Are you interested in understanding the quantified risk of your company’s sensitive data? IBM reports that the average cost of a data breach is $4.88M, but where does that number come from?
It’s challenging to know what a data breach would mean for you and how to prioritize and mitigate risk without understanding the costs and risk factors associated with holding your data.
Quantitative Risk Analysis (QRA) is a process that organizations can use to determine risk in numerical terms.
It helps understand the risks of projects, financial modeling, and business processes. Following a QRA process, an individual or organization would
a) Identify the risks involved with a business or project (by examining historical and environmental data, threats, competition, constraints, industry standards, and other project-specific considerations)
b) Assess the costs of each risk
c) Calculate the probability of each risk taking place
d) Multiply probability times cost for each risk and summarize to get the total risk portfolio
Example: through this process, you may determine that the financial risk of all company-held social security numbers is a precise value, such as $1,461,240. Here is an example risk calculator you can try.

Risk can also be quantified at the device level.

In contrast, qualitative risk analysis is a higher-level and more subjective approach. This measure results in a risk assessment matrix that assigns 1-5 values to the likelihood and impact of a specific risk event.
Elements of Quantitative Risk Analysis
Comprising an interconnected set of logical, computational, and statistical methodologies, QRA calculates a numerical sum of the probability of a risk occurring and its potential impact. These methodologies typically include:
- The Monte Carlo Simulation – a computational algorithm to model a range of possible outcomes and their likelihood, based on thousands or millions of permutations, resulting in a histogram or probability distribution graph
- Sensitivity Analysis – involves running multiple variables through a system or mathematical model and observing the changes, demonstrating which variables exert the most impact on outcomes
- Expected Monetary Value (EMV) Analysis – where the probability of an event occurring is multiplied by its expected financial impact
- Decision Tree Analysis – a method to visualize risks, dependencies, and outcomes from multiple branches of possibilities
QRA Applied to IT and data security
QRA is a robust process for organizations that hold valuable data. It organizes vague impacts from data breaches and loss—regulatory fines, legal fees, reputation and brand damage, business disruption, and customer remediation—into a concrete framework with observable, measurable components.
Reasons to quantify data risk
- Provides the scientific basis for strategic risk management practices, helping companies formulate data-driven strategies where they know what levers to pull
- Empowers them to enact proactive data security, justifying the expense against the potential risk
- Ranks areas of greater risk and business impact, helping businesses prioritize their investments
QRA translates the broad range of impacts from a security event into a monetary value. Rather than a relative or qualitative metric, the financial value can provide a foundation for more precise data security management.
Instead of mitigating against a wide range of risks, organizations can focus on reducing financial exposure to an acceptable level.
Deciding which inputs should impact the monetary value still requires debate, consultation, and consensus among stakeholders. While each organization can and should review what is ultimately considered, the FAIR Institute offers a quantitative risk assessment framework for data that serves as a helpful guide.
Their process uses statistical analysis to determine the “probable frequency and magnitude of future loss,” Monte Carlo Simulation techniques to analyze multiple scenarios for their likelihood and impact, and financial impact analysis to aggregate potential losses stemming from productivity loss, reputation damage, legal fees and penalties, and incident response costs (including ransom payments).
In financial terms, the result is a starting point for your risk management strategy. From there, organizations can explore the factors contributing to risk exposure and make informed decisions to reduce it.
Activating data security strategies with QRA
Of course, the real value of performing QRA and generating an expected monetary value is to eliminate as much financial risk as possible. To guide this process, organizations will want to understand:
- What data is high-impact and highly likely to be compromised, and why? High-value data like credit card records or patient health information presents the highest risk. Start by locating and classifying data and understanding data flows—if this data flows through unsecured or unauthorized repositories, devices, and applications, it will require immediate redress.
- What data is lower value and not essential to business continuity? Categorizing lower-value files, such as marketing documents, helps organizations focus more on higher-priority data.
- What are the most effective ways to safeguard data based on our risk portfolio? Depending on the risk exposure, an organization might consider various security protocols, such as tight user access controls, multi-factor authentication, continuous data monitoring, or encryption for the most valuable data.
By automating FAIR, QRA software helps organizations generate their monetary risk assessment and manipulate data to answer these questions and build their strategy. These solutions identify, categorize, and map sensitive data, conduct the risk assessment, and provide visualization to filter and consume data insights.
Organizations can see their total risk in any currency through a single pane of glass. Further, they can understand their risk exposure by data type or file, device, application, and even user. By mapping data flows, organizations can see the exchanges that led to risk (e.g., a folder of sensitive data in a user’s shadow IT application).
This visibility and insight leads to the most effective action to reduce risk: turning off user access, adding new security steps to access specific data files, or encrypting high-risk data.
There is quick identification and reporting on material risks to stakeholders, board members, and regulators.
A Dynamic Data Security solution provides QRA and data encryption solutions in one platform.


