Most security teams can tell a board how many vulnerabilities they closed last quarter, but few can say what that work was worth in money. Ivan Milenkovic, VP Risk Technology EMEA at Qualys, argues that first-time economic models go wrong by starting with thousands of findings and trying to work upward to money. He advises reversing the order: name the handful of scenarios that would genuinely hurt, put a loss range on each, then work down to the assets and exposures that drive those losses.

Such a model should adjudicate on value at risk. A severe flaw on an unused test server adds almost nothing, while a moderate flaw on an internet-facing revenue system can add a lot, especially if attackers are already exploiting it. Milenkovic recalls a business unit that was ranked worst because it spent hours patching disconnected servers while scoring them the same as the payment gateway. With AI widening discovery—one frontier model surfaced more than 6,000 candidate high- or critical-severity flaws across over 1,000 open-source projects—the response is to say which issues matter and sign off on the ones judged acceptable to leave.

On proving the worth of incidents that never happened, he points to CFOs, who already own insurance and capital reserves and plan for bad days. Actuaries behind a broker already model cyber risk, but they know less about residual risk than the security team does. The job is to buy down plausible future loss until the chance of breaching financial backstops sits inside the limits the business has set. Nothing happened will never stand as evidence on its own, but an economic model makes avoided loss legible to finance. With one source, there are no differing views to reconcile.