Cyber Risk Quantification: What UK CISOs Must Show the Board
UK CISOs must translate cyber exposure into financial terms in 2026: boards no longer accept red-amber-green risk heatmaps as a substitute for probable loss figures.
The Financial Conduct Authority expects directors to understand operational and cyber exposures in terms they can act on, and the Information Commissioner’s Office requires senior accountability for personal data controls. That combination means boards increasingly expect to see probable loss ranges, control effectiveness scores and recovery time objectives — not a traffic-light dashboard that tells them nothing about what a breach would actually cost.
Why Are Boards Rejecting Red-Amber-Green Cyber Reporting?
A heatmap tells a board that a risk is “high” without saying high compared to what, or high in what currency. Non-executive directors making capital allocation decisions elsewhere in the business — where every proposal comes with a modelled financial return — reasonably ask why cyber risk is presented differently. If 2025 was the year resilience was tested across UK organisations, 2026 is shaping up as the year boards insist resilience be measured in numbers they can compare against other risks on the register.
This is not a cosmetic reporting change. Quantification forces CISOs to be explicit about assumptions — asset value, likelihood, control effectiveness — that a heatmap lets remain implicit. That discipline alone often reveals gaps in the organisation’s own understanding of its exposure.
Executive Action:
- Replace the cyber heatmap with a probable loss range for the top five scenarios
- Document the assumptions behind each figure so the board can challenge them
- Review and update the model at least twice a year, not annually
What Should a Quantified Cyber Risk Model Actually Include?
A credible model combines three inputs: the financial value of the assets or processes at risk, the likelihood of a given scenario based on threat intelligence and historical incident data, and the effectiveness of existing controls in reducing that likelihood or impact. CISOs should present a range, not a single number — boards understand uncertainty better than false precision, and a range signals the model is honest about what it does not know.
Recovery time objectives belong alongside the financial figures, not in a separate technical appendix. A board evaluating whether £2 million of proposed investment is justified needs to see both the loss avoided and how much faster the organisation would recover — the two numbers together, not apart, make the investment case.
Executive Action:
- Build loss models from asset value, likelihood and control effectiveness, not intuition
- Present a range rather than a single point estimate for every scenario
- Use INFORMD’s AI governance test and project review checklist as a template for structuring risk documentation
How Does This Connect to the UK Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, expands regulation across essential services and gives regulators tougher enforcement powers. It also raises the bar for what “understanding cyber risk” means at board level — a bill built around accountability for accounting officers, senior leaders and departmental CISOs assumes those leaders can articulate exposure in terms that support real decisions, not just compliance checklists.
CISOs preparing for this Bill’s eventual requirements should treat quantification as preparation, not an optional add-on. A board that can already answer “what would this cost us and how fast would we recover” is far better positioned to demonstrate the accountability the Bill expects than one still relying on a heatmap.
Executive Action:
- Map current cyber risk reporting against the accountability expectations in the Cyber Security and Resilience Bill
- Brief the board on gaps between current reporting maturity and what the Bill will expect
- Assign a named senior owner for cyber risk quantification, distinct from day-to-day security operations
How Should CISOs Introduce Quantification Without Losing Board Confidence?
Introduce quantification alongside the existing heatmap for at least two reporting cycles before replacing it entirely. A sudden shift from qualitative to quantitative reporting can make a board suspicious that previous risk ratings were unreliable, when in fact the organisation is simply maturing its measurement approach. Running both in parallel lets directors build confidence in the new figures against a reporting format they already trust.
CISOs should also be candid about which scenarios cannot yet be quantified with confidence, rather than forcing false precision across the board. Boards respect a CISO who says “we do not yet have reliable data for this scenario” far more than one who presents an unsupportable number.
Executive Action:
- Run quantified and heatmap reporting in parallel for at least two board cycles
- Flag scenarios where data is too immature to quantify reliably
- Use INFORMD’s capital approval assessment template to link cyber investment cases to quantified risk reduction
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
Cyber risk quantification translates security exposure into financial terms — probable loss ranges, control effectiveness and recovery time objectives — rather than qualitative ratings like a red-amber-green heatmap.
Heatmaps show relative severity without financial context, making it hard for directors to compare cyber risk against other risks on the register that are already expressed in monetary terms, such as credit or market risk.
Asset or process value at risk, likelihood based on threat intelligence and historical incident data, and the effectiveness of existing controls — combined to produce a probable loss range rather than a single number.
The Bill, introduced to Parliament in November 2025, expands regulation and enforcement across essential services and assumes accounting officers and senior leaders can articulate cyber exposure in decision-useful terms, making quantification a practical form of preparation.
