September 10, 2026
How To Measure and Quantify Risk in a Shifting Threat Landscape
While the value of a strong security posture might seem obvious, SecOps teams still struggle to communicate a return on investment to executive leadership.
In some ways, risk and security operations have slowly become conjoined, and CDW is observing this evolution among many of our customers. That's partly because they view the operationalization of risk reduction as being tied to the ability of security operations to respond to risk signals.
As a consequence, continuous threat exposure management (CTEM) is really where the two meet. Most organizations can measure risk in some way — and part of that is simply the detection of exposures — but we also must assess our ability to remediate against those exposures and then take action against them.
If you're just measuring activity and you're not measuring risk, you cannot effectively prioritize the way that you take action to try to remediate issues. You might see some interesting numbers, such as how many vulnerabilities you’ve patched, but you have no idea if that really impacts the business in a meaningful way. To bridge that knowledge gap, SecOps is becoming smarter, and risk management is getting much more focused on the business.
Why Compliance Keeps Winning Over Risk
CDW recently published the results of a survey we conducted. In it, 68% of respondents said they allocate resources based on risk likelihood and impact, but 71% cited compliance as their top driver. Those percentages are pretty close to one another, and I think there's a reason for that: Sometimes compliance ends up being a proxy for a risk-based analysis.
Most organizations will say they’re risk-based. But when you look closely, compliance is what gets inspected. It's what gets audited, and it's what gets funded in organizations. But true risk management requires a lot of judgment. You need business context, and you need to set priorities — decisions that can be difficult and require many stakeholders.
When it comes to risk and compliance, there are a variety of stakeholder groups in play. And what's meaningful from a risk perspective might be very different for a SecOps professional, the CEO, the CFO or the board of directors. When you're looking at risk, you have to consider what's important to those stakeholder communities, and you have to frame it that way. And the more security professionals understand those stakeholders’ points of view, the better they will be when presenting information to those stakeholders.
What Mature Organizations Do Differently When Measuring Risk
One statistic from the survey demonstrated a significant difference in the way organizations are measuring risk. The results revealed that 50% of respondents are using threat intelligence–driven assessments to quantify risk, while 39% are mapping risk to business impact.
That's a pretty big gap, and the reason I think you're seeing it is that most organizations today are still measuring either vulnerabilities or exposure. That's a baseline measurement that's been in play for a long time, but the more organizations begin to mature, the more they combine threat intelligence with the criticality of assets, meaning, “What is the minimum viable set of assets that we need to keep the business running? Is there any exploitable attack path associated with the threats that have been identified to those critical assets that keep the business functioning?” Suddenly, exploitability becomes very important.
Ultimately, you're using business impact to prioritize actions and continuously validate whether the controls in place are actually reducing risk. The approach shifts from simply identifying and measuring vulnerabilities to discerning which exposures could materially impact the business. When you're aligning SecOps, you have to ask whether you’re doing things that help reduce the material impact associated with a set of risks. If you're doing that, you're maturing as an organization.
How To Measure ROI Your C-Suite Will Actually Care About
The idea of viewing security as a means of measuring return on investment relative to risk is an important topic right now. Security organizations have traditionally used vulnerability management metrics like mean time to detect (MTTD) and mean time to respond (MTTR) because, honestly, they're relatively simple to identify. In both cases, lower is better. Lower amounts of time — that's relatively easy to determine. And it's something that folks can show as a proxy to ROI.
But while MTTD and MTTR are useful operational metrics, they really don't tell different stakeholder communities whether risk is going down. Just because you're doing something faster than you were is not a direct relationship to whether the overall risk to the business is improving.
The metrics that tend to matter most connect the activity that the security groups are performing with business outcomes. Think about things like reduction in critical exposure — those assets that represent the minimum viability, the idea that those assets are important to the function of the business. If we can measure reduction in critical exposures and show that we've closed attack paths to those high-value assets, we can show financial risk reduction to stakeholders who care about financial risk.
In other words, SecOps teams should think less about how fast the team runs and more about measuring whether the organization is safer. And that shift in mindset aligns the security team to the rest of the business, which makes it much easier to demonstrate where you're really getting ROI.
The C-suite cares about dollars. They care about compliance. And they care about operations. If we can show an improvement in our operational resiliency, if we can show real dollar impacts that are defensible and not just a guess, and if we can show that our compliance posture is improving, the C-suite will respond to that.
Why Is It So Difficult To Quantify Risk?
Many organizations still struggle with putting a value on cyber risk. We asked in the survey about the biggest barrier organizations are facing in doing so, and 46% said complex IT and cloud environments were that major barrier, suggesting that SecOps teams might need to adapt their risk frameworks to keep pace with all the infrastructure changes that are increasing complexity.
You have this sprawl of technology that's meant to protect the assets, and it's hard to figure out how that maps back to quantifying risk. But things have changed in the past four or five years. CDW customers now say they’re able to judge the maturity of their controls framework to see the level of loss across many different areas. And that is not only much easier than the traditional method but also provides that level of defensibility that business executives are going to require. You can say, "Listen, we validated via third parties that these are the real data out there about risk quantification."
We know that complexity isn't going away. So, risk frameworks have to become more dynamic by nature. Organizations need continuous visibility into assets, identities and cloud-based resources. It becomes even more challenging for those organizations that might have a lot of sub-entities operating on their own. They need to have visibility into third parties — and attack paths — instead of relying on point-in-time assessments. The goal has really shifted. It's not perfect inventory accuracy, per se. It's maintaining enough contextual awareness to make good risk decisions at speed.
As SecOps teams adapt, my advice is to enrich your operational security telemetry with business context so you can deliver better risk-based outcomes. That new perspective will put you in a position to make good risk decisions that protect what actually matters.
Learn how CDW helps organizations assess and bolster their cybersecurity posture.
Buck Bell
CDW Expert