Don't Predict Incidents. Estimate Consequences.
- Neil Hare-Brown

- 5 days ago
- 6 min read
Updated: 16 hours ago

Cybersecurity spends a remarkable amount of time trying to predict what attackers will do.
Driving damaging incidents such as:
Ransomware.
Business email compromise.
Credential theft.
Insider threat.
Supply-chain compromise.
Zero-day exploitation.
Extortion.
Fraud.
The list grows every year. And, inevitably, so can the complexity of the models we build around it.
To be honest, I think many cybersecurity professionals are now a bit jaded of reading largely unsubstantiated noise about cyberattack predictions - I know I am. Most of us work hard to pick out the needles in the haystack so that we can determine the real threat level and act accordingly.
But after responding first-hand to more than 1,000 cyber incidents, I have become increasingly convinced that this is often the wrong place to start. Although the actual cadence is nowhere near what the cybersecurity vendor-space would have us believe, attack techniques do change. Threat actor groups also. Malware changes - especially now with AI-assisted development and deployment.
However, the ways organisations actually lose money are much more stable.
That suggests a different approach. One that is anchored in a more useful and practical methodology.
Instead of trying to predict every incident, objectively estimate the consequences that matter.
The Problem With Predicting Attack Types
Threat modelling has an important place in cybersecurity.
Understanding how attackers operate helps us design controls, prioritise vulnerabilities and improve detection. However, it becomes much less useful when the objective is an executive investment decision.
A Board does not ultimately suffer a "ransomware loss". It suffers:
lost productivity,
response costs,
replacement costs,
legal and regulatory liabilities,
damage to competitive advantage,
reputational harm.
Those are the financial consequences. Remarkably different cyber incidents can produce very similar financial outcomes. A sophisticated ransomware attack and a relatively simple credential compromise may use completely different attack paths, yet both can ultimately result in data exposure, operational disruption, legal costs and customer loss.
From the perspective of the balance sheet, the attacker’s technique is often less important than the business outcome.
Most Serious Incidents Reduce to Two Fundamental Types
I have deliberately become suspicious of overly elaborate incident taxonomies. They can be useful operationally, but they are often unnecessary when trying to understand financial risk.
For most critical digital assets, two scenarios capture a very substantial proportion of the meaningful financial exposure:
Outage, where the asset, service or function is unavailable and Data Breach, where information associated with the asset is accessed, disclosed, copied or otherwise compromised.
While these scenarios are deliberately simple it does not mean cyber incidents themselves are always simple. Modern ransomware, for example, frequently combines both.
The attacker encrypts systems, causing an outage, while also stealing data and threatening its publication. One incident yet with two business consequences.
Similarly, business email compromise is fundamentally a breach of information and access, even where fraud becomes one of the consequences.
The purpose of simplification is not to deny complexity. It is to prevent complexity from obscuring the decision.
What About Extortion and Fraud?
Extortion clearly matters. So does fraud.
There are individual incidents where either can create very large losses but the relative importance of these components has changed. For example, increasingly, ransomware victims do not pay. Where extortion payments do occur, they can still be material, but the broader costs of disruption, recovery, investigation, legal advice, notifications and reputational harm can dwarf the payment itself. The 2026 Chubb Cyber Claims Report, highlights that, while cyber incident claims have fallen in number over the last 5 years, the losses have, on average, grown substantially.
Fraud presents a similar issue. Large frauds certainly occur, but many losses can be frozen or recovered, and in a major breach the surrounding business interruption and legal consequences may be more financially significant than the initial fraudulent transaction.
This is why I favour starting with the dominant consequence scenarios rather than trying to model every possible form of criminal behaviour individually.
If an additional factor is genuinely material, include it. But it should have to earn its place.
Ask the People Who Actually Know
This approach also solves another problem.
If we ask business leaders to estimate the probability of a particular ransomware variant successfully compromising a specific application next year, we are asking them a question they are poorly equipped to answer. If instead we ask, "What happens if this application is unavailable for five days?", the conversation changes immediately.
Operations can discuss lost production. Finance can estimate lost productivity and additional expenditure. Technology can estimate restoration and replacement costs. Legal can assess contractual and regulatory consequences. Communications can discuss reputational impact. Commercial leaders can consider competitive consequences.
These people understand the business. That expertise is what we need.
Similarly, ask, "What happens if the information held by this critical asset is breached?"
Again, the management team can reason about the consequences.
We have moved from asking people to speculate about attackers to asking them about the business they already understand. That is a much better use of expertise and it leverages what an organisation already has.
Objectivity Does Not Require Certainty
There is a trap here. Once we move into financial quantification, people often believe they need to provide a single precise answer. They don't.
For example, nobody can tell us that the next serious outage will cost exactly £4,237,615.
That level of precision would be fiction. But an informed management team may be able to say:
losses below £2 million would be unusually low;
losses between £3 million and £5 million are quite plausible;
losses above £8 million would require several adverse circumstances to coincide.
Once collaborative discussion, with suitably expert participants, objectively challenges the ranges the results become truly useful information. We do not need certainty. We need plausible bounds.
With reasonable ranges, uncertainty itself can be modelled. The objective is not to pretend we know exactly what will happen. It is to understand the financial landscape well enough to make a better, informed decision. Absolutely, we may rely on external sources but ultimately, no one knows better what losses are likely to occur should an incident be experienced. We only need to ensure that estimations are determined objectively.
Consequences Are More Stable Than Threats
This is one of the reasons I think consequence-based analysis is so useful.
Cybersecurity changes extraordinarily quickly. The terminology we use today may look dated in five years.
New attack techniques will emerge. New vulnerabilities will be discovered. New technologies will create new opportunities for attackers.
But businesses will still lose money in recognisable ways. People will still be unable to work. Experts will need to respond. Technology may need replacing. Legal liabilities will arise. Competitive positions may be weakened. Reputations may be damaged. The attacks will evolve. However, the economics are much more persistent.
From Prediction to Bounded Futures
There is another engineering idea behind this approach.
We cannot know precisely which cyber incident will occur next. But we can estimate a useful range of plausible outcomes.
Effective controls then help constrain that range. They do not give us certainty but they do help bound the future within practical limits. I believe that distinction really matters.
A well-designed control environment is not one in which nothing bad can happen. Of course, such an environment does not exist. It is one in which the range of plausible adverse outcomes has been constrained to a level that the entity can manage and that gives us something financially meaningful to work with.
Focus on What You Can Decide
Cybersecurity will always require threat intelligence.
It will always require technical analysis. However, those activities should serve the decision rather than become the decision.
When a Board is considering investment, I believe the more useful questions are often much simpler:
What critical asset are we concerned about?
What happens if it becomes unavailable?
What happens if its information is breached?
What are the plausible financial consequences?
What can we do to reduce, transfer, accept or avoid those consequences?
Those are questions that connect cybersecurity directly to business value. Once we can describe the potential consequences in financial terms, we are finally in a position to start making informed investment decisions.
In the next paper, I want to look at the information we use to get there and why every question, field and metric should have to justify its contribution to the decision.
Thought for the week
"Attack techniques change. The ways organisations lose money are remarkably persistent."

