Methodology

From Zero to One Number

A 12-step playbook for building a Risk P&L — from first risk assessment to board-ready report. Every method grounded in McKinsey, BCG, and Bain research.

Steps
13
Timeline
6–8 weeks
MBB Sources
25+
Assess →Quantify →Treat →Operate

12 steps · 8 weeks · From zero to one number

The Question

"How can I calculate the financial impact of a security risk and report to management a total amount of all risks accepted by individuals?"
The answer is a Risk P&L — a financial statement for cyber risk. It starts with gross exposure, deducts controls, classifies treatments, and produces one EUR number: the total amount of risk accepted by named individuals, with their authority level beside it.
McKinsey
Board wants risks in EUR, not technology metrics. Risk appetite must cascade through delegation tiers.
BCG
No correlation between spending and maturity. Quantify with Monte Carlo. Measure ROI per initiative.
Bain
Only 24% follow best practices. 20-capability maturity model identifies gaps. Insurance market context.
0

Define Your Terms ▾

What a risk assessment is — and what it is not

Duration: 1 dayWho: CISO + Risk Manager
FAIR 3.0 (Open Group, Jan 2025) ISO 27005:2024 NIST CSF 2.0 (Feb 2024)
Output
Shared vocabulary across security, finance, and board
1

Identify Crown Jewels & Risk Scenarios ▾

List the assets that matter most, then the threats to each

Duration: 3–5 daysWho: CISO + Business Unit LeadersSee live output →
BCG: Crown Jewels Stratification (Jan 2023) McKinsey: Risk-Based Approach (2019) Bain: 20-Capability Maturity Assessment
Output
Risk register with 10–15 scenarios mapped to crown jewels
2

Score Likelihood ▾

How often will each risk happen? Use data, not guesses.

Duration: Half dayWho: SOC Lead + Threat Intel + Security EngineerSee live output →
FAIR 3.0: Loss Event Frequency (LEF) BCG Cyber Doppler: Poisson distribution (Phase 2) McKinsey: Probability-loss matrix (2019)
Output
Likelihood score (1–5) per risk with documented rationale
3

Calculate Business Impact in EUR ▾

Turn every risk into a specific EUR number. This requires Finance and Legal.

Duration: 1–2 weeksWho: CISO + CFO team + Legal + Business UnitsSee live output →
FAIR 3.0: Loss Magnitude (LM) BCG: Megabreach avg USD 52M (Sep 2025) McKinsey: Downtime-to-EUR conversion (Aug 2022) Bain: Ransomware > USD 250B projection (2025)
Output
Inherent VaR per risk. Total inherent risk (reference: EUR 84.2M)
4

Map Controls & Measure Effectiveness ▾

What defences exist, and how well do they actually work?

Duration: 1–2 weeksWho: Security Engineering + Tool OwnersSee live output →
FAIR-CAM v1.0 (Open Group, 2024) BCG Cyber Doppler: 128+ controls mapped Bain: 20-capability gap identification Gartner CARE: "Effective" dimension
Output
Residual risk per scenario. Total residual (reference: EUR 38.6M)
5

Classify Each Risk: Mitigate, Transfer, Accept, Unsigned ▾

Four treatment options — same as any business risk

Duration: Half dayWho: CISO + CRO + Risk CommitteeSee live output →
BCG: Four-way treatment split (Sep 2025) ISO 27005:2024: Risk treatment options BCG: "No correlation between spending and maturity"
Output
Treatment classification per risk with rationale
6

Build the Delegation Authority Matrix ▾

Who can accept how much risk — cascading from the board

Duration: 1 weekWho: CISO + CRO + CFO + Board SecretarySee live output →
McKinsey: Risk appetite cascading (Feb 2026) McKinsey: Delegation matrix concept (Aug 2022) SOCI Act Art. 20: Personal liability CPS 234 Art. 5: Management body responsibility
Output
Signed delegation authority framework
7

Build the Accepted Risk Ledger ▾

The table that answers the original question: who accepted what, in EUR

Duration: 2–3 daysWho: Risk Manager + All AcceptorsSee live output →
SOCI Act Art. 20: Personal accountability CPS 234 Art. 5(2)(c): Clear roles and responsibilities McKinsey: Named acceptor per risk
Output
Accepted Risk Exposure by person — the one number for management
8

Connect Live Tool Evidence ▾

Keep the numbers current with data from tools you already own

Duration: 1 day setup, 2–3 hours/monthWho: Security Engineering + SOCSee live output →
BCG Cyber Doppler: Live frequency adjustment McKinsey: Strategic Nerve Center (Dec 2025) Gartner CARE: "Effective" dimension (2024) FAIR-CAM v1.0: Evidence-based adjustment
Output
Evidence-adjusted ALE (reference: static EUR 3.61M → EUR 9.42M, +161%)
9

Calculate Investment ROI ▾

For every EUR spent, how much risk does it remove?

