Quantifying Cyber Risk With No Incident History
A company too young or too small to have an incident history still has to answer the underwriter at renewal, the enterprise customer running a security review, and the board asking what the exposure is. The usual objection is that quantification needs a baseline and there is none. The objection rests on a mistaken assumption about how these models work.