# Cyber Risk Quantification: Ditch The Spreadsheet And Take A Seat At The Business Table

“I want to quantify my cyber risk using the FAIR risk model. Now I need to make a decision: build a spreadsheet or use a commercially available software such as RiskLens.” Have you had this conversation with yourself?

We’ve heard people say this on quite a few calls. It’s exciting because more and more organizations are adopting FAIR and are moving towards quantifying their cyber risk. That being said, home grown solutions – specifically spreadsheets – aren’t necessarily the answer.

Don’t get me wrong, as a math graduate, I LOVE SPREADSHEETS! Programming, color coding, and making them easy for other people to use and navigate. However, there are times when I bang my head against a wall trying to figure out why the yellow diamond with an exclamation point is suddenly my answer instead of a numeric value I was expecting.

Am I using the spreadsheets to quantify cyber risk? No, rather for much easier tasks. So, I can imagine the headache accompanied with the implementation of Monte Carlo simulations only to get the bothersome “#VALUE” output. Are there other frustrations with going the spreadsheet route? Yes, like:

1) Delayed start of quantification

It takes time to build a spreadsheet. If analysts are tasked today to make a spreadsheet to quantify cyber risk, it could take months or even up to a year for a quantification spreadsheet to be up and working.

2) Things are figured out as you go

At first, it might seem like it will be a piece of cake to make a spreadsheet that is able to quantify your cyber risk. Then as the spreadsheet is being built, it becomes clear that more information is needed from different disciplines – cyber, finance, risk, math, etc. – making it hard to incorporate multi-disciplinary knowledge and formulas from all.

This is problematic if multiple analysts are working on one spreadsheet. They must send the spreadsheet to one another and make sure the newest version is being edited. Don’t forget that if new values are inputted into new cells then you have to run another simulation to get the updated scenarios.