How to Calculate the Real Cost of a Third-Party Breach
Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how organizations can move beyond vague warnings about risk and start putting real numbers behind the potential cost of a third-party breach. If you want security leaders, executives, and boards to take third-party cyber risk seriously, you need to understand how to quantify its financial impact.
Many security teams still rely on qualitative risk language like “high,” “medium,” or “critical,” but those labels rarely drive action. Jeffrey, Bob, and Ferhat break down why calculating the financial impact of a third-party breach is essential for communicating with executives, prioritizing vendors, and securing the right investments in risk management. From understanding uncertainty to building models that are accurate enough to guide decisions, this conversation offers practical insight into how leading teams estimate breach costs and translate cyber risk into business language.
In this episode, you’ll learn:
* Why calculating the financial impact of a third-party breach is critical for executive decision making
* How security leaders translate cyber risk into dollars, euros, or pounds
* Why “something bad could happen” is not enough to justify cybersecurity investment
* The difference between precision and usefulness when modeling cyber risk
* How risk quantification helps prioritize vendors and third-party exposures
* Why boards and executives respond better to financial risk than technical risk language
Don’t risk letting third-party cyber risk remain invisible to leadership. Learn how to calculate the real financial impact of a third-party breach and turn risk conversations into decisions that protect your organization.
0:00 Introduction & Teaser
0:50 Welcome & Episode Overview
2:01 Guest Introduction: Jack Jones & the Origin of FAIR
7:17 Challenges to Implementing Risk Quantification
10:57 Wrap-Up with Jack Jones
11:23 Calculating Financial Impact of a Third-Party Breach
25:54 Precision vs. Accuracy in Risk Models
30:01 Research Roundup: Cybersecurity Outlook 2026
36:44 Agree or Disagree
39:41 Outro & Next Episode Preview