(TR07)(INCYBER) Quantifier le risque cyber : mieux mesurer pour mieux protéger, gérer et assurer

(TR07)(INCYBER) Quantifier le risque cyber : mieux mesurer pour mieux protéger, gérer et assurer

🎙 INCYBER 👥 7K 📅 April 14, 2026 ⏱ 57 min 👁 97 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

cyber riskquantificationFAIRMonte Carlorisk management

Summary

This roundtable discussion, part of the INCYBER Forum Europe 2026, brings together five experts from cybersecurity, risk management, and insurance to explore the quantification of cyber risk. Pierre-Louis Louisan from Qualys introduces the concept of a Risk Operations Center (ROC) that aggregates assets, vulnerabilities, and threats to provide real-time risk scoring and prioritization, enabling proactive risk management. Rebia Bardo Girard from AXA describes their approach to quantifying risk for clients, including the use of an AI-driven tool (RQI) that generates risk profiles and action plans in 15 minutes, and emphasizes the importance of translating technical risk into financial terms for CFOs. Estelle Boyer Chigic from CNP Assurances shares their experience using the FAIR methodology and Monte Carlo simulations to quantify cyber risk for a specific business line, highlighting the importance of understanding the business, engaging stakeholders, and iterating on the model. The discussion covers challenges such as lack of historical data, the need for cross-functional collaboration, and the limitations of current tools. The panel concludes that quantifying cyber risk is essential for informed decision-making, resource allocation, and effective insurance coverage, but it remains an evolving practice with inherent uncertainties.

189 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in the practical, real-world perspectives shared by the panelists, who represent both technology vendors and insurance companies. They provide concrete examples of how cyber risk quantification is implemented, such as Qualys’s ROC and AXA’s RQI tool, and discuss the benefits of translating risk into financial terms to engage executives. The argumentation is coherent and grounded in professional experience, but it is largely anecdotal and lacks rigorous scientific evidence. The panelists acknowledge limitations, such as the reliance on expert judgment and the challenges of data scarcity, which adds credibility. However, the discussion is somewhat promotional, with vendors highlighting their solutions, and the scientific depth is moderate.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the panelists reference established methodologies like FAIR and Monte Carlo simulations, but they do not provide detailed citations or empirical data. The sources cited in the description are limited to the INCYBER forum website and LinkedIn, which are not directly related to the technical content. The title accurately reflects the content, which focuses on quantifying cyber risk for protection, management, and insurance. The discussion is well-structured and covers multiple perspectives, but it lacks independent verification and peer-reviewed references.

209 words

Title / Content Match

The title accurately reflects the content, which focuses on quantifying cyber risk for protection, management, and insurance purposes.

Quality & Reliability

7/10

The panel consists of industry experts from Qualys, AXA, and CNP Assurances, providing practical insights and case studies. The discussion is grounded in professional experience and references established methodologies like FAIR and Monte Carlo simulations. However, the content is largely promotional and lacks peer-reviewed sources or independent verification.

Key Moments

Cited Sources

  • INCYBER Forum Europe — Official website of the INCYBER Forum Europe, the event where this roundtable took place.
  • INCYBER Europe LinkedIn — LinkedIn page of INCYBER Europe, providing updates and networking opportunities.

Concurring Sources

  • FAIR Institute — The FAIR Institute promotes the FAIR methodology for cyber risk quantification, aligning with the approach discussed in the video.
  • NIST Cybersecurity Framework — The NIST framework provides a structured approach to managing cyber risk, complementing the quantification methods discussed.

Dissenting Sources

  • Cyber Risk Quantification: A Critical Review — Some academic critiques argue that current quantification methods, including FAIR, rely heavily on subjective inputs and may not accurately capture the complexity of cyber risk.

Contribution & Novelties

The video provides a practical overview of cyber risk quantification from the perspectives of a technology vendor and two insurance companies. It highlights the importance of translating cyber risk into financial terms for executive decision-making and shares real-world implementation experiences using methodologies like FAIR and Monte Carlo simulations. The discussion also addresses challenges such as data scarcity and the need for cross-functional collaboration.

Pour aller plus loin :

  • FAIR Institute — The official site for the FAIR methodology, offering resources and training.
  • Monte Carlo method — Wikipedia article explaining the Monte Carlo simulation technique used in risk analysis.
  • ISO/IEC 27005 — International standard for information security risk management, providing a framework for risk assessment.

114 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, with a slight emphasis on quantity and reliability. This indicates a well-rounded discussion with practical insights, though the technical depth is moderate and the reliability is based on expert opinion rather than empirical data.

Reliability 7/10

💬 No comments were provided for analysis.