Risky Business: Quantitative Risk Assessments as Enabling Devices in Cybersecurity
Quantitative risk assessment (QRA) is a growing practice in the cybersecurity field. This paper examines QRA the use in various industries and the problems with its use. The focus of the qualitative research is to understand why cybersecurity organizations might want to use QRA even if it produces untrue and potentially problematic results. It draws from other bodies of work that view QRA as a