RootCaws · Risk lab

Risk Benchmarks

Starting ranges for cyber loss estimates, where every number states where it came from and what it will not support. Each shard gives an annual event frequency and a per-event loss, as three-point estimates you can drop straight into a Monte Carlo.

The point is not that these numbers are right. It is that a range carrying six citations and a range someone typed from memory should not look equally authoritative — so here the sources travel with the numbers.

When and where to use it

Use it when

  • You need a starting frequency and loss range and refuse to type one from memory.
  • You are reviewing someone else's quantification and want to see whether the inputs cite anything.
  • You are about to load a shard into another lab tool, or teaching why “industry average” is not a number.

Do not use it when

  • You are about to call these benchmarks. Most are governed starters. Nothing in the corpus is high confidence.
  • You need a portfolio total across shards. Four currencies, no FX table — do not add them.
  • A bridged frequency is going into a board deck without the country it came from and the limitation that says so.

How to use it

  1. Filter. Twelve shards across countries and threat types. Narrow to the population nearest the thing you are modelling.
  2. Read the badges. Every shard carries a maturity status, a provenance tier, and how many of its parameters sit at each confidence level. Most are governed starters rather than reviewed benchmarks.
  3. Open the sources. Expand a shard and each of its six parameters names the study, the publication date, the confidence, and the limitation on its use — including which frequencies are bridged from another country because no local rate is published.

Take it into your organisation

  1. Build your own shard file: population, threat, six parameters, a named source, a date, a confidence, a limitation. A parameter without those fields is not allowed into a model that will be shown.
  2. When you borrow a rate from another country, the limitation sits on the same slide as the number.
  3. Revisit shards when the source is republished. A 2019 survey is a 2019 survey.
  4. Take the discipline, not the figures. Every input traces to a publication or to a named estimator. None of these figures are yours until you have read the limitation and decided it still applies.

The notes below are the honest limits. If a number from here reaches a board deck, its limitation belongs on the same slide.

The shards

Filter to the population nearest the thing you are modelling, then open a shard's sources before quoting any of its numbers.

Loading…

Starters, not benchmarks

Read each shard's status. Most are governed starters, meaning the evidence is real but the shard has not cleared human benchmark review.

Some frequencies are borrowed

Where no local per-firm rate is published, a shard may bridge from another country that has one — the US data-breach frequency comes from a UK survey. Each such parameter says so in its own limitation.

Currencies differ, and there is no FX table

Four currencies across the shards. Do not add them together without converting first, and state the rate and date when you do.

Carry the caveats forward

If a number from here reaches a board deck, its limitation belongs on the same slide.