Directors are increasingly asked to sign off on cyber risk without a clear view of how the underlying number was produced. A defensible assessment needs to survive that question: not just what the exposure is, but how it was built.
The five stages behind a defensible number
A cyber risk assessment that can withstand board-level scrutiny runs through the same sequence every time, regardless of which company it is applied to.
1. Company. The operating model, revenue drivers, and the business processes the company cannot run without. This sets the scope of everything that follows. 2. Dependencies. The assets, technologies, suppliers, and access paths that connect to those processes. Exposure does not live in a company’s own systems alone; it lives in the chain. 3. Scenarios. Threat intelligence and business context converted into company-specific loss events, not generic industry-wide risks copied from a template. 4. Quantification. Frequency and magnitude modelled to P50 and P95, so the assessment states both a realistic case and a severe one, rather than a single blended figure that hides which one it represents. 5. Decisions. Treatment economics, prioritisation, and the specific questions worth putting to management, rather than a bare score with no next step attached.
Running the stages in order, every time, is what makes the output inspectable. A director can ask where a figure came from and trace it back through a scenario, a dependency, and a business process, instead of being told to trust a maturity rating.
Why this matters for governance specifically
A board is not evaluating whether a company has a firewall. A board is evaluating whether management is making informed resourcing decisions under uncertainty, which is a different question. Quantified exposure, expressed as a range rather than a colour, gives directors a number that fits the same risk-oversight framework used for financial, operational, or legal risk. It also creates a paper trail: an evidence-labelled assessment shows what was known, what was assumed, and when.
That distinction matters when a director is asked, after the fact, what the company knew about its exposure and when. A maturity score answers nothing. A dated, evidence-labelled assessment answers exactly that question.
What “good” looks like in practice
A sound assessment is confidence-tagged throughout: every estimated field states whether it rests on verified evidence or an assumption, and neither is presented as the other. It is re-run on a cadence rather than treated as a one-time exercise, since exposure moves as a company’s dependencies and control environment change. And it ends in a management question set, not a score: specific decisions the assessment should prompt, not a number that sits in a report unread.
The practical takeaway
An assessment a board can rely on is one where every euro figure can be traced back to a scenario, a dependency, and a business process, calibrated to a stated confidence range, and reviewed before it reaches the table. Anything less is a rating, not an assessment.
