operational disruption. Cyber risk has often sat outside this framework, discussed separately and scored differently. This separation makes it harder to prioritize risks across the enterprise and harder to align cyber decisions with broader business objectives.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;By expressing cyber risk in financial terms, CRQ allows it to be evaluated alongside other enterprise risks. It becomes easier to see where cyber scenarios rank relative to non‑cyber threats, and easier to decide where leadership attention and capital should be focused.&lt;/font&gt;&lt;/p&gt;

&lt;h2 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;A note on precision - and why it’s not the point&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;One of the most common objections to CRQ is concern about accuracy. After all, how can anyone reliably estimate the cost of a future cyber event?&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;The answer is that CRQ is not about perfect prediction. It’s about&lt;/font&gt; &lt;font color="#000000" face="Arial, sans-serif"&gt;reasonable estimation and transparency&lt;/font&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;. Good CRQ explicitly acknowledges uncertainty, documents assumptions, and focuses on ranges rather than exact figures. In practice, this often leads to more credible discussions, not less.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Executives are accustomed to making decisions based on forecasts, scenarios, and incomplete data. What they need is not certainty, but a clear understanding of what drives risk and how different choices influence potential outcomes. CRQ provides that structure.&lt;/font&gt;&lt;/p&gt;

&lt;h2 style="line-height: 41px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Why this matters now&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Cyber losses are becoming more visible, more material, and more disruptive. At the same time, organizations face increasing pressure to justify security spending and demonstrate sound governance. In this environment, relying on purely qualitative or technical risk descriptions is no longer sufficient.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Organizations that can explain cyber risk in business terms are better positioned to make disciplined investments, engage their boards effectively, and avoid both overreaction and complacency.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 24px;"&gt;&lt;font color="#000000" face="Arial, sans-serif"&gt;Cyber Risk Quantification doesn’t eliminate cyber risk, but it does make it manageable in the way business leaders expect.&lt;/font&gt;&lt;/p&gt;&lt;br&gt;
&lt;br&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13597460</link>
      <guid>https://societyinforisk.org/Blog-Posts/13597460</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Tue, 30 Sep 2025 11:52:29 GMT</pubDate>
      <title>SiRAcon '25 Highlights and Recap: Day 3</title>
      <description>&lt;H1&gt;&lt;FONT style="font-size: 21px;" color="#000000"&gt;&lt;U&gt;SiRAcon ’25 Highlights&lt;/U&gt;&lt;/FONT&gt;&lt;/H1&gt;

&lt;H2&gt;&lt;FONT style="font-size: 21px;" color="#000000"&gt;&lt;STRONG&gt;From Zero to Quant to ERM&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;&lt;BR&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;SiRAcon ’25 took place last week Sep. 9-11, 2025 at the Boston Federal Reserve in Boston, MA, which marks the second year that SiRAcon has occurred at this venue.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;The event theme this year was “From Zero to Quant to ERM,” building on last year’s theme of “From Zero to Quant” and emphasizing the need to have conversations about cybersecurity risk as part of broader enterprise risk management decisions. Presentations reinforced this theme and brought in considerations for AI, industry standards to aid adoption, and steps for continued growth based on learnings from the past.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;The event saw more than 100 attendees between in-person and virtual attendees, and the SiRA Slack and Zoom chat allowed for lively and energizing discussion and debate across the event. As always, the SiRA community was engaged and thought-provoking throughout the week, with excellent conversations taking place during breaks across the event. The sense of community at this conference is always amazing!&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;If you happened to miss this year’s SiRAcon but registered, you can still&lt;/FONT&gt;&lt;/EM&gt; &lt;A href="https://web.cvent.com/event/aea3fabb-28f2-48e0-99b7-9eab5e226ee4/summary"&gt;&lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;access session recordings&lt;/FONT&gt;&lt;/EM&gt;&lt;/A&gt; &lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;through the event site. If you did not register, the recordings will soon be added to the Members’ Area of&lt;/FONT&gt;&lt;/EM&gt; &lt;A href="http://www.societyinforisk.org"&gt;&lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;www.societyinforisk.org&lt;/FONT&gt;&lt;/EM&gt;&lt;/A&gt; &lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;and you can access them (as well as recordings from previous SiRAcons and past webinars) by becoming a Member of SiRA:&lt;/FONT&gt;&lt;/EM&gt; &lt;A href="https://societyinforisk.org/join"&gt;&lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;https://societyinforisk.org/join&lt;/FONT&gt;&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;H4&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;U&gt;Day 3: Thursday, Sep. 11, 2025&lt;/U&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/H4&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;U&gt;Keynote: The Evolving Landscape of Risk Quantification: Past, Present, and Future&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Jack Jones&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;The final keynote presenter of SiRAcon ’25 was Jack Jones, who provided a historical perspective of cybersecurity risk management. Jack connected the world of cyber risk to the medical industry, bringing in the notion of “Cybersecurity 2.0,” which will be characterized by consistent terminology and causal probabilistic models, quantitative ranges and distributions, and empirical data focus with forecasting evaluation. Jack also touched on AI, highlighting its potential value in scenario engineering and threat modeling.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;U&gt;Cross-Industry Lessons in Risk Quantification: Medical, Aviation, and Shipping Perspectives&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Didier Jourdain&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Continuing the trend of looking at other industries for lesson to be learned, Didier Jourdain utilized examples from the medical, aviation, and shipping industries to suggest an efficient approach to decision making. Didier noted the use of ordinal scales in these industries when rapid decision-making is required, noting the familiarity of these scales to these practitioners, but that more in-depth analysis can be used when time allows and requires.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;U&gt;Moving Toward Risk-Based Compliance: PCI DSS 4.0 Targeted Risk Analysis&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Jim Lipkis&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Jim Lipkis, with input from Aaron Arutunian, dove into target risk analysis (TRA) for specific control criteria. Jim noted that compliance does not necessarily mean security, but he posited whether compliance requirements might support stronger security postures. Jim advocated for conducting high-level assessments first to identify what’s actually important before performing deeper analysis to allocate resources to focus on truly critical controls.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;U&gt;Insecure at Any Speed: Why Secure by Design is Not Enough&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;John Benninghoff&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Beginning with a historical overview of the auto industry and factors resulting in improved safety, John Benninghoff made connections to the CISA “Secure by Design” initiative. John noted the potential externalities from security incidents, notably that third-party breaches affect numerous interconnected companies. John ended with a call to action to professionalize the software engineering profession with proper tools and moral obligations.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;U&gt;Keeping Score: Using Real Breach Data to Evaluate Control Effectiveness&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Matt Berninger&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;The final presentation of SiRAcon ’25 was from Matt Berninger, who went into the latest cybersecurity controls report from Marsh McClennan that analyzed the relationship between control attestations and breach performance. Matt concluded that the controls that mattered in 2023 still matter, but he noted that it is harder to differentiate due to high adoption rates (such as 98-99% MFA adoption). Matt also highlighted that using the Exploit Prediction Scoring System (EPSS) and contextual scoring frameworks is recommended over CVSS scores alone.&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="center"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;_____________________________________________________________&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;During SiRAcon ’25, the SiRAcon Planning Committee also announced exciting news: &lt;STRONG&gt;SiRAcon ’26 will take place from Apr. 21-23, 2026 at the Boston Federal Reserve in Boston, MA&lt;/STRONG&gt;. Full event details, including the event theme, presentation proposal deadlines, and registration, will be announced in coming weeks.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Thank you to everyone who made SiRAcon ’25 a success, particularly the keynote presenters and speakers, SiRA Board Members and SiRAcon Planning Committee Members, and attendees alike!&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Thank you, too, to the sponsors of SiRA and SiRAcon ’25:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;SiRA Organizational Sponsors&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;A href="https://www.marshmclennan.com/"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;Marsh McClennan&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
      &lt;/LI&gt;

