Scott Sumner is chief information security officer at Dassault Systèmes.gettyThe CISO has spent 40 minutes walking the board through a tidy slide deck. Ransomware is red; insider threat is yellow. The formatting looks great, and the language is clear. The directors have been listening attentively until the audit committee chair asks: "What does red mean in dollars, and how confident are you?"The CISO doesn't have an answer. The heatmap wasn't designed to answer that question.​That moment is playing out in boardrooms across the Fortune 1000, and it is a leading indicator of a transition cyber risk reporting is making. Risk assessment in the financial sector started maturing in the '90s, followed by operational risk in the 2000s. The qualitative era is ending, and boards know it.Why The Heatmap Survived This LongColor-coded risk matrices became the default because nothing better was practical. Cyber risk involves rare events, sparse and often subjective data, and an ecosystem that changes faster than any model of it. Telling a board "this is high risk, and we need to deal with it now" felt more honest than pretending to know a number. Less charitably, heatmaps also made convenient justification for more headcount and more tools.However, three things have changed:1. Regulators have increasingly viewed heatmaps as insufficient on their own. The SEC's cyber disclosure rules require public companies to determine whether an incident is material, which is difficult without quantification. Several rules—including the EU's NIS2 directive—are moving in the same direction. "We rated it high" is not a defensible answer to a regulator asking how a company concluded an incident was immaterial.2. The insurance market was repriced during the pandemic. Carriers that once wrote policies on the strength of a questionnaire now demand real actuarial inputs: loss distributions, control efficacy estimates and scenario analysis. Companies that rely solely on qualitative heatmaps may struggle to demonstrate the rigor insurers increasingly expect, potentially affecting pricing, coverage terms or underwriting decisions.​​3. The tooling caught up. ​Statistical techniques such as Bayesian inference, Monte Carlo simulation and Markov modeling are no longer confined to hedge funds and academic research. Today, security organizations can run these probability-based risk models on commodity hardware using data they already collect. The methodological barrier that once justified relying on simple risk heatmaps no longer exists.​​What Quantitative Cyber Risk Actually Looks Like​The math matters less than the conversation it enables.Picture a manufacturer trying to understand the financial impact of a ransomware attack on its production systems. A traditional heatmap produces a familiar answer: the risk is "high." A quantitative assessment instead estimates the likelihood of the event, the range of potential financial losses and the uncertainty around those estimates.That changes the discussion in the boardroom. Rather than debating whether a risk is "red" or "yellow," directors can compare the expected impact of different security investments. One initiative may cost more but reduce far more financial exposure, while another may deliver a better short-term return but leave greater downside risk. The board, CFO and CISO are no longer debating opinions. They are making a capital allocation decision using the same framework applied to every other major business investment.​What Boards Should Be Asking NowA board does not need to learn Monte Carlo to govern this transition. It needs to ask three questions and listen carefully to the answers:1. "Can the CISO quantify the company's top cyber risks in financial terms?​If not, the company is making cyber decisions on intuition disguised as analysis, and the board has no defensible record of having challenged them.2. "Does risk reporting show change over time?" Whether risk exposure is accelerating, decelerating or stable is the clear evidence that investments are working (or not). Static risk registers are a lagging indicator at best and governance theater at worst. A board overseeing a function that cannot show whether its own work is reducing risk is not exercising oversight; it is making itself feel like it is.3. "Will our company's approach survive inspection, especially in the courtroom?" Regulators, attorneys and acquirers will all examine how cyber risk decisions were made. A mature and quantitative analysis with stated assumptions and confidence intervals is easy to defend on its own merits.​The Governance QuestionFinancial risk reporting was also a gut-feel exercise at one point. Over time, financial institutions replaced intuition with quantitative techniques such as value at risk, stress testing and scenario analysis because boards needed a defensible basis for capital decisions and shareholder disclosures. Operational risk made the same journey a decade later, for the same reasons.Cyber risk is on the same journey, likely compressed into a shorter timeline because the regulatory, insurance and litigation pressures are arriving all at once. The companies that prepare now can improve their ability to make better cyber investments while surviving scrutiny their competitors may not. Acquirers, increasingly, price cyber exposure into deals; a target that cannot quantify its own risk invites a discount.The question is no longer whether cyber risk reporting will become more quantitative. That transition has already played out in financial and operational risk. The only uncertainty is how quickly organizations make the shift.​​The audit committee chair is going to ask. The only question left is whether the CISO arrives with an answer.​​​Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?