Habr•October 7, 2026•🇷🇺Translated from Russian

Digitizing Cyber Risks: How to Communicate Cyber Threats to Boards in the Language of Money

Solar has published a detailed guide on digitizing cyber risks, explaining how to translate technical cyber threats into financial terms that resonate with boards of directors and investors.

Cyber Risks as Operational Risks

Cyber risks are defined as the potential for events that compromise the confidentiality, integrity, or availability of information assets. These risks fall under operational risk but feature unique traits: high speed of impact spread, scalability across infrastructure, and reliance on external suppliers and cloud platforms.

Threat actors include external groups such as hacktivists, ransomware operators, and nation-state actors, as well as internal actors ranging from negligent employees to privileged insiders.

Qualitative and Quantitative Assessment Approaches

Assessment methods combine qualitative expert judgment with quantitative modeling. Qualitative analysis uses workshops, Business Impact Analysis (BIA), BCP and DRP plans, and industry benchmarks to produce risk ratings and heat maps.

Quantitative methods rely on the FAIR taxonomy, statistical modeling, and Monte Carlo simulations when sufficient incident data exists. A hybrid approach fills data gaps with expert input while documenting assumptions for later refinement.

Four-Stage Digitization Process

  • Identification of critical assets, business processes, and attack surfaces.
  • Analysis of incidents, threats, vulnerabilities, and threat actor profiles to estimate probability.
  • Conversion of scenarios into financial figures covering downtime costs, investigation expenses, recovery efforts, regulatory fines, lost revenue, and reputational damage.
  • Continuous monitoring and recalculation of estimates as the threat landscape and business environment evolve.

Expected annual losses are calculated using the formula ALE = ARO × SLE, where ALE represents annualized loss expectancy, ARO is the annualized rate of occurrence, and SLE is single loss expectancy.

Business Value and Integration

The quantified outputs enable organizations to calculate ROSI (Return on Security Investment) and compare protective measures against budget constraints. They also allow cyber risks to be incorporated into enterprise risk management (ERM) alongside other operational risks.

Regulatory requirements and the growing financial impact of incidents on revenue, profit, and business continuity make this financial translation increasingly necessary for strategic decision-making.

Related articles

Habr•Policy & Regulation

Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions

A Russian security researcher developed an open-source tool to scan websites for dependencies on foreign services that could be cut off abruptly. The scan of 50 major Russian sites including banks, retailers, telecoms, airlines, delivery services, online schools and government portals revealed that servers have largely been migrated domestically. However, critical components such as SSL certificates, analytics platforms and fonts remain tied to overseas providers. 43 out of 50 sites still use foreign SSL certificates, primarily from Belgian GlobalSign and American Let's Encrypt, while only four rely on the Russian NUC certificate from the Ministry of Digital Development. The study also highlights legal obligations under Roskomnadzor rules effective since March 2023 requiring prior notification for cross-border personal data transfers. Many sites continue using Google Analytics, Google Fonts and reCAPTCHA without realizing the compliance and resilience risks. The tool assigns letter grades from A to F based on the number of foreign dependencies detected.

AntiMalware•Policy & Regulation

Russian Interior Ministry Accuses Telegram of Ignoring Drug Trafficking Requests

The Russian Ministry of Internal Affairs has publicly stated that Telegram completely ignores requests from law enforcement agencies aimed at combating illegal drug trafficking. According to the ministry, the messenger has become one of the main platforms, alongside darknet markets, for involving teenagers in narcotics-related crimes. Acting head of the Main Directorate for Drug Trafficking Control Kirill Smurov highlighted that Telegram administration does not respond to official inquiries and refuses to share necessary information. In contrast, Yandex promptly removes prohibited content either independently or upon the first police request. Since 2022, approximately 153,000 crimes have been committed using Telegram, while Roskomnadzor has issued more than 150,000 content removal demands that received no response. Founder Pavel Durov, who is included in the Rosfinmonitoring list of terrorists and extremists, has not engaged with Russian authorities on these matters.

AntiMalware•Policy & Regulation

UK Regulator Ofcom Investigates Meta Over Instagram Instants Compliance With Online Safety Act

Britain's communications regulator Ofcom has opened an investigation into Meta to determine whether the company properly assessed risks before launching the Instagram Instants feature. The probe focuses on compliance with the Online Safety Act, specifically the potential for illegal content distribution and harms to minors. Instants, introduced in May 2026, allows users to exchange images that disappear after viewing. Under UK rules, platforms must update risk assessments before rolling out significant changes. Ofcom will first gather evidence and, if violations are found, issue a preliminary decision allowing Meta to respond. Penalties for non-compliance can reach 18 million pounds or 10 percent of global turnover, whichever is higher. Meta maintains it conducted risk analysis and implemented safeguards such as forwarding restrictions and teen account protections before launch.

AntiMalware•Policy & Regulation

Russia Plans Additional Security Checks for Gosuslugi Portal Access

Prime Minister Mikhail Mishustin has directed the Ministry of Digital Development to develop extra authentication measures for the Gosuslugi portal used by 120 million citizens. The new controls would apply both to initial logins and to account recovery procedures. Details on the exact checks and implementation timeline remain unspecified as the ministry must first propose a concrete mechanism. In parallel, officials are preparing a third package of anti-fraud measures that includes a unified consent platform inside Gosuslugi for managing personal data processing permissions. The platform would let users view which organizations access their data, revoke prior consents, and report violations. Russian police have separately warned that fraudsters are already exploiting the topic of account protection by sending messages that threaten blocking or data leaks and urge victims to call provided numbers.