      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;A href="https://www.ostrichcyber-risk.com/"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;Ostrich Cyber-Risk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
      &lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;SiRAcon ’25 Gold Sponsor&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;A href="https://www.marshmclennan.com/"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;Marsh McClennan&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
      &lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;SiRAcon ’25 Bronze Sponsors&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;A href="https://www.empiricalsecurity.com/"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;Empirical Security&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
      &lt;/LI&gt;

      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;A href="https://www.ostrichcyber-risk.com/"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;Ostrich Cyber-Risk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
      &lt;/LI&gt;

      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;A href="https://www.opengroup.org/"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;The Open Group&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
      &lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;
&lt;/UL&gt;&lt;FONT style="font-size: 16px;" color="#000000"&gt;Finally, thank you to the&lt;/FONT&gt; &lt;A href="https://www.bostonfed.org/"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;Boston Federal Reserve&lt;/FONT&gt;&lt;/A&gt; &lt;FONT style="font-size: 16px;" color="#000000"&gt;for acting as a phenomenal host yet again and to the&lt;/FONT&gt; &lt;A href="https://www.yotel.com/en/hotels/yotel-boston"&gt;&lt;FONT style="font-size: 16px;" color="#0563C1"&gt;YOTEL Boston&lt;/FONT&gt;&lt;/A&gt; &lt;FONT style="font-size: 16px;" color="#000000"&gt;for providing fantastic accommodations and space for attendees.&lt;/FONT&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13547357</link>
      <guid>https://societyinforisk.org/Blog-Posts/13547357</guid>
      <dc:creator />
    </item>
    <item>
      <pubDate>Tue, 23 Sep 2025 11:22:42 GMT</pubDate>
      <title>SiRAcon '25 Highlights and Recap: Day 2</title>
      <description>&lt;H1&gt;&lt;FONT color="#000000" style="font-size: 21px;"&gt;&lt;U&gt;SiRAcon ’25 Highlights and Recap: Day 2&lt;/U&gt;&lt;/FONT&gt;&lt;/H1&gt;

&lt;H2&gt;&lt;STRONG&gt;&lt;FONT&gt;From Zero to Quant to ERM&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;

&lt;P align="left"&gt;&lt;FONT style="font-size: 14px;"&gt;&lt;BR&gt;
&lt;FONT&gt;SiRAcon ’25 took place last week Sep. 9-11, 2025 at the Boston Federal Reserve in Boston, MA, which marks the second year that SiRAcon has occurred at this venue.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left"&gt;&lt;FONT style="font-size: 14px;"&gt;The event theme this year was&amp;nbsp;&lt;EM&gt;&lt;FONT&gt;From Zero to Quant to ERM&lt;/FONT&gt;&lt;/EM&gt;, building on last year’s theme of&amp;nbsp;&lt;EM&gt;&lt;FONT&gt;From Zero to Quant&lt;/FONT&gt;&lt;/EM&gt;&amp;nbsp;and emphasizing the need to have conversations about cybersecurity risk as part of broader enterprise risk management decisions. Presentations reinforced this theme and brought in considerations for AI, industry standards to aid adoption, and steps for continued growth based on learnings from the past.&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left"&gt;&lt;FONT style="font-size: 14px;"&gt;The event saw more than 100 attendees between in-person and virtual attendees, and the SiRA Slack and Zoom chat allowed for lively and energizing discussion and debate across the event. As always, the SiRA community was engaged and thought-provoking throughout the week, with excellent conversations taking place during breaks across the event. The sense of community at this conference is always amazing!&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left"&gt;&lt;FONT color="#2C3E50" style="font-size: 14px;"&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;If you happened to miss this year’s SiRAcon but registered, you can still&lt;/FONT&gt;&lt;/EM&gt;&amp;nbsp;&lt;A href="https://web.cvent.com/event/aea3fabb-28f2-48e0-99b7-9eab5e226ee4/summary"&gt;&lt;FONT color="#0563C1"&gt;&lt;EM&gt;access session recordings&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;&lt;EM&gt;&lt;FONT color="#000000"&gt;through the event site. If you did not register, the recordings will soon be added to the Members’ Area of&lt;/FONT&gt;&lt;/EM&gt;&amp;nbsp;&lt;A href="http://www.societyinforisk.org/"&gt;&lt;FONT color="#0563C1"&gt;&lt;EM&gt;www.societyinforisk.org&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;&lt;EM&gt;&lt;FONT color="#000000"&gt;and you can access them (as well as recordings from previous SiRAcons and past webinars) by becoming a Member of SiRA:&lt;/FONT&gt;&lt;/EM&gt;&amp;nbsp;&lt;A href="https://societyinforisk.org/join"&gt;&lt;FONT color="#0563C1"&gt;&lt;EM&gt;https://societyinforisk.org/join&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;.&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;H2&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT style="font-size: 14px;"&gt;&lt;SPAN class="Apple-style-span" style="text-decoration: underline;"&gt;Day 2: Tuesday, Sep. 10, 2025&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;

&lt;P&gt;&lt;BR&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;The State of SiRA&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Darrell Waurio, SiRA Board President&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Darrel Waurio got day 2 started with a brief session focused on the vision and goals of SiRA for the near future. Darrell highlighted the five strategic priorities of the SiRA Board: member community development, sponsor relationships, strategic partnerships, Board strategic direction and oversight, and financial sustainability. Darrell included a call for volunteers to help SiRA meet these goals.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 14px;"&gt;&lt;FONT color="#000000"&gt;(For more details, please read the SiRA President’s Letter:&lt;/FONT&gt; &lt;A href="https://societyinforisk.org/Presidents-Letter"&gt;&lt;FONT color="#0563C1"&gt;https://societyinforisk.org/Presidents-Letter&lt;/FONT&gt;&lt;/A&gt;&lt;FONT color="#000000"&gt;)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Keynote: Is AI the Biggest Risk to Risk Analysis – Or its Future?&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Lonnie Chrisman&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Lonnie Chrisman was the keynote presenter for day 2 and dove straight into an engaging presentation focused on AI. Lonnie emphasized the impacts of AI on information risk analysis, highlighting increases in the ability to perform multi-step tasks and tying this to a movement from reactive risk management to proactive strategic planning. Lonnie noted that future (and current!) risk analysts can make great use of AI to provide improvements to modeling efforts and helping to fill a gap where there is missing expertise. Lonnie advised that risk analysts should adopt AI tools to increase performance and efficiency.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Surfing the Risk Sine Wave&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Tyler Britton and Taylor Maze&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Presenting remotely, Tyler Britton began his session developed with Taylor Maze by noting the limitations of traditional risk reporting: risk burn-down charts show consistent downward trends, but they create an unrealistic expectation that risk approaches zero. In reality, a net risk approach provides a better insight into risk oscillation and allows better risk management, based on risk tolerance and appetite and with allowances for variation built in.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Student Research Competition Winners&lt;/U&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Day 2 featured the Inaugural SiRA Research Competition Winners Isaac Teuscher and Philip Akekudaga, who gave brief presentations on their research.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Automating the RMF: Lessons from the FedRAMP® 20x Pilot&lt;/U&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Isaac Teuscher&lt;/FONT&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Isaac Teuscher’s presentation focused on FedRAMP, which is the process to authorize cloud-based software for use by U.S. federal agencies and changes coming with FedRAMP 20x. Isaac provided insights into these changes based on a case study involving first-hand experience, tying in the NIST Risk Management Framework (RMF) and addressing evidence and documentation considerations.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Quantifying Systemic Risk in Critical Power Infrastructure Using FDNA: From Single-Node Failure to Grid-Wide Cascades&lt;/U&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Philip Akekudaga&lt;/FONT&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT style="font-size: 14px;"&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;Philip Akekudaga’s presentation focused on function dependency network analysis (FDNA, which is a graph&lt;/FONT&gt;&lt;/EM&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;‑&lt;/FONT&gt;&lt;/EM&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;based methodology for identifying, representing, and quantifying dependencies. Philip applied FDNA to a simulation to understand and improve the resilience of electric power grids, noting possible tie-ins to dynamic models to capture real-time varying shocks as well as enterprise portfolio planning to prevent cascading failures through capability chains.&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Quantifying the Cost of Cyber Risk&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Scott Stransky&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Following the presentations by the SiRA Research Competition winners, Scott Stransky used cyber insurance data to dive into the history of insurance risk modeling, cyber data types, correlation studies, and academic research. Scott highlighted the advantages offered by using insurance data, notably that there is high fidelity in incident details (including remediation efforts). Scott also noted that there is no statistically significant increase in ransomware incidents after buying cyber insurance.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;A Quant-a-Be’s Journey to Integrate CRQ at an Enterprise Scale&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Sean Atkinson&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Sean Atkinson offered insight into lessons learned from implementing a risk quantification program, offering open and honest lessons learned from attempts and resistance met. Sean noted his various failed attempts and what was learned at each stage, providing attendees with clear ways to improve communication within an organization and improve adoption efforts. Sean stressed the need to meet each department where they are in understanding (i.e., don’t present deep analytics to someone new to quantification) and to use current methodologies as a bridge to quantification.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Adversarial Machine Learning and AI Forensics&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Paul Starrett&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Paul Starrett kicked off his presentation by ensuring common understanding of AI forensics, which is the process of collecting, analyzing, interpreting evidence to prove/disprove legal disputes involving AI systems. Paul used his experience throughout his career to provide real-world examples and emphasize the need to plan for adoption beforehand, rather than after.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;&lt;U&gt;Quantifying in the Age of Hallucination: How I Learned to Stop Worrying and Trust the AI (Sometimes)&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Tony Martin-Vegue&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Rounding out day 2 was Tony Martin-Vegue, who offered some clear guidance on safe AI adoption:&lt;/FONT&gt;&lt;/P&gt;

