How Many Cyber Risk Scenarios Should You Model?
Scenario libraries grow. A program starts with ransomware and a data breach, adds a third-party failure after a supplier incident, splits ransomware into encryption and extortion variants, adds a cloud outage, and two years later holds forty entries nobody has revisited. The usual guidance suggests a range, somewhere between five and fifteen, which is a reasonable starting point and answers the wrong question.