Book Review: From Heatmaps to Histograms

Book Review: From Heatmaps to Histograms

By
Key Takeaways
  • Decision-Making Over Visualization: From Heatmaps to Histograms argues that the purpose of risk management is not to produce better charts but to support better business decisions through meaningful quantification.
  • A Practical Path to Quantification: Rather than treating cyber risk quantification as an academic exercise, Tony Martin-Vegue provides a pragmatic framework that helps practitioners move from qualitative assessments to defensible, evidence-based analysis.
  • Communication Matters as Much as Analysis: The book emphasizes that quantitative models only create value when they are translated into clear narratives that help executives understand uncertainty and make informed choices.
  • Quantification Extends Beyond Cyber Risk: Although written from a cybersecurity perspective, the principles and techniques discussed can be applied across operational, enterprise, technology, fraud, resilience, and third-party risk management.
  • Human Judgment Remains Essential: While acknowledging AI's growing role in research and analysis, the book argues that human expertise remains indispensable for validating assumptions, interpreting results, and making accountable decisions.
Deep Dive

I have argued for years that risk is no longer a color. Red, amber, and green may make a report easier to scan, but they do not necessarily make risk easier to understand. The heatmap can tell an executive that something has been placed in a red box. It generally cannot explain how frequently the event might occur, what range of financial consequences the organization faces, whether a proposed control is worth its cost, or how one uncertain choice compares with another.

This is the challenge Tony Martin-Vegue confronts directly in From Heatmaps to Histograms: A Practical Guide to Cyber Risk Quantification. It is a substantial, practical, and deliberately provocative book that challenges the comfortable rituals of cyber risk management. More importantly, it does not simply attack heatmaps and walk away. It gives practitioners a path from criticism to capability.

I know Tony and have had him aboard the GRC Report's Risk Is Our Business podcast twice. Our first discussion was Heatmaps, Histograms and Star Charts: Quantifying Risk with Tony Martin-Vegue. He later returned for a deeper conversation tied directly to the book: From Heatmaps to Histograms: Rewriting Cyber Risk on the Bridge with Tony Martin-Vegue.

That relationship deserves disclosure, but familiarity does not remove the need for objectivity. A useful book must stand on the quality of its argument, the coherence of its structure, and its ability to improve practice. By those measures, Tony has produced an important contribution to cyber risk as well as the broader discipline of risk management.

A Practitioner's Book, Not a Mathematical Sermon

Tony's credibility comes not merely from studying quantitative risk but from practicing it. He brings more than 25 years of cybersecurity and technology risk experience and estimates that he has conducted approximately 1,000 quantitative risk assessments across cyber, fraud, operations, and enterprise risk.

That experience shapes the book. It does not read like a statistician descending from the mountain to inform mathematically illiterate risk professionals of their many sins. It reads like a practitioner who remembers what it felt like to stand at the bottom of the mountain and wonder where the trail began.

The book's origin story captures this well. Tony describes presenting cyber risk to executives alongside credit, liquidity, and market risk leaders. The other risk functions discussed exposure through dollars, ranges, probabilities, and limits. Their presentations triggered debate about investment, mitigation, insurance, and strategy.

Tony presented data breach risk as "medium" and an outage as "high." The executives nodded politely, and the conversation moved on. That contrast drove him to search for a better approach.

Many cyber and GRC professionals will recognize that scene. A great deal of risk reporting creates the appearance of communication without producing an actual decision. The heatmap is presented, the risk register is reviewed, everyone acknowledges the red items, and then the meeting ends with remarkably little clarity about what should happen next.

Tony's central argument is that uncertainty is not a defect to be concealed behind categorical labels. It is the terrain on which risk management operates. The role of the risk professional is therefore not to manufacture certainty but to help the organization make better decisions with incomplete information. Quantification, in this context, is not about pretending that an estimate is perfectly precise. It is about replacing vague adjectives with defensible ranges that make uncertainty visible and useful.

