Best cyber risk/security product: RiskLens
The US software company's product enables reporting and decision-making on cyber security
OpRisk Awards 2016
How can you put a figure on cyber risk? Too many businesses struggle to translate what, on the face of it, is an IT problem into a measure of financial risk that can be understood by non-technical executives.
Some 15 years ago, the co-founder of RiskLens, Jack Jones, was asked by his then-employer, US-based Nationwide Insurance, to quantify the cyber risk the company faced, and how much this risk would be reduced as a result of the multi-million dollar investment in cyber security technology that he was advocating.
He realised that his answers – "lots" and "some" – were woefully inadequate. "He thought, these are reasonable questions; we should be able to quantify cyber risk exposure," says Nick Sanna, chief executive of RiskLens, the US software company that grew out of that awkward board meeting.
It seems obvious that people should be using the same measuring stick... but previously, people weren't speaking the same language
Nick Sanna, RiskLens
The first step was to develop a model that could be applied consistently to cyber risk. "It seems obvious that people should be using the same measuring stick... but previously, people weren't speaking the same language," Sanna says.
The solution was found in factor analysis of information risk (Fair), an international standard value-at-risk model for cyber security and operational risk, which allows for the understanding, analysis and quantification of information risk in financial terms.
The second step was to encourage business heads to put dollar numbers on the estimated impacts of cyber security breaches – for example, the cost of business interruption, reputational damage, or the legal costs associated with theft of customer information.
"The number one objection was ‘I don't have enough data to give you'," says Sanna. The simple answer was to ask for ranges, which are then used to provide single or aggregate loss exposure reports.
To arrive at an enterprise-wide loss exposure, the RiskLens platform combines information on a company's current state of cyber security with these figures for the estimated impact of a cyber security breach. "What the system allows is for business people to get involved in the cyber security process," says Sanna.
Software as a service
While Jones initially built a consulting business applying the Fair VAR model, RiskLens subsequently developed a software-as-a-service offering, launched at the end of 2014. Clients use the system for regular reporting and decision-making regarding cyber security spend. It can also be used to calculate the amount of cyber insurance cover it might be necessary to purchase – and even by insurers, in calculating how to price that cover.
One insurance client says the product "has been key for moving from subjective assessments of risk to a data-driven approach to the underwriting of cyber insurance".
RiskLens is now looking beyond cyber risk. "We've been getting a lot of enquiries to expand our solution into operational risk," says Sanna, such as risks around physical security, weather impacts – and even opening a new subsidiary. "There's no standard model to quantify operational risk – the Fair model is agnostic and is very well applicable to operational risk exposures."
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Awards
Collateral management and optimisation product of the year: LSEG Post Trade
LSEG Post Trade wins Collateral management and optimisation product of the year for interconnected services that help mitigate counterparty risk and optimise capital usage
Clearing house of the year: LCH
Risk Awards 2025: LCH outshines rivals in its commitment to innovation and co-operation with clearing members
Driving innovation in risk management and technology
ActiveViam secured three major wins at the Risk Markets Technology Awards 2025 through its commitment to innovation in risk management and technology
Regulatory reporting product of the year: Regnology
Regnology retains its award for Regulatory reporting product of the year at this year’s Risk Markets Technology Awards.
Electronic trading support product of the year: TransFICC
TransFICC’s One API and automation solutions earned the Electronic trading support product of the year award by tackling fragmentation and streamlining workflows in fixed income and derivatives markets
Market data vendor of the year: S&P Global Market Intelligence
S&P Global Market Intelligence wins Market data vendor of the year for its comprehensive data solutions and tools supporting trading, risk management and compliance
Best use of machine learning/AI: CompatibL
CompatibL’s groundbreaking use of LLMs for automated trade entry earned the Best use of machine learning/AI award at the 2025 Risk Markets Technology Awards, redefining speed and reliability in what-if analytics
Clearing house support product of the year: FIA Tech
FIA Tech won Clearing house support product of the year for its TDN solution, which streamlines post-trade processing in ETDs by increasing efficiency, reducing risk and enhancing transparency