Forge University
CISM

Stop Saying "High Risk." Start Saying "$2.4 Million a Year."

August 19, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Color-coded risk warnings on one side of a table transforming into stacked coins on the other

A security leader who says a risk is "high" gives a board nothing to act on. A security leader who says a risk carries an annualized loss expectancy of $2.4 million gives the board a number it can compare against the cost of a control, an insurance premium, or a competing budget request. That shift from color-coded scoring to dollar-denominated analysis is exactly what CISM's risk management domain trains, and it is increasingly what regulators expect to see documented.

Why do qualitative risk ratings fail under audit and regulatory scrutiny?

Qualitative scoring fails because "high," "medium," and "low" don't hold still across reviewers or over time. NIST's guide for conducting risk assessments notes that in qualitative assessments the range of values is comparatively small, which makes relative prioritization or comparison across a set of reported risks genuinely difficult, and that unless each value is clearly defined, different experts can produce significantly different results from the same facts.

That inconsistency is a liability once a regulator, auditor, or plaintiff's attorney asks how a risk rating was derived. A heat map can't answer whether a $500,000 control investment was justified. A dollar figure can, which is why the FAIR Institute points out that quantification lets an organization show how a specific investment in a control reduces annualized loss expectancy by a measurable amount, rather than simply asserting the investment was warranted.

What does the CISM exam actually require you to know about quantifying risk?

CISM devotes an entire job practice domain to this, not a footnote. According to ISACA's official CISM exam content outline, the certification tests candidates across four domains built from research and validation with subject matter experts and industry leaders worldwide, and information security risk management is one of the largest of those domains by weight. Candidates are expected to move past intuition and apply structured methods, including the core quantitative building blocks: single loss expectancy, annualized rate of occurrence, and the resulting annualized loss expectancy that ties a specific threat to a specific dollar figure per year.

That matters for procurement because a CISM credential is not a generic "security awareness" badge. It is evidence that the holder was tested on producing the exact artifact a board, auditor, or regulator now expects: a defensible number, with an assumption trail behind it, rather than a color on a slide. If you're building out a security governance function and want a curriculum overview of how risk analysis fits alongside governance, incident response, and program management, the CISM certification prep resources lay out the full domain breakdown.

How did the SEC turn risk quantification into a documentation requirement?

The SEC didn't mandate a specific risk formula, but it did mandate that companies show their work on materiality. The SEC's 2023 rules on cybersecurity risk management, strategy, governance, and incident disclosure require registrants to describe their processes for assessing, identifying, and managing material risks from cybersecurity threats, along with the material effects or reasonably likely material effects of those risks. The same rules require an Item 1.05 Form 8-K within four business days once a registrant determines an incident is material.

That four-day clock is the practical problem. A team that has never quantified anything cannot suddenly produce a defensible materiality judgment under deadline pressure. A team that already tracks single loss expectancy and annualized rate of occurrence for its top risk scenarios has the inputs sitting in a register, ready to be recalculated against a live incident. The certification isn't decorative here. It's the difference between a materiality determination a general counsel can sign off on and one built on a gut call made in a conference room.

What do state and sector regulators expect a CISO's risk register to contain?

Financial services regulators go further than the SEC and name the governance chain explicitly. Under New York's cybersecurity regulation, Section 500.4 requires a designated CISO to oversee the cybersecurity program, including the risk assessment, and it requires the board or senior governing body to receive the CISO's annual report covering program status, material risks, material incidents, and remediation plans. The regulation doesn't dictate which risks to mitigate, but it does require the program to be risk-based and the decisions to be documented, with each risk assigned a response of mitigate, accept, transfer, or avoid.

"Risk-based and documented" is a quantitative standard in practice, even when the regulation text stays technology-neutral. A board asked to accept residual risk on a named threat wants to know what it's accepting in dollar terms, not just a rating. This is the same governance and risk documentation muscle covered in Forge University's broader certification resources, which walk through how domain-specific skills map to the controls an auditor will actually ask to see evidence of.

How does a certification function as staff-accountability evidence for procurement?

When a regulated organization hires or promotes into a security leadership role, the CISM credential answers a question procurement and compliance teams are increasingly required to ask: can we show, on paper, that the person accountable for this risk register was independently tested on the methodology behind it? That question shows up in vendor due diligence questionnaires, in cyber insurance underwriting, and in board minutes documenting why a particular hire was deemed qualified to sign a risk acceptance.

A table helps make the contrast concrete between what each rating style actually delivers to a decision-maker.

Risk Communication StyleWhat It Tells a BoardWhat It Tells an Auditor
Qualitative (Low/Medium/High)A relative sense of concernLittle repeatable methodology
Quantitative (ALE in dollars)A number to weigh against control costAn assumption trail (SLE x ARO) that can be reviewed and challenged

The right column is what a certified risk analyst is trained to produce, and it's what shows up in board minutes and audit workpapers as the paper trail behind a risk acceptance decision.

Building the skill instead of hoping it develops on the job

Quantitative risk analysis isn't intuitive, and most security professionals never see it modeled well before they're asked to defend a number in front of a board. It has to be practiced with real scenarios: estimating asset value, modeling threat frequency, calculating single loss expectancy, and stress-testing the resulting annualized loss expectancy against a skeptical audience. That's a different skill than knowing the definitions of the CIA triad or the phases of an incident response plan, even though both matter.

If your team is preparing for CISM or building this into a broader security governance track, you can start training with a study plan that treats the quantitative risk domain as its own discipline rather than a set of vocabulary words to memorize. The exam rewards candidates who can walk through the arithmetic and the assumptions behind it, because that's precisely what a regulator, an auditor, or a board member will ask for when the number matters.

The executive-accountability case, stated plainly

None of this is about making risk sound more sophisticated for its own sake. It's about closing the gap between what a security leader claims and what a board, regulator, or auditor can independently verify. A rating of "high" is an opinion. An annualized loss expectancy of $2.4 million, built from a documented asset value, threat frequency, and control effectiveness, is a claim someone else can check. Certification bodies like ISACA test for the second kind of output because that's the kind regulated industries now require as a matter of governance, not preference.

For an organization deciding who gets to own a risk register, that distinction is the entire procurement decision. A credential that verifies the quantitative method was tested, not just referenced, is the closest thing to independent assurance a hiring manager or compliance officer can get before the number ever reaches a boardroom.

Start training free at Forge University