&lt;OL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Accelerate don’t outsource – use AI for tasks you already understand&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;

  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Assume wrong until proven right – verify all sources and claims from AI&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;

  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 14px;"&gt;Keep humans at the wheel – never let AI make final risk decisions&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Tony concluded his presentation by noting that AI fluency paired with human judgment will differentiate successful analysts.&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="center"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;_____________________________________________________________&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;During SiRAcon ’25, the SiRAcon Planning Committee also announced exciting news:&amp;nbsp;&lt;STRONG&gt;SiRAcon ’26 will take place from Apr. 21-23, 2026 at the Boston Federal Reserve in Boston, MA&lt;/STRONG&gt;. Full event details, including the event theme, presentation proposal deadlines, and registration, will be announced in coming weeks.&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT style="font-size: 14px;"&gt;Thank you to everyone who made SiRAcon ’25 a success, particularly the keynote presenters and speakers, SiRA Board Members and SiRAcon Planning Committee Members, and attendees alike!&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 17px;"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;Thank you, too, to the sponsors of SiRA and SiRAcon ’25:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;SiRA Organizational Sponsors&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;FONT&gt;&lt;A href="https://www.marshmclennan.com/"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#0563C1" style="font-size: 14px;"&gt;Marsh McClennan&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
      &lt;/LI&gt;

      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;FONT&gt;&lt;A href="https://www.ostrichcyber-risk.com/"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#0563C1" style="font-size: 14px;"&gt;Ostrich Cyber-Risk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
      &lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;SiRAcon ’25 Gold Sponsor&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;FONT&gt;&lt;A href="https://www.marshmclennan.com/"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#0563C1" style="font-size: 14px;"&gt;Marsh McClennan&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
      &lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000" style="font-size: 14px;"&gt;SiRAcon ’25 Bronze Sponsors&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;FONT&gt;&lt;A href="https://www.empiricalsecurity.com/"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#0563C1" style="font-size: 14px;"&gt;Empirical Security&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
      &lt;/LI&gt;

      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;FONT&gt;&lt;A href="https://www.ostrichcyber-risk.com/"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#0563C1" style="font-size: 14px;"&gt;Ostrich Cyber-Risk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
      &lt;/LI&gt;

      &lt;LI&gt;
        &lt;P style="line-height: 19px;"&gt;&lt;FONT&gt;&lt;A href="https://www.opengroup.org/"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#0563C1" style="font-size: 14px;"&gt;The Open Group&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
      &lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;
&lt;/UL&gt;&lt;FONT style="font-size: 14px;"&gt;&lt;BR&gt;
&lt;FONT color="#000000"&gt;Finally, thank you to the&lt;/FONT&gt; &lt;A href="https://www.bostonfed.org/"&gt;&lt;FONT color="#0563C1"&gt;Boston Federal Reserve&lt;/FONT&gt;&lt;/A&gt; &lt;FONT color="#000000"&gt;for acting as a phenomenal host yet again and to the&lt;/FONT&gt; &lt;A href="https://www.yotel.com/en/hotels/yotel-boston"&gt;&lt;FONT color="#0563C1"&gt;YOTEL Boston&lt;/FONT&gt;&lt;/A&gt; &lt;FONT color="#000000"&gt;for providing fantastic accommodations and space for attendees.&lt;/FONT&gt;&lt;/FONT&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13544879</link>
      <guid>https://societyinforisk.org/Blog-Posts/13544879</guid>
      <dc:creator />
    </item>
    <item>
      <pubDate>Tue, 16 Sep 2025 12:02:50 GMT</pubDate>
      <title>SiRAcon '25 Highlights and Recap</title>
      <description>&lt;H1&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#000000" style="font-family: Arial, Helvetica, sans-serif; font-size: 21px;"&gt;&lt;U&gt;SiRAcon ’25 Highlights and Recap: Day 1&lt;/U&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H1&gt;

