この数字はなぜ信用できるのか。
- ・CISOaaS のリスク金額は、攻撃チェーン上の客観的指標で算出します(主観的な「発生確率」を使いません)。
- ・損失額は単一の予測値ではなく、確率分布として推定します(95% 信頼区間と最悪ケースを併記)。
- ・投資額は情報セキュリティ経済学の最適理論に基づき、過不足が起きない範囲を示します。
- ACRA:攻撃チェーン上で客観的にリスクを定量化
- FAIR:確率分布で 95% 信頼区間と最悪ケースを表現
- Gordon-Loeb:情報セキュリティ経済学の最適投資理論
Why we can quantify risk.
CISOaaS assessments rest on our own method ACRA and information security economics.
Not 'a feeling' — a framework for numbers you can defend with evidence.
ACRA — Attack Chain Risk Assessment
Attack Chain Risk Assessment
Traditional risk assessment uses 'impact × probability of occurrence,'
but estimating that probability is highly subjective and its basis is opaque.
ACRA is our own method built to solve this.
It breaks the attack — from initial intrusion to actual damage — into 4 phases,
Position on the attack chain・Ease of attack・Presence of compensating controls and derives a baseline risk from them.
Risk is then mitigated in steps according to implementation status.
Each phase is mapped to MITRE ATT&CK framework tactics,
ensuring consistency with international threat taxonomies.
Loss is computed via the international standard FAIR (Factor Analysis of Information Risk) and Monte Carlo simulation, expressed not as a single point estimate but as a probability distribution. Showing 'what's the 95% range, what's the worst-case' makes executive decisions more confident.
Probability estimates are subjective.
Hard to defend with evidence.
Objective metrics. MITRE ATT&CK-aligned.
See the underlying logic (4-phase attack chain, loss distribution, optimal investment model)
Initial Access, Execution, Persistence
Stealth, Defense Impairment, Discovery
Privilege Escalation, Lateral Movement
Exfiltration, Impact
Mapped to the MITRE ATT&CK Framework
FAIR + Monte Carlo — loss as a probability distribution
Factor Analysis of Information Risk
Annualized Loss Expectancy (ALE) is computed not as a single point estimate but as a probability distribution. Based on the FAIR standard, per-occurrence loss magnitude is modeled with the PERT distribution and frequency with the Poisson distribution. Monte Carlo simulation then runs 10,000 scenarios.
This gives you 'the 95% range (19 years in 20)' and 'what a 1-in-20-year bad year looks like' — precise loss numbers as input to the optimal investment computation (Gordon-Loeb).
Loss = Frequency × Magnitude
- FAIR
- Factor Analysis of Information Risk. An international framework that decomposes information risk into 'frequency × magnitude' and expresses it as a probability distribution.
- Probability distribution
- Instead of fixing a single value, this expresses 'how likely each outcome is.' It captures the typical value, the 95% range, and the worst case at once.
- PERT distribution
- A distribution shaped by three points — minimum, most likely, and maximum. Aligns well with expert estimates and is used to model per-occurrence loss magnitude.
- Poisson distribution
- A distribution that models 'how many times an event occurs in a given period.' Used here to estimate the yearly frequency of incidents.
- Monte Carlo simulation
- A method that samples randomly from the distributions above to run 10,000 scenarios, producing the full distribution of annual losses.
Stepwise risk mitigation
Risk levels step down according to implementation status. If other controls in the same phase work as compensating controls, risk is further reduced.
When other safeguards within the same attack phase are sufficiently implemented, the target safeguard's risk is reduced by one further step.
Gordon-Loeb optimal investment model
Based on the Gordon-Loeb (2002) theory from information security economics, we compute the optimal upper bound for security investment — preventing both over-investment and under-investment.
Optimal Investment Formula
