5 Lessons from Tony Martin-Vegue on Making Cyber Risk Quantification (CRQ) Work in the Real World

Cyber Risk

5 Lessons from Tony Martin Vegue

When your guest speaker has a sticky note on his laptop that reads “Don’t melt the reader’s brain,” you know you’re in for a refreshingly human take on a technical topic.

That’s exactly what happened during our recent “From Heatmaps to Histograms” webinar, where Tony Martin-Vegue — cyber risk quantification (CRQ) expert, author, and former Netflix risk leader — joined Marie Giesbert, CMO at Citalid, to unpack what CRQ really looks like in the real world.

In just 45 minutes, Tony delivered a masterclass in making cyber risk quantification practical, approachable, and impactful. He shared how organizations can move beyond red–yellow–green heatmaps and start making business-driven decisions that resonate with executives.

Whether you’re a CISO, risk manager, or simply curious about how to make cyber risk more actionable, here are five key lessons from Tony that will help you rethink your approach.

1. CRQ Isn’t About Math — It’s About Better Decisions

One of the most common misconceptions about CRQ is that it’s all about complex math, simulations, and statistical modeling. Tony debunks that myth right away.

“I don’t make you come to me. I come to you.”

Instead of starting with Monte Carlo simulations or probability distributions, Tony recommends starting with what stakeholders actually care about: making better, faster, and more confident decisions.

CRQ is not about overwhelming people with numbers — it’s about enabling smarter choices. When framed this way, quantification becomes a tool for empowerment, not confusion.

2. It’s Time for CISOs to Upgrade the Conversation

CISOs are often stuck in a reactive role, reporting on technical metrics that don’t resonate with the board. Tony argues it’s time to change that.

“Let’s stop talking about colors — and start talking about strategy and return on investment.”

The traditional approach — “we turned three reds into three yellows” — no longer satisfies executives. Boards want to understand how security investments translate into reduced risk exposure, ROI, and strategic trade-offs.

CRQ allows CISOs to speak the language of business. By quantifying risk in financial terms, security leaders can position themselves as strategic partners, not just technical guardians.

3. Take Baby Steps: Progress Beats Perfection

Transitioning from qualitative to quantitative risk analysis doesn’t have to be a dramatic overhaul. Tony advocates for a “baby steps” approach that builds confidence gradually.

“You don’t need to rip off the band-aid — baby steps are fine.”

Start by using your existing heat maps as visualization tools for quantified data. Use Excel to run your first few dozen risk assessments — it’s more than capable of handling thousands of Monte Carlo simulations.

Learn how Citalid turns cyber risk into a language executives and boards actually use

EXPLORE CYBER GOVERNANCE

Once your organization sees the value, you can scale with more robust tools and platforms. The key is to show results early and build momentum.

4. Risk Is Psychological — Not Just Numerical

One of the most insightful moments in the webinar came when Tony addressed the emotional reactions people have to risk figures.

“Risk is more than numbers — it’s psychological. Meet people where they are.”

When someone says, “That number feels too high,” it’s not necessarily a challenge to your methodology — it’s a psychological response. Tony encourages risk analysts to explore the context behind these reactions, ask questions, and understand expectations.

This human-centered approach helps build trust and makes CRQ more relatable across the organization.

5. CRQ Is Both a Compliance Win and a Strategic Advantage

Yes, CRQ can help you check the compliance box. But that’s just the beginning.

“Let’s make the auditors happy — and have better conversations about ROI while we’re at it.”

By integrating the FAIR framework into existing standards like ISO or NIST, organizations can satisfy auditors while unlocking strategic insights. CRQ enables conversations about insurance coverage, capital reserves, and investment prioritization — topics that go far beyond basic compliance.

It’s a win-win: regulatory alignment and smarter business decisions.

Final Thought: CRQ Is About Continuous Improvement

Whether you’re launching your first CRQ initiative or scaling an existing program, Tony’s advice boils down to one powerful principle:

“CRQ helps you make slightly better decisions than you did yesterday. That’s progress.”

And that’s exactly the mindset driving Citalid’s mission. With Citalid Core, organizations go beyond static risk reporting. They gain a dynamic, decision-support platform that empowers CISOs, risk managers, and business leaders to:

  • Prioritize mitigation actions based on financial impact
  • Justify cybersecurity budgets with ROI-backed arguments
  • Align cyber strategy with business objectives
  • Inform cyber insurance negotiations with quantified exposure

CRQ is not the destination—it’s the compass.
It’s not about producing perfect numbers. It’s about enabling better decisions, faster, and with greater confidence.

Because in the end, cyber risk quantification isn’t just about risk.
It’s about business intelligence.

More content

Related content