&lt;H2&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;SPAN&gt;&lt;STRONG&gt;From Zero to Quant to ERM&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;
&lt;SPAN&gt;SiRAcon ’25 took place last week Sep. 9-11, 2025 at the Boston Federal Reserve in Boston, MA, which marks the second year that SiRAcon has occurred at this venue.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;
&lt;SPAN&gt;The event theme this year was&lt;/SPAN&gt; &lt;EM style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif;"&gt;From Zero to Quant to ERM&lt;/EM&gt;&lt;SPAN&gt;, building on last year’s theme of&lt;/SPAN&gt; &lt;EM style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif;"&gt;From Zero to Quant&lt;/EM&gt; &lt;SPAN&gt;and emphasizing the need to have conversations about cybersecurity risk as part of broader enterprise risk management decisions. Presentations reinforced this theme and brought in considerations for AI, industry standards to aid adoption, and steps for continued growth based on learnings from the past.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;
&lt;SPAN&gt;The event saw more than 100 attendees between in-person and virtual attendees, and the SiRA Slack and Zoom chat allowed for lively and energizing discussion and debate across the event. As always, the SiRA community was engaged and thought-provoking throughout the week, with excellent conversations taking place during breaks across the event. The sense of community at this conference is always amazing!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;
&lt;EM style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif;"&gt;If you happened to miss this year’s SiRAcon but registered, you can still&lt;/EM&gt; &lt;A href="https://web.cvent.com/event/aea3fabb-28f2-48e0-99b7-9eab5e226ee4/summary" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT color="#0563C1"&gt;&lt;EM&gt;access session recordings&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt; &lt;EM style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif;"&gt;through the event site. If you did not register, the recordings will soon be added to the Members’ Area of&lt;/EM&gt; &lt;A href="http://www.societyinforisk.org" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT color="#0563C1"&gt;&lt;EM&gt;www.societyinforisk.org&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt; &lt;EM style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif;"&gt;and you can access them (as well as recordings from previous SiRAcons and past webinars) by becoming a Member of SiRA:&lt;/EM&gt; &lt;A href="https://societyinforisk.org/join" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT color="#0563C1"&gt;&lt;EM&gt;https://societyinforisk.org/join&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif;"&gt;.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;H2&gt;&lt;FONT&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT style="font-size: 16px;"&gt;&lt;SPAN class="Apple-style-span" style="text-decoration: underline;"&gt;Day 1: Tuesday, Sep. 9, 2025&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;BR&gt;
&lt;SPAN&gt;&lt;U&gt;Keynote: Quantitative Enterprise Risk Management&lt;/U&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;SPAN&gt;Graeme Keith&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;&lt;SPAN&gt;Graeme Keith kicked off SiRAcon ’25 as the keynote presenter on Tuesday, Sep. 9. Graeme stressed the need for risk management to influence decision-making in an organization. The models used need to be actionable, causal, stochastic, and simple, but adequate. Graeme stressed that enterprise risks occur and impact across the scale of the organization and that enterprise risk management aligns enterprise objectives and decisions with governance.&lt;/SPAN&gt;&lt;BR&gt;
&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;U&gt;Zero Trust in CRQ? Or CRQ in Zero Trust?&lt;/U&gt;&lt;/SPAN&gt;&lt;BR&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;SPAN&gt;John Linford&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT color="#000000"&gt;Following Graeme, John Linford dived into a presentation on areas where cyber risk quantification might be included as part of an organization’s Zero Trust transformation. John emphasized the mindset shift required to adopt Zero Trust and built on this to offer areas where CRQ might complement the transition and decision-making.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;&lt;BR&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;Why We Resist: Uncovering the Psychological Barriers to Effective ERM&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;&lt;FONT&gt;Jason Leuenberger&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;Jason Leuenberger showed the power of the mind in his presentation, providing an open and honest glimpse into his own thought processes to demonstrate the value of Kegan’s Immunity to Change and Self-Determination Theory. Jason tied these concepts back to why risk initiatives face resistance and offered suggestions for designing ERM programs that will actually work.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;Integrating Cyber Risk and Enterprise Risk Using the NIST 8286 IR&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;Andrew Shea&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;The Integrating Cybersecurity and Enterprise Risk Management (ERM) series of publications from NIST provide a valuable resource for any organization attempting to integrate cyber risk with enterprise risk, as shown by Andrew Shea. Andrew provided a breakdown of the documents in the series and offered guidance on implementation timelines and approach, highlighting technical and non-technical mitigations and utilizing the risk-adjusted return on capital (RAROC) methodology.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;Navigating the Changing Cyber Landscape: Trends, Costs, and Risk Mitigation Strategies&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;Wendy Hou-Neely&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;Wendy Hou-Neely kept the energy of day 1 flowing with an overview key cyber risk trends and statistics, highlighting the top threat areas as well as ransomware payment trends, major incident driving costs, and business interruption costs. Wendy also stressed some key risk mitigations and controls, including MFA, data management best practices, and considerations for third-party risk management.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;(Nearly) a Decade of Risk Management: Lessons Learned and What’s Next&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;SPAN&gt;David Severski&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;David Severski rounded out day 1 with an insightful (and cat-filled) presentation focused on security incident trends analysis. David offered real-world data from the Cyentia Institute to showcase changes in incident frequency (increasing), the probability of experiencing a security event (increasing for most organizations, but decreasing for mega corporations), and financial impact data (increasing). David kept the energy high and attention focused to round out the first day!&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;" align="center"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;_____________________________________________________________&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;" align="center"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="display: inline !important;"&gt;&lt;FONT&gt;&lt;FONT color="#000000"&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT color="#000000"&gt;During SiRAcon ’25, the SiRAcon Planning Committee also announced exciting news: &lt;STRONG&gt;SiRAcon ’26 will take place from Apr. 21-23, 2026 at the Boston Federal Reserve in Boston, MA&lt;/STRONG&gt;. Full event details, including the event theme, presentation proposal deadlines, and registration, will be announced in coming weeks.&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;Thank you to everyone who made SiRAcon ’25 a success, particularly the keynote presenters and speakers, SiRA Board Members and SiRAcon Planning Committee Members, and attendees alike!&lt;/P&gt;

&lt;P&gt;Thank you, too, to the sponsors of SiRA and SiRAcon ’25:&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;SPAN&gt;SiRA Organizational Sponsors&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;&lt;A href="https://www.marshmclennan.com/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#0563C1"&gt;Marsh McClennan&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;

      &lt;LI&gt;&lt;A href="https://www.ostrichcyber-risk.com/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#0563C1"&gt;Ostrich Cyber-Risk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;

  &lt;LI&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;SPAN&gt;SiRAcon ’25 Gold Sponsor&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;&lt;A href="https://www.marshmclennan.com/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#0563C1"&gt;Marsh McClennan&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;

  &lt;LI&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;SPAN&gt;SiRAcon ’25 Bronze Sponsors&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;

  &lt;LI style="list-style: none; display: inline"&gt;
    &lt;UL&gt;
      &lt;LI&gt;&lt;A href="https://www.empiricalsecurity.com/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#0563C1"&gt;Empirical Security&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;

      &lt;LI&gt;&lt;A href="https://www.ostrichcyber-risk.com/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#0563C1"&gt;Ostrich Cyber-Risk&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;

