cyber-risk-quantification

Convert technical security risks into financial metrics using the FAIR model.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill cyber-risk-quantification
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cyber-risk-quantification
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/ciso-toolkit/skills/cyber-risk-quantification
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill cyber-risk-quantification

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill bridges the gap between technical security risks and executive business language, providing top risk scenarios, likelihood × impact, and a risk register to aid in treatment decisions.

Core Features & Use Cases

  • Risk Scenarios: Identifies and derives concrete, business-relevant loss events from threat modeling and intelligence.
  • Likelihood and Impact: Offers qualitative and quantitative risk estimations, including frequency × magnitude.
  • Risk Comparison: Compares risk against the organization's appetite/tolerance and flags risks that exceed limits.
  • Risk Treatment: Recommends treatment for each significant risk, such as mitigation, transfer, or acceptance.

Quick Start

To use this skill, execute the command: run cyber-risk-quantification.

Frequently Asked Questions about cyber-risk-quantification

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I convert technical security risks into business and financial metrics?

To convert technical security risks into business and financial metrics, apply the FAIR model to translate threat modeling and intelligence data into a structured risk register with likelihood × impact calculations for executive decision support.

What is the best way to quantify cybersecurity risk for business decision-making?

Quantifying cybersecurity risk for business decision-making involves deriving concrete loss events from threat intelligence, estimating frequency and magnitude, and comparing results against organizational risk appetite to recommend mitigation, transfer, or acceptance treatments.

How do I estimate the likelihood and impact of security threats using the FAIR model?

Estimating likelihood and impact with the FAIR model requires analyzing threat modeling data to calculate frequency × magnitude, producing both qualitative and quantitative risk estimations for your top security risk scenarios.

Can I compare identified security risks against my organization's risk appetite and tolerance?

Yes, you can compare identified security risks against your organization's risk appetite and tolerance. The process flags specific loss events that exceed defined limits and recommends appropriate risk treatment actions.

How do I structure a cybersecurity risk register for executive reporting?

Structuring a cybersecurity risk register for executive reporting requires mapping technical vulnerabilities to business-relevant loss events, documenting likelihood × impact scores, and outlining treatment decisions to bridge the gap between security analysis and business language.

When do I need cyber risk quantification instead of qualitative security analysis?

You need cyber risk quantification instead of qualitative security analysis when executives require financial metrics to support security governance decisions, prioritize risk treatment, and justify cybersecurity investments based on organizational risk tolerance.

Related Skills