Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Informing and empowering: the role for risk data in cyber security decision making (Page 11)
Cyber resilience

Informing and empowering: the role for risk data in cyber security decision making

February 19, 20256 Mins Read
Data flows concept.

By Ivan Milenkovic

In February 2025, a new organization based in the UK called the Cyber Monitoring Centre (CMC) launched its operations. This organization is a not-for-profit that aims to provide independent data on cyber security issues and how serious they are for businesses. This has the potential to be highly valuable for IT security professionals – by introducing a standardised cyber event categorisation system, the CMC is addressing a critical gap around the lack of consistent, large-scale data to support cyber risk quantification (CRQ).

The lack of consistent independent data for risk management has held CISOs back and made it harder for them to consistently work with the rest of the business around risk. What the CMC offers should mean that security leaders will finally have access to reliable, aggregated information that can inform their risk assessments, threat modelling, and decision-making.

However, while getting an independent source of risk data is a step in the right direction, it is not a silver bullet that will solve all the problems that CISOs have around managing risk. To get this right, security leaders need to express how risk affects their own organizations; and do this in ways that other business leaders can understand.

Collaborating around risk data

To build up a picture of risk, outside data can provide some context. However, it is a snapshot of how an issue might affect the overall market. What might be a serious risk to one company could be insignificant to another, based on what systems are running and how well those internal processes around software updates or mitigations function in practice. For a company with automated patching and rapid software change management processes, a new zero-day will be a lot less risky than one where patching takes weeks and deployment is inconsistent.

Getting that understanding of how big risks apply to an individual organization is a challenge, particularly when the business leadership is not technical. To overcome this problem, security leaders have to collaborate with their peers within the business on the operational processes that exist around risk as a whole. This involves looking at financial and compliance requirements. In practice, it means getting on the same page as the CFO and the lead for compliance within the business.

At heart, cyber risk is not just an IT issue – it’s a business issue that requires quantifiable, evidence-based decision-making. At the same time, CFOs and compliance teams need that insight into how cyber issues might affect their decision making. Using data – and more particularly a mix of internal data and external validation – you can provide those peers with better information on what levels of risk really exist. This enables the group to take a more proactive approach to risk before threats hit, centralising risk response into an operational approach that works across departments.

Coordinating an operational response to risk

To make the above work effectively, a risk operations centre (ROC) acts as a central place for risk data and telemetry across the entire enterprise. ROCs need to integrate the insights that are available from external sources like the CMC with their own insights. This data can come from threat intelligence feeds and from tools like vulnerability management, providing insight into internal IT and cloud assets. Not only does this make it easier to look at organizational risk in a holistic way, it can take place in a proactive manner.

This combination of internal and external data can be used to manage and respond to risk in a way that reflects the organization’s own specific industry and compliance requirements, infrastructure security needs, risk appetite, and threat profile. This combination of externally sourced intelligence and internal risk framework data can support a comprehensive strategy around security that fits with the business and then turn that strategy into actions based on any new developments.

This is where collaboration around risk data is both essential and made easier through better CRQ processes. Getting a specific figure and risk level associated with particular issues makes it easier to make appropriate changes in practice, whether that is carrying out patching quickly or taking a key system offline to deploy a patch or mitigate the problem in the face of a clear and present threat. When people can work around the same value – the amount of money at stake – it is easier to get support for making those changes and to make them stick over time. This makes it operationally more efficient, as the business understands what is at stake.

For IT security teams, protecting the business against risk is a laudable goal. But it is very hard for these teams to express what ‘good’ or ‘great’ security actions look like to the rest of the business. Achieving optimum results means that a business can continue to deliver value to customers, or an organization can support citizens effectively, with zero or minimal disruption and within forecast thresholds. We need data from external and internal sources to reframe all those efforts around reducing risk; and the data has to be put into a framework specifically designed for organizational leaders. This needs to show how the business achieves direct value for itself from its security investments.

The launch of the CMC – and the data feed it can provide – will help bridge the gap between qualitative and quantitative risk management, making it easier to justify security investments with data-backed reasoning. However, success will depend on how well organizations use this information alongside their own internal risk frameworks. By getting this mix of internal and external data right and using it to support more effective communications, CISOs can make the right decisions and get the support they need. More importantly, those decisions will be positioned specifically around how they support the business to achieve its strategies and aims.

The author

Ivan Milenkovic is Vice President Risk Technology EMEA at Qualys a cloud security company. Ivan leads work with customers on their risk strategies across their operations. Prior to joining Qualys, Ivan held roles as a Global Cyber Consulting Head of Operations with Atos and Global CISO for WebHelp.

UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleKey risk trends impacting boardrooms and the c-suite in 2025 and beyond
Next Article DORA: the ESAs provide an update on the designation of critical ICT third-party service providers

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Five arrows converge to show the move towards enterprise resilience.

Enterprise resilience: moving from program to decision capability

April 30, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?