      &lt;LI&gt;&lt;A href="https://www.opengroup.org/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT color="#0563C1"&gt;The Open Group&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;
    &lt;/UL&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;BR&gt;
&lt;SPAN&gt;Finally, thank you to the&lt;/SPAN&gt; &lt;A href="https://www.bostonfed.org/" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT color="#0563C1"&gt;Boston Federal Reserve&lt;/FONT&gt;&lt;/A&gt; &lt;SPAN&gt;for acting as a phenomenal host yet again and to the&lt;/SPAN&gt; &lt;A href="https://www.yotel.com/en/hotels/yotel-boston" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;FONT color="#0563C1"&gt;YOTEL Boston&lt;/FONT&gt;&lt;/A&gt; &lt;SPAN&gt;for providing fantastic accommodations and space for attendees.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;SPAN&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;SPAN&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P align="left" style="display: inline !important;"&gt;&lt;FONT&gt;&lt;SPAN&gt;We look forward to seeing everyone again next year at SiRAcon '26!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13542618</link>
      <guid>https://societyinforisk.org/Blog-Posts/13542618</guid>
      <dc:creator />
    </item>
    <item>
      <pubDate>Wed, 03 Sep 2025 13:01:39 GMT</pubDate>
      <title>How Effective Are Your Controls?</title>
      <description>&lt;H2&gt;&lt;FONT color="#242424"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 24px;"&gt;&lt;STRONG&gt;From Control Checklists to Measurable Confidence&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Controls are the backbone of any risk program. Firewalls, access controls, backups &amp;amp; MFA are just a few examples. Many organizations are packed with them. But here’s the question: how do you&lt;/FONT&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;really&lt;/FONT&gt;&lt;/EM&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;know if those controls are working? And more importantly, how effective are they compared to the cost of maintaining them?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;The “How Effective Are Your Controls?” track at SIRAcon ’25 is about moving beyond assumptions and audits to measurable evidence. Instead of treating controls as a binary measure of either “in place” or “not in place”, we’ll explore how quantification can reveal the actual risk reduction they deliver. That means better investment decisions, sharper communication with leadership, and less reliance on gut feel.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;We oftentimes think ROI is the right way to go about it, but executives might not look at it that way - we are investing, but technically speaking, we aren’t getting returns. It’s time we start looking at it from the perspective of risk reduction rather than a return.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;This track is for anyone who’s ever struggled to prove the value of security spend or wondered if compliance checkboxes are actually reducing risk. By applying quantitative approaches, you’ll leave with tools to measure, compare, and optimize the controls that make up your security (and enterprise) defense posture.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;H2 style="line-height: 33px;"&gt;&lt;FONT color="#242424"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 23px;"&gt;Quantifying Control Effectiveness&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Controls aren’t perfect, they’re probabilistic. A phishing filter doesn’t block&lt;/FONT&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;every&lt;/FONT&gt;&lt;/EM&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;malicious email. Backups don’t guarantee flawless recovery. But by treating controls as measurable (rather than assumed) risk mitigators, you can bring clarity to messy questions:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;What’s the actual likelihood reduction from multi-factor authentication?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;How do patching frequencies shift your risk curve?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Which of your overlapping tools are duplicative—and which are essential?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Sessions in this track will showcase methods to estimate control performance with real-world data, benchmarks, and expert judgment, helping you move from vague confidence to evidence-based decision-making.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;H2 style="line-height: 33px;"&gt;&lt;FONT color="#242424"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 23px;"&gt;The RROI (Risk Reduction on Investment) of Security Spend&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Budgets are tight, risks are rising, and boards want proof. This part of the track will help you connect control effectiveness directly to dollars and cents. You’ll see how to calculate the risk reduction per dollar spent, prioritize investments based on quantified impact, and identify diminishing returns when layering controls.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Expect to walk away with frameworks for answering the age-old CFO question:&lt;/FONT&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;“If I give you another million dollars, how much risk does that take off the table?”&lt;/FONT&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;H2 style="line-height: 33px;"&gt;&lt;FONT color="#242424"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 23px;"&gt;Modeling Controls in a System, Not a Vacuum&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Controls don’t exist in isolation, they work in layers with overlaps and gaps. A single vulnerability scan might not stop a breach, but combined with patch management, incident response, and endpoint detection, it forms a defense-in-depth system.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;This track will show you how to model control performance as part of a broader ecosystem. Think: Monte Carlo simulations showing defense layers, scenario analysis that tests controls against realistic attack paths, and system-level views that reveal where a single weak link undermines the whole chain.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;H2 style="line-height: 33px;"&gt;&lt;FONT color="#242424"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 23px;"&gt;Beyond Cyber: Controls Everywhere&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Although security controls may take the spotlight, the same thinking applies outside of cyber. Internal financial controls, environmental safeguards, safety systems - these are all “controls” that deserve measurement. Sessions may highlight how techniques developed in risk quant can be applied across domains, reinforcing enterprise-wide control confidence.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Sample Use Cases:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Cyber: Measuring MFA effectiveness in reducing credential theft incidents.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Operational: Estimating the reduction in workplace accidents from a new safety training program.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Financial: Quantifying how a segregation-of-duties control reduces fraud risk.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;H2 style="line-height: 33px;"&gt;&lt;FONT color="#242424"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 23px;"&gt;From Assurance to Influence&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Ultimately, this track isn’t just about proving that controls exist, it’s about showing how they perform, in language that resonates with executives and boards. Attendees will learn to communicate control effectiveness in terms of risk reduction, business outcomes, and strategic priorities.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;Sessions may explore:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Approaches for benchmarking controls against peers&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;How to incorporate control uncertainty into quant models&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Linking control effectiveness to enterprise risk appetite&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;Telling a compelling control story to leadership&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT style="font-size: 15px;"&gt;&lt;BR&gt;
    &lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 23px;"&gt;Controls as Measurable, Not Assumed&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 21px;"&gt;&lt;FONT color="#242424" style="font-size: 15px;"&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;The “How Effective Are Your Controls?” track is about replacing blind trust with measurable assurance. You’ll leave with strategies to make your control program more transparent, defensible, and impactful - armed with the evidence you need to prove that your controls aren’t just&lt;/FONT&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;there&lt;/FONT&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;, they’re&lt;/FONT&gt;&lt;/SPAN&gt; &lt;SPAN style="background-color: transparent;"&gt;&lt;EM&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;working&lt;/FONT&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: transparent;"&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;.&lt;/FONT&gt;&lt;FONT color="#000000" style="font-size: 15px;"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;At SIRAcon ’25, we’re not just asking if you have controls in place. We’re asking how much they matter, how much they reduce risk, and how you can prove it.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;&lt;BR&gt;&lt;/P&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13538251</link>
      <guid>https://societyinforisk.org/Blog-Posts/13538251</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Tue, 12 Aug 2025 11:50:35 GMT</pubDate>
      <title>From Cyber-Centric to Enterprise-Wide: Expand the Impact of Quantification</title>
      <description>&lt;p style="line-height: 19px;"&gt;&lt;span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 15px;"&gt;&lt;strong&gt;Risk Quantification Beyond Security&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 15px;"&gt;Risk quantification doesn’t stop at just security. We have used the term cyber risk quantification so heavily (for good reason) that people seem to forget we can quantify any kind of risk. The applications are endless—what about quantifying the negative outcome that can stem from hitting “reply all” to an email asking for anonymous submissions? Or estimating the productivity loss if a coworker microwaves last night’s fragrant fish dinner in the office microwave?&lt;/span&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;As those examples show, some of the most innovative applications of risk modeling are happening outside cybersecurity—covering workplace tomfoolery, supply chains, finance, and even climate and environmental risk. The “Risk Measurement Outside of Cyber” track at SiRAcon ’25 is your invitation to break down silos and explore how quant can support truly enterprise-wide resilience.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;This track is for forward-thinkers who see risk measurement as more than a security function. Whether you're in cyber, ops, or enterprise risk, you'll walk away with tools to extend your modeling practice into new domains—while staying grounded in the rigorous, defensible approaches that define good quant.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;strong&gt;Modeling the Messy World of Supply Chains&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Just-in-time works brilliantly—until it doesn’t. Supply chain risk is not just about disruptions; it’s about understanding the ripple effects of delays, geopolitical instability, or labor unrest on your business outcomes. In these sessions, you’ll learn to bring structure and quantification to a system that often feels chaotic. You’ll see how probabilistic models, scenario analysis, and cross-functional collaboration can reveal the real financial stakes behind operational hiccups and help you make a defensible case for resilience investments.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;strong&gt;Financial Risk Quant for Non-Quants&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;You don’t need to be on Wall Street to use financial modeling. From value-at-risk (VaR) to cash flow stress testing, these techniques can be adapted to help organizations prepare for worst-case scenarios, budget effectively, and understand the downstream financial effects of incidents—cyber or otherwise. This track will focus on translating financial quant concepts into accessible, actionable tools for decision-making, capital planning, and insurance choices.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;strong&gt;Environmental and Climate Risk: Measured and Modeled&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;span style=""&gt;Environmental risk is not a far-off concern—it’s here now, and it’s measurable. Climate volatility, extreme weather events, shifting regulations, and ESG pressures all create uncertainty. Talks here could cover how to work with environmental risks, even with imperfect data, and show how to integrate climate risk scenarios into operational, financial, and strategic planning. You’ll gain strategies to turn uncertain data into actionable insights that support both resilience and sustainability goals.&lt;/span&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;strong&gt;Sample Use Cases Across Domains&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Supply Chain Risk: Modeling the cost impact of a two-week port closure on seasonal product availability.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Financial Risk: Estimating cash flow stress from a sudden legal settlement unrelated to cyber incidents.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Environmental Risk: Quantifying potential downtime costs from an extreme heatwave affecting warehouse operations.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Thinking Like an Enterprise Risk Function&lt;/font&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;br&gt;&lt;/font&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Cyber risk quant started as a niche—but it doesn’t have to stay one. This track will also explore how cyber professionals can evolve their models and language to contribute to broader enterprise risk efforts. Think: integrating cyber into operational risk heatmaps, showing cumulative exposure across domains, or linking cyber incidents to financial and reputational outcomes.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Sessions may explore:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Frameworks for aligning cyber quant with ERM practices&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Building shared assumptions across risk domains&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Communicating cross-domain risks to boards and executives&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;The art of zooming out: when to keep cyber-specific detail and when to abstract for enterprise view&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Because when risk is everyone's responsibility, quant can’t live in just one department.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;strong&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;One Discipline, Many Domains&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;The “Risk Measurement Outside of Cyber” track is about scale, translation, and collaboration. You’ll leave with the mindset and methods to take what you’ve learned in cyber and apply it to the rest of the enterprise—helping your organization become more adaptive, resilient, and future-ready.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;At SiRAcon ‘25, we’re not just advancing cyber risk measurement—we’re elevating risk quant to meet the full spectrum of enterprise challenges. And we’re doing it one model, one scenario, one shared framework at a time.&lt;/font&gt;&lt;/p&gt;

