From Heatmaps to Histograms: A Practical Guide to Cyber Risk Quantification
商品資訊
ISBN13:9798868822995
出版社:Apress
作者:Tony Martin-Vegue
出版日:2026/04/03
裝訂:平裝
商品簡介
Cyber risk quantification (CRQ) is the practice of measuring cybersecurity risk using numbers --not colors or guesswork. Instead of labeling risks "high," "medium," or "low," CRQ uses probabilities, ranges, and impact estimates to help organizations make better, data-informed decisions about risk.
In a world where ransomware gangs operate like small businesses, every core function of an organization is digital, and Boards and regulators are demanding meaningful, defensible risk metrics, CRQ has never been more relevant than now. And thanks to AI, it's about to scale fast.
At the same time, CRQ is often misunderstood as expensive, technical, or just "voodoo math." People assume you need a stats degree, six-figure software, or a room full of analysts. This book is here to prove otherwise.
From Heatmaps to Histograms is a hands-on, plain-English guide written by a seasoned practitioner who's built CRQ programs at top global companies. It's packed with step-by-step instructions, practical tips, templates, shortcuts, AI prompts, and plenty of myth-busting to take you from CRQ skeptic to CRQ champion--even if you've never cracked open a statistics book.
All techniques in this book can be performed in Excel or Google Sheets--no coding required. But for readers who want to go further, you'll find dozens of GenAI prompts that help you generate risk scenarios, clean messy data, or even "vibe-code" your way through a Monte Carlo simulation in Python or R. You'll also get guidance on when to not use AI, how to spot hallucinations, and how to integrate it responsibly into your risk practice.
CRQ is no longer optional. This is your roadmap for making it work--cheaply, ethically, and effectively.
What You Will Learn:
- A beginner-friendly introduction to the statistical foundations of CRQ, including Monte Carlo simulations, credible intervals, Bayesian reasoning, and simple methods for summarizing uncertainty--without requiring a math or coding background.
- How to gather, vet, and work with data--even when it's scarce, messy, or missing.
- How to perform full end-to-end quantitative risk assessments using only Excel or Google Sheets.
- How to harness the power of generative AI to supercharge risk analysis workflows.
- How to apply CRQ and GenAI responsibly and ethically, with clear guidance on common pitfalls, misuse scenarios, and how to ensure transparency, fairness, and trustworthiness in your analysis and reporting.
Who This Book is for:
Beginner/Intermediate in the cyber/technology risk management field
主題書展
更多書展購物須知
外文書商品之書封,為出版社提供之樣本。實際出貨商品,以出版社所提供之現有版本為主。部份書籍,因出版社供應狀況特殊,匯率將依實際狀況做調整。
無庫存之商品,在您完成訂單程序之後,將以空運的方式為你下單調貨。為了縮短等待的時間,建議您將外文書與其他商品分開下單,以獲得最快的取貨速度,平均調貨時間為1~2個月。
為了保護您的權益,「三民網路書店」提供會員七日商品鑑賞期(收到商品為起始日)。
若要辦理退貨,請在商品鑑賞期內寄回,且商品必須是全新狀態與完整包裝(商品、附件、發票、隨貨贈品等)否則恕不接受退貨。

