Why Your Cyber Risk Assessments Change Nothing (5 Fixes)

Simply Cyber
Simply CyberMar 22, 2026

Why It Matters

By turning risk assessments into decision‑making tools, organizations can allocate security budgets more effectively, reduce compliance fatigue, and strengthen board confidence in cyber investments.

Key Takeaways

  • Traditional risk assessments rarely drive actionable decisions today
  • Use probability ranges instead of single-point estimates for risk
  • Align cyber risk metrics with existing financial frameworks
  • Match communication tools to audience: boards need dollars, engineers need CVSS
  • Demonstrate due diligence through documented, range‑based risk analyses

Summary

The video challenges the status quo of cyber risk assessments, arguing that most of today’s GRC practices produce heat maps and registers without influencing real business decisions. Steve McMichel deconstructs why risk management has become ritualistic, citing “risk theater” and the false precision of single‑point loss estimates, and he proposes a shift toward engineering‑focused tools and quantitative ranges.

Key insights include the observation that few organizations tie risk quantification to concrete decisions, the pitfalls of presenting a red‑quadrant heat map that never moves the board, and the advantage of expressing threats as probability ranges (e.g., 5‑10% chance of a $2‑8 million ransomware loss). He also critiques prescriptive thresholds, noting that static metrics like click‑rate can damage security culture, while dynamic, range‑based assessments better reflect cyber’s evolving nature.

McMichel references Adam Showstack’s keynote poll—where almost no hands raised for risk‑driven decisions—and Tony Martin‑Veg’s “boardroom moment” where executives ignored a high‑risk heat map. He illustrates the improved approach with a concrete ransomware scenario that sparks discussions about insurance, mitigation spending, and capital reserves.

The takeaway for practitioners is threefold: rewrite top risks using probability ranges, verify that each assessment drives a decision, and tailor communication tools to the audience—bug bars for developers, dollar‑based risk quantification for finance, and clear ROI narratives for the board. Implementing these fixes can revitalize GRC careers and deliver measurable business value.

Original Description

Heat maps generated. Registers maintained. Boxes checked. Decisions unchanged. Sound familiar?
In this video, Steve McMichael shows you:
✅ Why heat maps fail executives (and where they actually work)
✅ The false precision trap that kills your credibility
✅ 5 principles to make risk management actually drive decisions
TIMESTAMPS:
0:00 - Stop trying to manage cyber risk?
0:30 - Intro
1:04 - The critique: Risk quantification that leads nowhere
1:54 - The problem of risk theater
2:29 - The boardroom moment
3:42 - The false precision trap
4:10 - How other industries handle uncertainty
5:12 - The case for prescriptive standards
6:02 - Why prescriptive standards break down
7:10 - Engineering mechanisms: Bug bars & CVSS
8:24 - 5 Principles for doing risk management properly
8:35 - Principle 1: Connect to what the business understands
9:08 - Principle 2: Embrace uncertainty
10:14 - Principle 3: Make your analysis lead to decisions
10:38 - Principle 4: Speak the language of your audience
11:05 - Principle 5: Demonstrate due diligence
11:26 - Stop performing, start practicing
11:41 - 3 things you can do Monday morning
RESOURCES MENTIONED:
🎙️ Richard Seiersen on Cyber Risk Quantification: https://www.youtube.com/watch?v=8ZvBfKiCMD8
📖 Chris Hughes - GRC is Ripe for a Revolution: https://www.resilientcyber.io/p/grc-is-ripe-for-a-revolution
📖 Tony Martin-Vegue - Heatmaps to Histograms: https://www.tonym-v.com/essays
📚 How to Measure Anything in Cybersecurity Risk (Hubbard & Seiersen): https://www.amazon.ca/How-Measure-Anything-Cybersecurity-Risk/dp/1119085292
🔧 GRC Engineering Manifesto: https://grc.engineering/
WANT TO GO DEEPER?
Check out the Cyber Risk Management Foundations course with Steve McMichael featuring 3 hours with Dr. Gerald Auger in Simply Cyber Academy: https://academy.simplycyber.io/p/acrmf
=========================
Simply Cyber empowers people who want a rewarding cybersecurity career 💪
=========================
=========================
All the ways to connect with Simply Cyber
=========================

Comments

Want to join the conversation?

Loading comments...