As humans, we are not good at estimating risk. Technology innovator, Ray Amara summed this up, saying, “We tend to overestimate the effect of a technology in the short run and underestimate the effect in the long run.”
To estimate and manage risk effectively, we have to understand two things. The first is the real financial impact that attacks or breaches can have. The second is the potential likelihood that those events will take place.
The Risk Management Association’s 2024 survey of Chief Risk Officers listed cyber risk as the number one issue. Gartner points to spending on IT security solutions growing at 15 percent year on year, to $212 billion in 2025. Additionally, the amount of spending on risk will double by 2027 as well.
How to improve risk management effectiveness
If we want to manage risk effectively, we have to rethink our approach and stop looking at IT security issues on their own. Instead, we have to define risk better for the entire business. American inventor Charles Kettering described this approach as: “A problem well defined is a problem half solved.”
For many IT security teams, risk data usually comes from multiple sources using different tools and scoring mechanisms. These values are hard to amalgamate and normalise to measure the true risk to the business. This can sometimes reduce risk management to a ‘tick box’ exercise that does not add much value. If you cannot normalise the data and enrich it with business context, its value can be limited.
Security leaders need accurate information on the impact of any new or potential issue. They also need a view of the long tail of residual risk they can’t fix. This information needs to be correlated with financial models showing the potential business impact. Put bluntly, we need cold, hard cash values against security issues and probabilities for those issues being exploited in the real world.
This process is known as Cyber Risk Quantification (CRQ). It puts empirical values on risks that represent plausible future losses that could disrupt or derail the business. According to Gartner’s Hype Cycle for Cyber Risk Management, 60 percent of cybersecurity functions will implement business impact-focused risk assessment methods by 2026.
Building out risk management collaboration
Modelling risk helps security teams prioritise against the true business impact. It also helps CISOs educate their boards. What risks exist? How quickly are they being remediated? What support is needed for additional budgets to reduce exposure further?
Yet this kind of data is useful beyond the security team. Chief Financial Officers want to understand the financial impact that any risk event will have on the business. However, they are not IT security experts, so they may not understand the financial aspects of cyber risk.
They have to choose the right financial instruments to manage that risk. To do that, they need the right insight. For example, buying cyber insurance is a necessary step for managing risk. However, getting the appropriate level of coverage requires specific risk insights from the CISO.
The compliance function can also use this data to improve their planning and coverage. By flagging areas where risks would lead to failing compliance rules, the compliance function can work with the security and IT operations team to fix those problems before they become significant issues with fines attached to them.
Centralising risk operations
Risk affects the whole organisation, and data on risk can be used across multiple teams. In the past, this has been a recipe for teams concentrating on their own needs and not working together effectively. Siloed data brings a lack of insight. Teams don’t have the full picture available to them, and they cannot answer the right questions in the first place.
To solve this, we have to look at our operations around risk. How does data on risk conditions get used? How does it get updated over time? Who is responsible for sharing that information so it can be trusted? Ultimately, where is that data coming to and processed so there is a single source of truth around risk?
Introducing the Risk Operations Centre (ROC)
The security team now owns the data around security issues and alerts through the Security Operations Centre (SOC). To understand risk, companies need a Risk Operations Centre (ROC) to manage decisions proactively around risk. The ROC aims to deliver the insight that the security and IT operations teams need to reduce risk.
The ROC also provides the CFO information on potential financial impact and the compliance team with regulatory impact data. While the SOC might detect new threats, the ROC provides prioritised information to the business, the SOC and IT Ops teams. It enables them to work together to carry out remediation and mitigation tasks.
Why is the ROC separate from the SOC? This is because the spread of data is about more than just new alerts or threat intelligence. A ROC should support multiple sources of data. These include IT security tooling, IT asset data, software vulnerabilities, application security, cloud security, and threat intelligence feeds.
The ROC should serve as a cross-functional hub for risk that continuously responds to changes across the organisation. As changes in risk posture occur, the appropriate response can be coordinated based on the business context.
The goal of risk management is to reduce the level of financial impact that any individual issue might pose to the organisation. Understanding risk in a business context ensures resources are deployed more effectively. The overall goal for this is not just to make the business secure. It is to help the business achieve its goals safely and securely. The ROC approach should make that long-term change stick.

Qualys, Inc. (NASDAQ: QLYS) is a leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

