&lt;p&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;br&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13530870</link>
      <guid>https://societyinforisk.org/Blog-Posts/13530870</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Wed, 09 Jul 2025 22:05:01 GMT</pubDate>
      <title>Smarter Models, Sharper Insights: AI in Quantitative Risk Measurement</title>
      <description>&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;STRONG&gt;Artificial intelligence is everywhere, but how do you separate the hype from the helpful when it comes to risk models?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;The “AI in Quantitative Risk Measurement” track at SIRAcon ‘25 is all about the practical side of integrating AI and machine learning into your risk analysis. Not to build flashy toys—but to make your models faster, smarter, and more insightful.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;This track isn’t about automating your entire job away. It’s about enhancing your ability to detect patterns, handle uncertainty, and generate defensible, data-driven insights with greater efficiency. If you’ve ever wondered whether a model could learn from past scenarios, detect bias in your inputs, or help you forecast risk with fewer assumptions, we think you’ll find some answers here.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;STRONG&gt;AI that Adds, Not Obscures&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;In risk, clarity matters more than complexity. That’s why these sessions will focus on interpretable AI&lt;/FONT&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;tools and techniques that enhance your understanding instead of burying it in black-box algorithms.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Potential session topics include:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Leveraging machine learning to spot patterns in incident and loss data&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Using natural language processing (NLP) to extract risks and controls from unstructured sources&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Building AI-enhanced models that provide explainable outputs—not just predictions&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Identifying when AI helps… and when it just adds noise&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Because if you can’t explain how your model works, you probably can’t defend it either.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;STRONG&gt;Faster, Leaner Modeling with ML&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;AI can do more than just analyze data. It can accelerate how you prep, structure, and test your models. We’re hoping to hear from experts on time-saving applications of machine learning that let you skip the grunt work and get to insight faster.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Learn how to:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Auto-clean and cluster messy data sets from multiple sources&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Use AI to flag anomalies and inconsistent assumptions before they skew your results&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Train models on historical loss data to inform probability distributions and impact ranges&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Optimize Monte Carlo simulations with smarter parameter tuning and convergence detection&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;No data science background required—just a low tolerance for cleaning up messy models.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;STRONG&gt;Redefining Risk Scenarios with AI&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Scenario development is the heart of good risk quantification, but it’s also one of the most labor-intensive steps. We’d like to hear from experts on how AI can augment scenario creation with smarter suggestions, better inputs, and real-time threat intelligence integration.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Expect to see talks covering:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Tools that generate realistic risk scenarios based on current threat trends&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Ways to blend AI-generated insights with SME judgment (without losing control)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Techniques for continuously updating scenarios as new data becomes available&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Risk storylines driven by both structured and unstructured sources&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;The result? More relevant scenarios. Less mental gymnastics.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;STRONG&gt;AI + Human Judgment = Better Risk Decisions&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;AI isn’t here to replace you. As long as you approach it properly, it’s here to supercharge you. The real value of AI in quant isn’t in outsourcing thinking, but in enhancing it. Sessions in this track will help you strike the right balance between automation and expert oversight, and show you how to turn AI outputs into decisions leadership can trust.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;You’ll walk away with:&lt;/FONT&gt;&lt;/P&gt;

&lt;UL&gt;
  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;A working knowledge of AI’s strengths and limits in risk modeling&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;Practical tools to experiment with right away (no PhD required)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;

  &lt;LI&gt;
    &lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;New ideas for solving old problems like data gaps, stale assumptions, and overworked analysts&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;/LI&gt;
&lt;/UL&gt;&lt;BR&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;&lt;STRONG&gt;Build Better Models, Make Smarter Moves&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;The “AI in Quantitative Risk Measurement” track is designed for risk professionals who want to move beyond spreadsheets and truly level up their modeling practice. Whether you're just starting to explore AI or already experimenting with it in your workflows, this track offers real-world insights, not just research papers.&lt;/FONT&gt;&lt;/P&gt;

&lt;P style="line-height: 19px;"&gt;&lt;FONT style="font-size: 15px;" color="#000000"&gt;At SIRAcon ‘25, we’re not just talking about the future—we’re putting it to work.&lt;/FONT&gt;&lt;/P&gt;&lt;BR&gt;

&lt;P&gt;&lt;BR&gt;&lt;/P&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13519182</link>
      <guid>https://societyinforisk.org/Blog-Posts/13519182</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Wed, 18 Jun 2025 01:38:16 GMT</pubDate>
      <title>Unlocking Better Risk Decisions: The Power of Decision, Behavioral, and Data Science at SiRAcon</title>
      <description>&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;At SiRAcon 2025, we're not just measuring risk—we’re exploring how risk&lt;/font&gt; &lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;decisions&lt;/font&gt;&lt;/em&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;actually get made. That’s why this unique track dives deep into the intersection of Decision Science, Behavioral Science, and Data Science—disciplines that go far beyond numbers and models to influence the very core of enterprise risk management.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 33px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Why this track matters&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;In theory, good data should lead to good decisions. But in practice? It's messier. Cognitive biases, organizational politics, incomplete information, and poorly designed models can all distort risk assessments and decisions. This track confronts that reality head-on.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;By blending technical methods with human insight, speakers will share strategies for making risk quantification more useful, usable, and actionable across the enterprise.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 33px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;What to Expect from this Track&lt;/font&gt;&lt;/h3&gt;

