How to run a cyber risk analysis yourself
A risk analysis is two estimates and one multiplication. Everything difficult about it is in deciding what exactly you are estimating - which is why the method starts with a definition and not with a number.
At a glance
- What it produces
- An expected value per scenario: likelihood multiplied by damage
- Time required
- About an hour for a listed company with public filings
- Inputs needed
- A resolution rule, a base rate, a damage bound, all publicly available
- What it cannot do
- Predict an outcome; it bounds one and prices the uncertainty around it
What a risk analysis actually is
A risk analysis answers one question: how much should I expect to lose from this, in expectation, across every way it could go. It is not a prediction of what will happen. It is a weighted account of what could, and the weight is a probability you have to defend rather than a feeling you have to declare.
The arithmetic is deliberately trivial. For each scenario, estimate the likelihood it occurs and the damage if it does, multiply them, and add up. The result is an expected value, and its most useful property is that it re-sorts scenarios against intuition: a 5 per cent chance of losing 40 per cent carries twice the weight of a 40 per cent chance of losing 5 per cent, and almost nobody ranks those correctly by eye.
The reason so many risk analyses are worthless is not that the arithmetic is hard. It is that the scenarios were never defined tightly enough to estimate. 'Reputational damage' is not a scenario; 'the launch slips past the quarter end, announced by the company' is. If a scenario cannot be written as something that either did or did not happen by a date, no probability you attach to it means anything.
A number without a resolution rule is a mood with a decimal point. Define the event first, estimate second - never the other way round.
What the output is actually good for
The first use is comparison against a price. If a market says 12 per cent and your analysis says 4, you have a disagreement you can inspect: either your base rate is wrong, your scenario is not the one the market is pricing, or the market is wrong. Two of those three are fixable by reading more, and finding out which is most of the value of doing this at all.
The second use is sizing. An expected value tells you what a position is worth in the long run; the spread of the scenarios tells you how much of it you can afford to be wrong about. A thesis whose expected value comes almost entirely from one low-probability scenario is a different proposition from one where five scenarios contribute evenly, even when the totals match exactly.
The third use is the one people skip, and it is the most valuable. A completed analysis frequently says: do not trade this. When the expected value sits inside the spread, or when the scenario that dominates it is the one you understand least, the correct output is no position. An analysis that has never once told you to stand aside is not an analysis, it is a justification.
- Compare against the market price, then find out which of you is wrong and why.
- Size the position against the spread of scenarios, not just the total.
- Notice when one scenario carries most of the expected value - that is your real exposure.
- Accept 'no position' as a valid and common result.
The method, in six steps
The steps below are the whole method. They are in this order because each one constrains the next: you cannot pick a base rate before you have defined the event, and you cannot bound the damage before you know which scenario you are bounding. Skipping ahead is the single most common way these analyses go wrong.
Everything the method needs is public. Filings are free on EDGAR, price history is free from any exchange data page, incident base rates are published annually by Verizon and IBM, and legal deadlines are in the regulations themselves. There is no proprietary input anywhere in this list, which is worth knowing before you pay anyone for a number you could have derived.
Two disciplines make the difference between a real analysis and a decorated guess. Write the estimate down before you look at the price - once you have seen the price you cannot un-see it, and your 'independent' estimate will drift towards it. And record the reasoning next to each number, so that when the outcome arrives you can tell which step was wrong rather than concluding vaguely that you were unlucky.
- Filings and disclosures: SEC EDGAR full-text search, free, and the only authoritative record for a US issuer.
- Price history: any exchange or broker data page, for measuring what comparable events actually did.
- Incident base rates: the Verizon breach report and the IBM cost report, annually, with a stated vintage.
- Legal deadlines: the regulations themselves, not a summary of them - the trigger wording is the whole point.
- The company's own words: investor relations, newsroom, earnings calls, read for what they commit to rather than for tone.
1Define the event
Write it as something that either did or did not happen by a date. If you cannot, stop here
Where most analyses already fail
2Read the resolution rule
Which document settles it, published where, by when - and what happens if nobody publishes anything
3Find the base rate
How often has this happened to comparable companies, with a source and a vintage
4Bound the damage
A range, not a point, expressed as a share of something named - market capitalisation, bookings, revenue
5Plot the matrix
Likelihood against damage for every scenario, then multiply to get the expected value
6Compare with the price
Last, never first. Then decide which of you is wrong, or take no position
The step that must not move to the front
Behind the subscription
The rest of this entry is the part that changes a decision: what moves the price, which contract sets it, who ships it and where that can be cut off.
The five variables, and a worked matrix
The five inputs that decide the answer, and the GTA 6 leak plotted through all of them - five scenarios, five expected values, one conclusion.
Where each input actually comes from
Five sources, what each one is authoritative for, how often it updates, and the failure mode of each.
Step four, worked: bounding the damage
The damage calculation on the live case, line by line - including the part of it that reversed within a day.
Step six: turning the estimate into a position
How to convert a matrix into a market question, and the four checks that decide whether to take a position at all.
Included with a subscription
Create an account to unlock the full entry — price drivers, trading venues, trade flows and the live markets attached to it.
Frequently asked questions
- How do I do a cyber risk analysis myself?
- Six steps, in order: define the event as something that either did or did not happen by a date; read the resolution rule to find which document settles it; find a base rate from a sourced, dated population study; bound the damage as a range expressed against a named denominator; plot likelihood against damage for each scenario and multiply to get expected values; and only then compare with the market price. Every input is public and free.
- What is a risk matrix and why use one?
- It plots each scenario by how likely it is and how much damage it causes, so that scenarios of different shapes become comparable. Its value is that it re-sorts against intuition: a 5 per cent chance of a 40 per cent loss carries twice the expected weight of a 40 per cent chance of a 5 per cent loss, and almost nobody ranks those correctly without doing the multiplication.
- Where do I get the numbers?
- Filings from SEC EDGAR, price history from any exchange data page, incident base rates from the annual Verizon breach report and the IBM cost report, legal deadlines from the regulations themselves, and commitments from the company's own investor relations pages. None of it is paywalled. Record which source each estimate came from, so you can tell later which step was wrong.
- How do I estimate a probability I cannot look up?
- Anchor on the closest population base rate you can source, then adjust for the specific case and write down each adjustment and its reason. An unanchored estimate is untestable; an anchored one with recorded adjustments can be checked step by step after the outcome. If you cannot find any anchor at all, that is itself information: the scenario is probably defined too loosely to estimate.
- When should the analysis tell me not to trade?
- When the expected value sits inside the spread and fees, when the scenario carrying most of the expected value is the one you understand least, or when you cannot name evidence that would change your mind before resolution. A method that has never returned 'no position' is not measuring anything - it is producing justifications.
Primary sources
The worked example is an illustration of the method, not a recommendation or a forecast. The scenario probabilities are estimates, labelled as such, and the prices behind them go stale quickly.
Related entries
Prediction markets carry real risk of loss. Nothing on Market Guy is financial advice — it is research tooling to help you think, not a signal to trade.