The Book Builds Capability in Deliberate Stages

One of the book's greatest strengths is its architecture. Tony does not throw the reader into a fully decomposed FAIR model and expect enthusiasm to overcome confusion. He constructs the subject progressively.

The opening sections establish the intellectual and historical case for quantitative risk. The book then moves into ranges, frequency, magnitude, Monte Carlo simulation, risk statements, loss forms, and the interpretation of distributions. From there, it tackles what is often the greatest practical obstacle: data. External research, internal organizational evidence, and subject-matter expertise are treated as complementary sources that can be evaluated, challenged, and combined. Later sections take the reader through complete assessments, organizational adoption, decision support, and the future role of artificial intelligence.

This progression is important because many professionals do not reject quantification on intellectual grounds. They reject it because it appears inaccessible. They assume that they need perfect historical data, expensive platforms, advanced statistical training, or an actuary embedded in the security team.

Tony methodically dismantles those assumptions. He shows how an analyst can begin with ordinary tools, use ranges rather than fictional point estimates, combine external baselines with internal experience, and structure expert judgment instead of dismissing it as subjective. His three-source model (external data, internal data, and subject-matter experts) is particularly useful because it reflects organizational reality.

Historical data is rarely complete, industry data is rarely perfectly comparable, and experts are rarely perfectly calibrated. The answer is not to abandon analysis but to understand the strengths and weaknesses of each source.

The book is also refreshingly pragmatic about FAIR. It is compatible with FAIR and includes a dedicated discussion of it, but it is not written as a FAIR catechism. Tony explicitly warns readers against confusing the taxonomy with the analysis or turning FAIR into a religion. His advice is to use as much decomposition as the decision and available evidence justify, not to create complexity merely to demonstrate methodological purity.

Communication Is the Real Test

A technically correct analysis can still fail if nobody understands it. Tony recognizes that the most difficult part of quantitative risk may not be Monte Carlo simulation, data collection, or estimating ranges. It is communicating the results so that executives, engineers, finance leaders, and operational stakeholders understand what the analysis means for the choice before them.

His emphasis on turning numbers into narratives is one of the book's strongest elements. An executive does not need to be impressed by the machinery of the simulation. The executive needs to understand the range of outcomes, the possibility of exceeding a meaningful threshold, the assumptions driving the result, and how the available options change exposure.

This is where many quantitative programs become their own form of theater. They replace a colorful matrix with an intimidating distribution and assume analytical sophistication automatically creates business value.

A histogram disconnected from a decision is no more useful than a heatmap disconnected from an objective (and even that heatmap is not useful). Tony understands this. The book repeatedly returns to the idea that the value is not in the mathematics itself but in the clarity the analysis creates. A complete assessment should move through scenario, evidence, ranges, simulation, interpretation, and ultimately a decision the business can act on.

From Risk Reporting to Decision Support

For me, the book reaches its strongest point when Tony moves beyond the mechanics of quantification and centers the discussion on decision-making. Risk management does not exist to maintain risk registers. It does not exist to populate dashboards, administer assessments, or generate quarterly packets for committees. Those may be supporting activities, but they are not the purpose. The purpose is to help people make decisions and choose wisely when objectives are pursued under uncertainty.

Tony states this clearly. Risk analysis should begin with a decision (and, from there, objectives tied to that decision), not a dashboard. The work matters when it helps someone choose between investments, controls, insurance options, operational alternatives, strategic moves, or competing allocations of resources. He argues that mature risk management is not about reducing every risk as far as possible. It is about optimizing the relationship among protection, performance, opportunity, and cost.

This aligns closely with my own view of GRC. Governance makes decisions, establishes objectives, and performs against those objectives (some break GRC into GPRC by adding performance). Risk management addresses uncertainty in achieving those objectives. Compliance acts with integrity in meeting obligations and commitments as the organization pursues those objectives. Quantification becomes valuable when it strengthens that capability, not when it operates as an isolated cyber analytics exercise.