&lt;h4 style="line-height: 28px;"&gt;&lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Decision Science: Structuring Better Choices&lt;/font&gt;&lt;/em&gt;&lt;/h4&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;How do you move from quantification to action? Decision science provides frameworks for structuring options, defining objectives, and assessing tradeoffs under uncertainty. Sessions in this area will explore:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;How to frame risk questions that matter to executives&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Using decision trees, value of information, and utility curves to clarify priorities&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Real-world case studies of decisions improved (or distorted) by modeling&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h4 style="line-height: 28px;"&gt;&lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Behavioral Science: Understanding Risky Humans&lt;/font&gt;&lt;/em&gt;&lt;/h4&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk isn’t just technical—it’s deeply human. Behavioral science helps us understand how people perceive, misinterpret, and respond to risk. This sub-track explores:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Common biases in interpreting risk data (e.g., overconfidence, probability neglect)&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Organizational friction: how teams resist or misapply quant models&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Nudging better decisions with communication, design, and defaults&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h4 style="line-height: 28px;"&gt;&lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Data Science: Driving Better Inputs&lt;/font&gt;&lt;/em&gt;&lt;/h4&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Behind every credible model is a mountain of messy, fragmented data. Data science helps risk professionals:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Clean and structure data from disparate sources&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Automate updates and detect outliers&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Apply machine learning techniques with caution and transparency&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;You’ll also hear from practitioners who are bridging the gap between raw telemetry and business-relevant insights, using real-world data pipelines to power meaningful risk decisions.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 33px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Risk Isn’t Just a Number—It’s a Decision Process&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;This track will challenge attendees to think differently about the role of quantification. It's not about producing the “perfect” number—it’s about producing information that improves decisions under uncertainty.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;You’ll leave with frameworks, stories, and tactics for:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Making your models more decision-relevant&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Communicating uncertainty more effectively&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Designing processes and cultures that absorb, not resist, risk intelligence&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;
    &lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 style="line-height: 33px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Join Us&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;If you’ve ever asked&lt;/font&gt; &lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;“Why aren’t they using our risk analysis?”&lt;/font&gt;&lt;/em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;, this track is for you. Decision, behavioral, and data science offer practical, often surprising answers—and this year’s speakers are bringing their best lessons forward.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Because at the end of the day, a quantified risk is only valuable if it helps someone make a better choice.&lt;/font&gt;&lt;/p&gt;

&lt;p&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;br&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13511475</link>
      <guid>https://societyinforisk.org/Blog-Posts/13511475</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Wed, 28 May 2025 15:09:23 GMT</pubDate>
      <title>SIRAcon 2025: Measurement Tips, Tricks, &amp; Tools</title>
      <description>&lt;h2 style="line-height: 55px;"&gt;&lt;font style="font-size: 23px;" color="#000000" face="Arial, sans-serif"&gt;Fix the Data. Trust the Model. Move Faster.&lt;/font&gt;&lt;/h2&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Behind every successful risk quantification effort is something most people never see: a messy, manual, and often frustrating process of wrangling data, building models, and troubleshooting why they just don’t behave like they should. That’s the reality of risk measurement—and it’s exactly what the&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;“Measurement Tips, Tricks, &amp;amp; Tools”&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;track at&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;SiRAcon ‘25&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;is here to tackle.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;This track isn’t about flashy dashboards or the latest software suite. It’s about the everyday work of making quantification practical, defensible, and trusted. If you've ever thought,&lt;/font&gt; &lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;“this model looks right, but something feels off,”&lt;/font&gt;&lt;/em&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;or spent hours trying to clean a spreadsheet someone exported from an obscure legacy system—this track is for you.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Data Hygiene in the Real World&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Before you model anything, you have to trust your data. That’s easier said than done when your inputs come from ticketing systems, config management databases, threat intel feeds, or one-off subject matter expert interviews.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;In this session, you'll learn proven methods for:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Spotting common inconsistencies in real-world cyber risk data&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Creating defensible assumptions when you don’t have a complete dataset&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Validating source quality—and knowing when a source is too noisy to use&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;Building workflows that let you revisit and update assumptions without starting from scratch&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;If garbage in = garbage out, this is how you take out the trash before it corrupts your model.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Troubleshooting Quant Models&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;“My loss exceedance curve looks weird.”&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;If you’ve ever said that out loud, congratulations—your LEC does in fact look weird, but you’re not alone. Diagnosing why your model output seems “off” takes more than gut instinct, which is what this talk track is about. This session will give you the skills to reverse-engineer your models when the results don’t match expectations.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Some possible topics to explore:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;How to identify hidden bias in your estimates or distributions&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Techniques for sensitivity analysis that highlight which inputs matter most&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Warning signs that your simulation isn't converging—or is overfitting to bad data&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Ways to communicate uncertainty and model limitations without undermining credibility&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;
    &lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;It’s not just about making models—it’s about making models that hold up under scrutiny.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Scripting Smarter Simulations&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Monte Carlo models are the backbone of modern risk quantification—but building simulations that are fast, flexible, and maintainable is an evolving art.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Sessions in this track might walk through:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Structuring simulations so they scale and adapt as your data evolves&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Writing modular code in Python, R, and Excel to reduce manual work&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Running multiple what-if scenarios in parallel without rewriting your logic every time&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Avoiding common performance bottlenecks when running large simulations&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;
    &lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;If you’re stuck in a spreadsheet swamp, or want to build scripts that do more of the heavy lifting, this will get you there faster.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Shortcuts and Time-Savers&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk teams are often under-resourced and over-asked—so efficiency isn’t a luxury, it’s a necessity. These sessions are full of “if only I knew this sooner!” kinds of tricks that help you move faster without compromising accuracy or integrity.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Talks in this track aim to address:&lt;/font&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Lightweight ways to automate recurring analysis tasks&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;How to templatize your modeling workflow to reduce errors&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Creative ways to repurpose prior assessments and speed up scenario development&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Quick checks you can run to spot red flags before presenting results&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;
    &lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Because the faster you can get to reliable insight, the more time you have to act on it.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Your Quant Practice, Supercharged&lt;/font&gt;&lt;/h3&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;The&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Measurement Tips, Tricks, &amp;amp; Tools&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;track delivers practical knowledge that risk professionals can apply the very next day. It’s for the people doing the work—building models, validating inputs, debugging strange outputs, and constantly evolving their methods to be more credible and more actionable.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;When you walk away from these sessions, you won’t just know&lt;/font&gt; &lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;how&lt;/font&gt;&lt;/em&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;to measure risk—you’ll know how to do it better, faster, and with a lot more confidence.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;At&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;SiRAcon ‘25&lt;/font&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;, we’re not just pushing boundaries—we’re refining the engine behind the insights that matter.&lt;/font&gt;&lt;/p&gt;&lt;br&gt;

