Certified Cyber Risk Quantification Professional (CCRQP) Workshop
This comprehensive 2-day workshop equips cybersecurity, risk, and business professionals with the skills to quantify cyber risk in financial terms, apply the FAIR model and Monte Carlo simulation, and communicate risk-based decisions with confidence.
Who Should Attend?
CISOs & Security Leaders
Risk Professionals
Security Architects & Analysts
IT Audit & Compliance Teams
Finance, Insurance & Business Risk Leaders
Why Attend the CCRQP Workshop?
Express cyber risk through measurable loss ranges
Gain practical experience applying the FAIR model to cyber risk scenarios
Build and interpret Monte Carlo simulations in Excel, with an optional Python track
Use quantified risk to justify control spend, insurance and risk appetite decisions
Learn to communicate cyber risk to boards and CFOs using financial language
Develop a foundation for establishing and maturing a Cyber Risk Quantification program
Why CCRQP Workshop Is Important?
Put a Number on Cyber Risk
Heat maps can show that a cyber risk is "High" or "Red", but they cannot clearly show what it could cost. Cyber Risk Quantification uses loss ranges and probabilities to make cyber risk measurable.
Make Security Investment Defensible
Quantified risk helps organizations evaluate whether a security control is worth the investment and compare potential costs against expected loss.
Strengthen Risk-Based Decisions
Use quantified risk to inform control prioritization, cyber insurance, risk transfer and risk appetite decisions.
Speak the Language of the Business
Build the confidence to take cyber risk from the security team to the boardroom and CFO with numbers, scenarios and evidence.
What Will You Learn?
Foundations and the FAIR Model
Why Quantify Cyber Risk?
- Limits of heat maps and qualitative ratings
- Qualitative vs. quantitative risk
- Speaking the language of the business
- Real incident case study
Risk Fundamentals and Terminology
- Asset, threat, vulnerability, control and loss event
- Inherent vs. residual risk
- Risk appetite and tolerance
- ALE and its limitations
Probability and Statistics Essentials
- Ranges vs. point estimates
- PERT, lognormal and beta distributions
- Calibration and overconfidence
- Monte Carlo simulation
The FAIR Model Deep Dive
- FAIR taxonomy
- Loss Event Frequency & Loss Magnitude
- NIST, ISO 27005 and hybrid approaches
Scenario Scoping and Decomposition
- Define asset, threat, effect and loss types
- Decompose a real-world-based scenario FAIR-style
Estimation, Simulation and Decision-Making
Data and Estimation
- Calibrated SME elicitation
- Internal data
- External sources
- Handling sparse data
Monte Carlo Simulation
- Build the model in Excel (Optional Python track)
- Run simulations
- Read the loss exceedance curve
- Interpret P50, P90 and P95
Control ROI and Risk-Based Decisions
- Before/after control scenarios
- Cost-benefit analysis and prioritization
- Cyber insurance and risk transfer
- Risk appetite thresholds
Communicating CRQ to Leadership
- Board and CFO-ready reporting
- Telling the story behind the numbers
- Common pitfalls and objections
End-to-End Quantification
- End-to-end quantification of a case scenario
- Evaluating a control investment
- Board pitch presentation
Building a CRQ Program
- Maturity roadmap
- Tools landscape
- Q&A and key takeaways