Discussion about this post

User's avatar
BHoskinson's avatar

Great article, I am definitely going to read through the Reddit AMA. I preordered the book so hopefully it will arrive soon after I finish reading Jack Jones second edition of measuring and managing information risk.

Keith Stouder's avatar

Tony, great article. I share the same challenge when explaining cyber risk: it requires both probability (likelihood) and magnitude (loss). You can make a rough judgment with only one, but you cannot determine actual risk without both. It is like blood pressure; you might infer something from a single number, but a true classification requires both systolic and diastolic values because they represent different phases of the system's function. Risk works the same way. I am curious to hear your thoughts on this analogy.

2 more comments...

No posts

Ready for more?