I once sat through most of an afternoon while a very capable group of people argued about whether a ransomware event would cost the company four million dollars or seven. Two consultants, a CFO, a general counsel and a security team. Three hours. Real expertise in the room.
Nobody asked how confident anyone was in either figure. When I finally did, the honest answer was that the true range ran from about one million to somewhere past forty. Every minute of that argument had been spent on a distinction that sat well inside the noise.
That meeting was not unusual. It is close to the standard experience of cyber risk quantification in large organisations, and it explains why a discipline with sound mathematics behind it so rarely changes what anyone does on Monday.
What a risk estimate is actually for
Begin where nobody disagrees. Expressing risk in money is better than a heat map. Red, amber and green cannot be added together, cannot be compared to the cost of a control, and cannot be argued with, which is exactly why they survived so long. Converting risk to dollars is real progress and I would not go back.
Now push one level down and ask what the estimate is for. It exists to help someone choose between actions. That is the whole job. And two actions are only distinguishable by a number if the number is precise enough to separate them.
Which means the useful output of a quantification exercise was never the central figure. It is whether the range around that figure is narrow enough to tell your options apart. If your exposure is four million give or take two hundred thousand, you can decide whether a nine hundred thousand dollar control is worth buying. If it is four million give or take twenty, you cannot, and no amount of debate about the four will change that.
Here is the sentence the rest of this rests on. A wide range is not a failed estimate. It is a finding, and the right response to it is to buy information rather than to buy defence.
The scenario that repeats
Take a manufacturer modelling ransomware exposure. The output comes back with a 90 percent confidence interval running from roughly 1.2 million to 46 million. The security team presents the mean. Leadership reacts to the mean. The debate that follows is about which of three controls to fund.
That debate is unresolvable, and the reason is visible if anyone decomposes the width rather than the mean. Almost all of the spread traces to a single input. How many systems would actually have to be rebuilt rather than restored, and how long a full restore genuinely takes at their scale.
Nobody in the building knows. The backup vendor's documentation gives a figure. The runbook repeats it. No one has ever executed a restore at anything close to full scale, so the model carries an enormous range on that one variable, and that range floods everything downstream.
The correct next expenditure is not any of the three controls. It is a full-scale restore test, which costs a weekend, some overtime and perhaps forty thousand dollars. Run it, and the range collapses to something like three to nine million. Now the control debate has an answer, and it takes twenty minutes.
The forty thousand dollars did not reduce risk by a single dollar. It bought the ability to spend the next nine hundred thousand correctly, which is worth considerably more.
Most of your uncertainty is self-inflicted
There is a fair objection to all of this, and it is the one every practitioner raises. Security will never have narrow ranges. The data does not exist, adversaries are not actuarial tables, and demanding precision before action is a recipe for paralysis dressed up as rigour.
That objection is right about one thing and wrong about the thing that matters.
It is right that adversary behaviour is genuinely unpredictable. Whether a particular group targets you next quarter is not knowable and never will be. That is irreducible uncertainty and no measurement removes it.
But open up a typical security risk model and look at what is actually driving the width. It is almost never the adversary. It is facts about your own environment that nobody has bothered to establish. How many systems are in scope. How long a restore really takes. Whether the cyber policy covers this particular scenario or excludes it in a clause nobody has read since renewal. What the contractual penalties are with your three largest customers. Which regulator has jurisdiction and what their published penalty range looks like.
None of that is unknowable. All of it is measurable in weeks by people already on payroll. That is self-inflicted uncertainty, and it is where most of the width lives.
The recovery assumption in particular deserves scrutiny, because it appears in nearly every model and is almost never tested. Arcserve's 2026 State of Data Resilience report, a vendor-sponsored survey of more than 200 IT professionals conducted in the first half of 2026 and weighted toward organisations under 500 employees, found that 65.1 percent were confident they could recover from a ransomware event within 48 hours. When recovery was actually validated, 35.4 percent met their recovery point and recovery time objectives. Roughly a quarter had never tested a full recovery at all.
Treat those numbers as directional rather than precise given the sponsorship and the sample. The direction is still the point. The single input that dominates the width of most ransomware models is the one input a majority of organisations have never measured.
The lower bar than you think
You also do not need narrow ranges everywhere, which is where the paralysis objection quietly overreaches. You need ranges narrow enough to separate the specific options currently in front of you. That is a far lower bar than actuarial precision.
If the choice is between a two hundred thousand dollar control and doing nothing, an estimate spanning six to eleven million is entirely sufficient. Buy it. The decision is not close and the width does not matter. The width only matters when the options are close together, and then it matters completely.
This is ordinary practice in every other field that prices uncertainty. An oil company drills an appraisal well before committing to development. A pharmaceutical company runs a phase two trial to decide whether phase three is worth funding. Insurers price the cost of a survey against the reduction in variance it buys. Security is the only risk discipline I know that treats a wide interval as an embarrassment to be hidden rather than as an instruction about what to do next.
Running it alongside what you already do
Nothing here requires a new methodology or a different vendor. On your next quantified risk, change only the presentation. Publish the range rather than the mean, and beside it publish a decomposition showing which two or three inputs account for most of the width.
Then add one line that most risk reports have never carried. What it would cost to measure the largest of those inputs, and how much the range would narrow if you did.
Three questions to put in front of your team on Monday. For your largest quantified risk, what are the 5th and 95th percentile values. Which single input, if you knew it exactly, would shrink that spread the most. And what would it cost to go find out.
If your team can answer the first question immediately, you are already running this well. If the answer to the second is the adversary, look harder, because it usually is not. If nobody has ever costed the third, that is the cheapest improvement available to your program this year.
What changes
Budget requests start arriving in sequence rather than all at once. Cheap measurement first, expensive controls second, and each control request arriving with an estimate precise enough to justify it. That sequencing is worth more than any individual purchase, because it applies to every purchase after it.
It also gives leadership and the board something better than an annual number that moves for reasons nobody can explain. They get to watch uncertainty shrink. A range that goes from 1.2 to 46 million one year, then 3 to 9 the next, then 4 to 6 the year after tells a story about a maturing program that no point estimate can tell, and it survives contact with a hard question.
The number tells you what you currently believe. The width tells you what to do about it.