About the Book

Coming Early 2026 — Get Your Copy

Cyber risk quantification (CRQ) is the practice of measuring cybersecurity risk with probabilities, ranges, and financial impact — not colors or guesswork. For too long, risk programs have relied on “high/medium/low” charts that fail to inform executives.

This book is a hands-on, plain-English guide that shows professionals how to build CRQ programs from scratch, run practical assessments in Excel, and use AI responsibly to accelerate analysis. Packed with case studies, templates, and step-by-step instructions, it transforms CRQ from intimidating theory into a tool any risk leader can apply.

ISBN: 979-8868822995

PREORDER


Praise for the Book

From Heatmaps to Histograms is a significant contribution to our profession and would be required reading for anyone in my organization if I were still a CISO. Brilliantly written for those with little or no background in quantitative risk measurement, it will also be valuable to those with years of experience. This is further evidence that Tony is one of the leading contributors to the future of our profession.
— Jack Jones, Creator of FAIR
Tony makes a strong case for replacing popular but flawed risk assessment methods and goes further by providing practical approaches for implementing better ones. Through clear examples and step-by-step guidance, he makes even quantitative concepts accessible. I highly recommend this book.
— Douglas Hubbard, Author and Measurement Expert
I finally have a clear answer to the question I’m asked most often by those just starting out: Where do I begin with measuring cyber risk? This book is the definitive starting point for anyone serious about becoming a cybersecurity risk modeler.
— Richard Seiersen, Author and Chief Risk Technology Officer, Qualys
I’ve been measuring cyber risk for over twenty years, and while better data still matters, practicality has become the real barrier to adoption. Conversations around cyber risk quantification are dominated by “Yeah, but how?” This book answers that question with concrete examples and practical guidance, striking the right balance between what you need to know and what you need to do.
— Wade Baker, Partner, Cyentia Institute
If you are stuck in a world of color-coded risks that promote confidence and certainty over clarity, this book offers a way forward. It provides a practical path away from risk matrices and heat maps and toward a world where uncertainty is acknowledged, ranges reveal tail risk, and Monte Carlo simulations replace calculations of convenience. If you’re wondering where to start your journey into quantified risk, this is it.
— Jay Jacobs, Co-founder and Chief Data Scientist, Empirical Security
This is the book I’ve been waiting for. It’s a true A-to-Z guide to cybersecurity risk forecasting written for both newcomers and seasoned professionals. Tony’s explanations are clear, his timing is impeccable, and his practical exercises make first-principles thinking accessible to everyone.
— Rick Howard, Cybersecurity Educator and Author
Tony’s book empowers both new and experienced risk professionals to communicate more effectively with boards and executives. By integrating models, experience, and clear, actionable steps, it provides practical tools for applying risk measurement in real organizations and finally moving beyond stoplight charts.
— Lisa R. Young, Cyber Risk Expert
Tony’s book empowers both new and experienced cyber risk professionals to level up their communication skills to the board and executives in a way no one else has done. By seamlessly integrating models, drawing upon years of invaluable experience, and presenting practical steps in actionable formats, this book equips readers with the tools to employ risk measurement techniques and successfully manage cyber risk for their organizations. We can finally eliminate the reliance on the stoplight technique, as his book provides a comprehensive solution for effective cyber risk management!
— Patti Degnan, Operating Partner, Andreessen Horowitz
You don’t just read this book; you do it. Tony has created a genuinely fun risk companion guide, with storytelling, step-by-step workflows, and templates that will have you running your first defensible risk scenario before you finish the last chapter. It belongs on every risk team’s onboarding list.
— Adrienne Allen, Security, Risk and Compliance Leader

Practical Skills You Can Use Right Away

By the end of From Heatmaps to Histograms, you’ll know how to turn risk analysis into real decision support — using proven methods, data, and tools.

Simple illustration of a calculator with addition, subtraction, multiplication, and division symbols on a blue background.

Run Simulations Without Complex Math

Use simple Monte Carlo techniques and everyday tools like Excel to model uncertainty and financial impact.

Line graph with an upward trend and an arrow at the end.

Build a Clear Mental Model for CRQ

Understand how cyber risk quantification (CRQ) works and why it’s essential for better decision-making.

Icon illustrating communication or connection between two people, with a checkmark indicating confirmation or success.

Communicate Risk with Executive Clarity

Turn your findings into stories and visuals that help leaders make confident, data-driven decisions.

Tools That Turn Insight Into Action

Tools and Downloads

Access practical worksheets and templates from From Heatmaps to Histograms to put cyber risk quantification into action.

A person working on a MacBook Air laptop displaying Google Analytics data, with a white mug with blue stripes and two black markers on the table beside.