risk | description |
---|---|
Cybersecurity Breach | Risk of a cybersecurity breach of the inventory system. |
Technology Outage | Risk of an inventory system outage. |
Loss of Customer | Risk of losing and existing customer or failure to acquire a new customer due to functional limitations of the inventory system. |
Risk Quantification Demo
Risk Quantification demonstration for my SIRAcon 2024 talk, “UnFAIR: Simplifying and Expanding Technology Risk Quantification.”
Note: the functions and report in the demo below have been migrated to a new project, quantrr, that supports both experienced R users with a package / RStudio installation, and novice users with a standalone installation. (I wanted to name it “qrisk”, but that’s already trademarked).
Questions/TODO
Environment Statement
The widget management system is over 30 years old and its architecture has not changed significantly since the original implementation. Over the years, the widget system has become an integral part of our services in managing widgets for our clients. In reviewing the system, three major risks were identified: First, the age of the technology prevents updating components of the system that no longer meet contemporary cybersecurity standards, which increases the risk of a breach. Second, the system is less reliable and experiences frequent outages, typically about 2 major outages per year, which results in lost revenue, contractual penalties, and overtime pay to recover from the incident. Third, limitations of the widget system have started to affect sales - we have recently lost a customer due to the functional obsolescence of the widget system, and expect to both lose more existing and prospective customers in the future due to increased competition in the widget management market.
Import
Import and validate data from Excel. The data in demo.xlsx
is based on the examples developed here. The data was collected from 3 Technology SMEs, 3 Business SMEs, and one SME with experience in both. Experts were calibrated, informed by historical and industry data, and only gave estimates for areas in which they were confident in answering.
Risks
Risk descriptions:
Forecast
Forecast risk using Monte Carlo simulation. The average events and losses for each risk are summarized below:
risk | avg_events | avg_losses |
---|---|---|
Cybersecurity Breach | 0.25975 | $7,417,978 |
Loss of Customer | 1.99956 | $10,341,045 |
Technology Outage | 2.01369 | $98,250 |
Losses
Losses by risk separately and in aggregate:
Loss Exceedance Curves
Plot loss exceedance curves for all risks and combined risk.
By Risk
Plot loss exceedance curves for each risk:
Interactive plot: