By Ivan Milenkovic
In February 2025, a new organization based in the UK called the Cyber Monitoring Centre (CMC) launched its operations. This organization is a not-for-profit that aims to provide independent data on cyber security issues and how serious they are for businesses. This has the potential to be highly valuable for IT security professionals – by introducing a standardised cyber event categorisation system, the CMC is addressing a critical gap around the lack of consistent, large-scale data to support cyber risk quantification (CRQ).
The lack of consistent independent data for risk management has held CISOs back and made it harder for them to consistently work with the rest of the business around risk. What the CMC offers should mean that security leaders will finally have access to reliable, aggregated information that can inform their risk assessments, threat modelling, and decision-making.
However, while getting an independent source of risk data is a step in the right direction, it is not a silver bullet that will solve all the problems that CISOs have around managing risk. To get this right, security leaders need to express how risk affects their own organizations; and do this in ways that other business leaders can understand.
Collaborating around risk data
To build up a picture of risk, outside data can provide some context. However, it is a snapshot of how an issue might affect the overall market. What might be a serious risk to one company could be insignificant to another, based on what systems are running and how well those internal processes around software updates or mitigations function in practice. For a company with automated patching and rapid software change management processes, a new zero-day will be a lot less risky than one where patching takes weeks and deployment is inconsistent.
Getting that understanding of how big risks apply to an individual organization is a challenge, particularly when the business leadership is not technical. To overcome this problem, security leaders have to collaborate with their peers within the business on the operational processes that exist around risk as a whole. This involves looking at financial and compliance requirements. In practice, it means getting on the same page as the CFO and the lead for compliance within the business.
At heart, cyber risk is not just an IT issue – it’s a business issue that requires quantifiable, evidence-based decision-making. At the same time, CFOs and compliance teams need that insight into how cyber issues might affect their decision making. Using data – and more particularly a mix of internal data and external validation – you can provide those peers with better information on what levels of risk really exist. This enables the group to take a more proactive approach to risk before threats hit, centralising risk response into an operational approach that works across departments.
Coordinating an operational response to risk
To make the above work effectively, a risk operations centre (ROC) acts as a central place for risk data and telemetry across the entire enterprise. ROCs need to integrate the insights that are available from external sources like the CMC with their own insights. This data can come from threat intelligence feeds and from tools like vulnerability management, providing insight into internal IT and cloud assets. Not only does this make it easier to look at organizational risk in a holistic way, it can take place in a proactive manner.
This combination of internal and external data can be used to manage and respond to risk in a way that reflects the organization’s own specific industry and compliance requirements, infrastructure security needs, risk appetite, and threat profile. This combination of externally sourced intelligence and internal risk framework data can support a comprehensive strategy around security that fits with the business and then turn that strategy into actions based on any new developments.
This is where collaboration around risk data is both essential and made easier through better CRQ processes. Getting a specific figure and risk level associated with particular issues makes it easier to make appropriate changes in practice, whether that is carrying out patching quickly or taking a key system offline to deploy a patch or mitigate the problem in the face of a clear and present threat. When people can work around the same value – the amount of money at stake – it is easier to get support for making those changes and to make them stick over time. This makes it operationally more efficient, as the business understands what is at stake.
For IT security teams, protecting the business against risk is a laudable goal. But it is very hard for these teams to express what ‘good’ or ‘great’ security actions look like to the rest of the business. Achieving optimum results means that a business can continue to deliver value to customers, or an organization can support citizens effectively, with zero or minimal disruption and within forecast thresholds. We need data from external and internal sources to reframe all those efforts around reducing risk; and the data has to be put into a framework specifically designed for organizational leaders. This needs to show how the business achieves direct value for itself from its security investments.
The launch of the CMC – and the data feed it can provide – will help bridge the gap between qualitative and quantitative risk management, making it easier to justify security investments with data-backed reasoning. However, success will depend on how well organizations use this information alongside their own internal risk frameworks. By getting this mix of internal and external data right and using it to support more effective communications, CISOs can make the right decisions and get the support they need. More importantly, those decisions will be positioned specifically around how they support the business to achieve its strategies and aims.
The author
Ivan Milenkovic is Vice President Risk Technology EMEA at Qualys a cloud security company. Ivan leads work with customers on their risk strategies across their operations. Prior to joining Qualys, Ivan held roles as a Global Cyber Consulting Head of Operations with Atos and Global CISO for WebHelp.