Duration: 2–3 daysWho: CISO + CFOSee live output →
BCG Cyber Doppler: ROI formula (patented) McKinsey: Risk-based saves EUR 9M vs maturity-based (2019) McKinsey: Altitude + trajectory reporting (Jan 2020)
Output
Prioritised investment table (reference: EUR 840K → EUR 12M reduction, 14.3× ROI)
10

Review Insurance Coverage ▾

What's insured, what's not, and where's the gap

Duration: Half dayWho: CISO + CFO + Insurance BrokerSee live output →
Bain: Ransomware > USD 250B (Global Insurance Report 2025) BCG: Cyber insurance as risk mitigation (Apr 2018) German AktG §§ 93, 116: Board fiduciary duties
Output
Coverage gap analysis and optimization recommendation
11

Document Regulatory Context ▾

SOCI Act, CPS 234, Privacy Act — why this is mandatory, not optional

Duration: 1 dayWho: Legal + Compliance + CISOSee live output →
SOCI Act (EU) 2022/2555 Art. 20, 21, 34 CPS 234 (EU) 2022/2554 Art. 5 Privacy Act (EU) 2016/679 Art. 83
Output
Regulatory mapping per risk + penalty exposure table
12

Assemble the Board Report ▾

Three numbers. One table. One ask.

Duration: 1 weekWho: CISO + Risk ManagerSee live output →
McKinsey: Risks not technology (Aug 2025) McKinsey: Altitude + trajectory (Jan 2020) Gartner CARE: Program defensibility (2024) Diligent/Bitsight: Cyber oversight = 3.7× TSR (Mar 2024)
Output
Board-ready report with three numbers, accepted risk ledger, investment ask

Timeline

6–8 weeks to first board-ready report. After the first cycle, quarterly updates take 1–2 weeks.

Week 1
Risk InventorySteps 0–1
Week 1–2
Likelihood ScoringSteps 2
Week 2–3
EUR ImpactSteps 3
Week 3–4
Control EffectivenessSteps 4
Week 4–5
Treatment + DelegationSteps 5–6
Week 5–6
Accepted Risk LedgerSteps 7
Week 6–7
Evidence + ROISteps 8–9
Week 7–8
Insurance + Board ReportSteps 10–12

Framework Attribution

McKinsey
Risk-Based Approach to Cybersecurity (2019) — risk-based vs maturity-based, EUR 9M savings
Creating a Technology Risk Appetite Framework (Aug 2022) — delegation cascading
Enhanced Cyberrisk Reporting (Jan 2020) — altitude + trajectory, KRI/KPI
Competitive Advantage Through Cybersecurity (Aug 2025) — board wants risks, not technology
Global Risk Productivity Survey (Feb 2026) — deeper risk appetite cascading
The Future of Risk (Dec 2025) — Strategic Nerve Center concept
Nth-Party IT Risk (Jul 2025) — 33% of breaches from supply chain
BCG
Cyber Doppler ROI Methodology (patented) — Monte Carlo + ROI formula
Reframing Cybersecurity as a Business Discipline (Sep 2025) — spending ≠ maturity, USD 52M megabreach avg
AI Is Raising the Stakes in Cybersecurity (Dec 2025) — 60% faced AI-powered attacks, 7% use AI defense
Overprotect Your Crown Jewels (Jan 2023) — crown jewels stratification
Cyber Insurance as Risk Mitigation (Apr 2018) — insurance transfer overlay
Bain
Most Companies Overestimate Their Cybersecurity (2024) — only 24% follow best practices
Global Insurance Report 2025 — ransomware > USD 250B projection
20-Capability Maturity Assessment — qualitative gap identification
Bain Capital Ventures Security Predictions 2026 — identity as primary failure mode
Standards & Frameworks
FAIR 3.0 (Open Group, Jan 2025) — LEF × LM quantification standard
FAIR-CAM v1.0 (Open Group, 2024) — Controls Analytics Model
NIST CSF 2.0 (Feb 2024) — Govern function for board accountability
ISO 27005:2024 — risk treatment options
Gartner CARE Framework (2024) — Consistent, Adequate, Reasonable, Effective
Diligent/Bitsight (Mar 2024) — cyber oversight ↔ 3.7× total shareholder return
Regulation
SOCI Act (EU) 2022/2555 Art. 20, 21, 34 — personal board liability, EUR 10M or 2%
CPS 234 (EU) 2022/2554 Art. 5 — management body ultimate responsibility
Privacy Act (EU) 2016/679 Art. 83 — EUR 20M or 4% turnover
German AktG §§ 93, 116 — board fiduciary duties, D&O exclusion risk

See it in action

The Risk P&L page shows a live implementation of this methodology — every EUR figure is interactive.

View Risk P&L →