Risk Quantification
Noun · Security & Infosec
Definitions
The practice of expressing security risk in measurable terms such as expected loss, financial ranges, or modeled probabilities rather than only qualitative labels. Risk quantification can improve decision-making, but it depends on assumptions and data that must be stated honestly.
In plain English: Putting numbers on security risk to help compare and decide.
Example: "The CISO used risk quantification to compare the expected annual loss from delayed MFA rollout against the implementation cost."