&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13503956</link>
      <guid>https://societyinforisk.org/Blog-Posts/13503956</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Tue, 06 May 2025 14:49:36 GMT</pubDate>
      <title>From Zero to Quant to ERM: The Role of Risk Decision Support in Modern Organizations</title>
      <description>&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;In the world of risk analysis, knowing the numbers is just the beginning. The real challenge, but also the value, lies in using those numbers to support better decisions. That’s why the Risk Decision Support track at this year’s SiRAcon 2025 will be insightful for anyone looking to advance from quantifying risk to managing it strategically.&lt;/font&gt;&lt;/p&gt;&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;From Zero to Quant to ERM&lt;/font&gt;&lt;/h3&gt;&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Continuing the evolution from last year’s theme &lt;/font&gt;&lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;“From Zero to Quant,”&lt;/font&gt;&lt;/em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt; this year’s theme &lt;/font&gt;&lt;em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;“From Zero to Quant to ERM”&lt;/font&gt;&lt;/em&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt; spotlights the journey organizations are on: from beginning their risk quantification efforts, to integrating those efforts into broader enterprise risk management (ERM) strategies. At the heart of that journey is decision support - the ability to turn data into action.&lt;/font&gt;&lt;/p&gt;&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Why Risk Decision Support Matters&lt;/font&gt;&lt;/h3&gt;&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Quantifying risk isn’t just about producing numbers; it’s about helping leaders make informed, defensible decisions under uncertainty. Whether you're prioritizing controls, selecting vendors, allocating budget, or evaluating cyber insurance options, quantitative models provide a structured way to weigh trade-offs and assess outcomes.&lt;/font&gt;&lt;/p&gt;&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;This track is for analysts, CISOs, risk managers, and decision-makers who want to bridge the gap between technical measurement and real-world action.&lt;/font&gt;&lt;/p&gt;&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;What to Expect in This Track&lt;/font&gt;&lt;/h3&gt;&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;The &lt;/font&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk Decision Support&lt;/font&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt; track will cover topics such as:&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Using Quant Models to Drive Action:&lt;/font&gt;&lt;font style="font-size: 15px;"&gt; Learn how organizations are applying Monte Carlo simulations, Value-at-Risk, and expected loss modeling to prioritize cybersecurity initiatives, justify budgets, and communicate risk in financial terms.&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;&lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Decision Frameworks That Integrate Quantification:&lt;/font&gt;&lt;font style="font-size: 15px;"&gt; Discover methods for embedding quantitative risk assessments into strategic frameworks - such as cost-benefit analysis, decision trees, and Bayesian updating to support rational, transparent decision-making across the enterprise.&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;&lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Real-World Case Studies:&lt;/font&gt;&lt;font style="font-size: 15px;"&gt; Hear from practitioners who’ve operationalized quant models, and learn what worked (and what didn’t) when translating analytics into business value.&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;&lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;p style="line-height: 19px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;"&gt;Bridging the Analyst–Executive Gap:&lt;/font&gt;&lt;font style="font-size: 15px;"&gt; Explore communication strategies for presenting quantitative results to non-technical stakeholders, ensuring data drives decisions without getting lost in translation.&lt;/font&gt;&lt;font style="font-size: 15px;"&gt;&lt;br&gt;&lt;br&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 style="line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Take the Next Step in Your Risk Journey&lt;/font&gt;&lt;/h3&gt;&lt;p style="line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;SiRAcon 2025’s Risk Decision Support track is your opportunity to explore how cutting-edge quant methods are being transformed into powerful decision-making tools. Whether you're deep in the modeling weeds or steering enterprise strategy, this track will spark new ideas and deliver practical insights you can apply immediately. Don’t miss the chance to be part of the conversations that are shaping the future of risk management. Let’s move beyond metrics and toward meaningful, data-driven decisions.&lt;/font&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13495882</link>
      <guid>https://societyinforisk.org/Blog-Posts/13495882</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
    <item>
      <pubDate>Wed, 23 Apr 2025 18:34:15 GMT</pubDate>
      <title>From Zero to Quant to ERM: Exploring the Expanding World of Risk Analysis at SIRAcon ‘25</title>
      <description>&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;SIRAcon ‘25 is set to take place September 9th-11th at the Boston Federal Reserve. This year's theme,&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;"From Zero to Quant to ERM,"&lt;/font&gt; &lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;highlights the evolving landscape of risk analysis. Building on its strong foundation in cyber risk quantification, this year's conference expands its focus to include broader Enterprise Risk Management (ERM) practices. Attendees can expect practical insights, hands-on guidance, and strategic frameworks to improve risk measurement across the enterprise.&lt;/font&gt;&lt;/p&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Presentations this year will center around several possible topics:&lt;/font&gt;&lt;/p&gt;

&lt;ul style=""&gt;
  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;span style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk Decision Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;span style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Measurement Tips, Tricks, and Tools&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;span style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Decision Science, Behavioral Science, and Data Science&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;span style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;AI in Quantitative Risk Measurement&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;span style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk Measurement Outside of Cyber&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;/li&gt;

  &lt;li&gt;
    &lt;p style="line-height: 19px;"&gt;&lt;span style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Control Effectiveness&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h4 style="background-color: transparent; line-height: 33px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk Decision Support&lt;/font&gt;&lt;/h4&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk quantification can guide strategic decision-making. Presenters will share methods for integrating risk data into prioritization and resource allocation processes, ensuring that organizations make informed decisions backed by quantified insights. Expect sessions that explore techniques like financial impact modeling, showcasing how risk quantification can improve outcome predictions and help leadership make data-driven decisions.&lt;/font&gt;&lt;/p&gt;

&lt;h4 style="background-color: transparent; line-height: 33px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Measurement Tips, Tricks, and Tools&lt;/font&gt;&lt;/h4&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Practitioners looking to improve their risk measurement processes need actionable strategies for enhancing data collection, analysis, and visualization. Expect sessions that will provide practical techniques for streamlining risk quantification efforts, ensuring practitioners can deliver clear, meaningful insights that resonate with stakeholders.&lt;/font&gt;&lt;/p&gt;

&lt;h4 style="background-color: transparent; line-height: 33px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Decision Science, Behavioral Science, and Data Science&lt;/font&gt;&lt;/h4&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Effective risk management requires more than just data – it demands an understanding of how people interpret and act on that data. By applying behavioral science principles, risk professionals can enhance their ability to communicate insights, drive change, and improve outcomes. Expect sessions that delve into psychology, cognitive biases, and data modeling to help attendees improve decision-making under uncertainty.&lt;/font&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;

&lt;h4 style="background-color: transparent; line-height: 33px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;AI in Quantitative Risk Measurement&lt;/font&gt;&lt;/h4&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Artificial intelligence and machine learning are revolutionizing risk quantification. Leveraging AI requires best practices to improve accuracy, efficiency, and insight in risk models. Expect sessions that offer practical applications of AI for forecasting, automation, and enhancing decision support capabilities.&lt;/font&gt;&lt;/p&gt;

&lt;h4 style="background-color: transparent; line-height: 33px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk Measurement Outside of Cyber&lt;/font&gt;&lt;/h4&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Risk quantification isn't limited to cybersecurity. Risk quantification techniques can be applied to broader domains, such as supply chain risk, financial risk, and environmental risk. Expect sessions that provide strategies for expanding risk frameworks to align with enterprise-wide objectives and improve resilience.&lt;/font&gt;&lt;/p&gt;

&lt;h4 style="background-color: transparent; line-height: 33px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Control Effectiveness&lt;/font&gt;&lt;/h4&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Ensuring that controls perform as intended is crucial for mitigating risk. Practitioners require practical strategies for assessing control performance, identifying gaps, and measuring control effectiveness. Expect sessions that provide frameworks for improving control designs, tracking key metrics, and ensuring alignment with organizational risk objectives.&lt;/font&gt;&lt;/p&gt;

&lt;h3 style="background-color: transparent; line-height: 41px;"&gt;&lt;font style="font-size: 17px;" color="#000000" face="Arial, sans-serif"&gt;Come Join Us!&lt;/font&gt;&lt;/h3&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;SIRAcon ‘25 promises to deliver valuable insights for risk professionals seeking to expand their skill sets and improve decision-making in their organizations. Whether you're new to risk quantification or looking to build on existing practices, this year's conference will provide the tools and knowledge needed to advance from zero to quant to ERM.&lt;/font&gt;&lt;/p&gt;

&lt;p style="line-height: 21px;"&gt;&lt;span style=""&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;You can register for SiRAcon ‘25 &lt;a href="https://societyinforisk.org/SiRAcon25" target="_blank" style=""&gt;here&lt;/a&gt;.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="background-color: transparent; line-height: 21px;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;Watch your email, LinkedIn, and the SiRAcon event site for the full agenda to be posted in April!&lt;/font&gt;&lt;/p&gt;

&lt;p style="background-color: transparent;"&gt;&lt;font style="font-size: 15px;" color="#000000" face="Arial, sans-serif"&gt;&lt;br&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="background-color: transparent;"&gt;&lt;br&gt;&lt;/p&gt;</description>
      <link>https://societyinforisk.org/Blog-Posts/13491035</link>
      <guid>https://societyinforisk.org/Blog-Posts/13491035</guid>
      <dc:creator>Joseph Breen</dc:creator>
    </item>
  </channel>
</rss>