Forward by Stuart McClure: CEO of Cylance “What the authors of this book have done is begin to define a framework and a set of algorithms and metrics to do exactly what the industry has long thought impossible, or at least futile: measure security risk.” Continue...

Forward by Daniel E. Geer, Jr., ScD.: CISO In-Q-Tel “It is my pleasure to recommend How to Measure Anything in Cybersecurity Risk….If you have any interest in taking care of yourself, of standing on your own two feet, of knowing where you are, then you owe it to...

“At a time when forecasts tell you a great deal about the forecaster but nothing about the future, comes a practical guide for capturing and articulating risk in the board room with great success.” —Tim McKnight, CISO, GE; former CISO,...

“A refreshing voice of reason in cybersecurity risk management. Richard and Douglas successfully rise above noisy security best practices and flashy methods; practitioners have a lot to gain from the clarity within this book’s pages.” —Vinnie Liu, partner at Bishop...

“I am excited to see a new method of risk management emerging from this book. Shifting from purely qualitative judgments and simplifications to a proven quantitative model that leverages measurements and the expertise of security professionals holds the promise...