Although the title appropriately focuses on cyber risk, the logic is much broader. Digital risk and resilience are specialized dimensions of operational risk and resilience, and the methods Tony explains can be applied across technology, operations, third parties, fraud, resilience, and enterprise risk. The book itself makes clear that its techniques extend beyond cyber into digital, operational, technology, and enterprise risk contexts.

AI Needs Judgment, Not Worship

The book's treatment of generative AI is timely without becoming breathless. Tony presents AI as a research partner, analytical accelerator, and tool for structuring information. He also stresses that it can produce plausible errors, fabricated sources, outdated information, and biased conclusions. And you have to love his comparison that people think AI is Data from Star Trek, when in reality it is Jack Sparrow from Pirates of the Caribbean, an analogy he writes about and one I use regularly in my presentations.

His essential position is that AI increases the importance of human judgment rather than eliminating it. As routine data gathering and calculation become easier, the differentiating skills move toward validation, interpretation, contextual understanding, model challenge, and communication.

This is exactly the conversation risk professionals should be having. The future is not a choice between human analysis and machine analysis. It is an orchestrated relationship in which machines accelerate research, configuration, modeling, and execution while humans remain accountable for context, challenge, and decisions. AI can generate a model, but it cannot assume responsibility for whether the model belongs in the decision.

Where I Would Add Some Nuance

The book is strongly argued, and its attack on qualitative risk practices is intentionally forceful. I largely share Tony's frustration. Too many organizations use ordinal scales as though they were measurements and multiply arbitrary numbers as though the resulting score had mathematical meaning.

Still, I would not argue that every qualitative artifact must be thrown into the fire. A heatmap may have limited value as an orientation device, a triage mechanism, or a simple communication shorthand, and I am willing to stretch acceptance of it provided everyone understands that it is not measurement. The problem begins when it is expected to support comparisons, investment choices, control optimization, insurance decisions, or board-level conclusions that it was never capable of supporting.

Tony offers some of this nuance himself. He acknowledges that practitioners may be required to operate within qualitative programs and explains that quantitative thinking can still improve their questions, assumptions, and communication even when the official heatmap remains. I would also frame "risk appetite" somewhat differently. I do not believe an organization has an appetite for risk in isolation. Organizations have an appetite for value. They pursue objectives and accept a degree of uncertainty and exposure because of the value they hope to achieve. However, Tony's broader emphasis on optimization rather than indiscriminate risk reduction leads in substantially the same direction.

Finally, this is not a comprehensive book on governance, GRC, enterprise risk management, controls, or the complete risk lifecycle, and it does not pretend to be. Tony explicitly limits the book to risk analysis while showing how analysis can support a living organization. Readers looking for an executive overview may find the book more detailed than they need. Practitioners who genuinely want to build competence will regard that same detail as one of its primary strengths.

Final Assessment

Tony succeeds because he combines conviction with practicality. He challenges deeply embedded practices, but he also understands that organizations do not change because an analyst returns from training and announces a revolution. They change when someone uses a better method to solve a real problem, support a difficult decision, and demonstrate value. His guidance to begin with one decision, build allies, integrate gently, and show progress rather than perfection reflects the hard-earned judgment of someone who has seen both successful and unsuccessful quantification programs.

I recommend this book to cyber risk professionals, CISOs, GRC teams, enterprise and operational risk leaders, internal auditors, consultants, and anyone frustrated by risk reports that generate activity but little insight. It will be particularly valuable to practitioners who know their current methods are inadequate but have been told that quantification is too complicated, too expensive, or too dependent on perfect data.

Tony demonstrates that the obstacle is not the absence of certainty. The obstacle is our unwillingness to work honestly with uncertainty. The future of risk management will not be found in increasingly elaborate shades of red, amber, and green. It will be found in better scenarios, better evidence, transparent assumptions, defensible ranges, and clearer decisions.

The destination is not the histogram. The destination is a better decision.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong