Become a partner

Slovak Arrow – from asset protection to risk analysis and management, from qualitative charlatanism to quantitative assessment (7 min)

Michal Hanus - , Cyber Risk Tamer and Visionary ·

Cyber risk has a price in euros – and the CRQ methodology can calculate it. If risk cannot be calculated, can we tolerate it at all? New Slovak legislation shifts the emphasis from ‘critical asset protection’ to systematic risk analysis and management across the entire interconnected ICT/OT environment, including the supply chain. The current methodology for risk analysis and management explicitly allows for the quantitative expression of risk in monetary terms and lists CRQ/Open FAIR methods as a legitimate option for meeting the requirements of the law.

The Czech-Slovak QICS community responded to this European first with an article entitled ‘Slovak Arrow’. The presentation and subsequent discussion will briefly outline how to bring cyber risk work to a level of management and decision-making that is understood by both the CFO and the CEO, as well as what the profession of a CRQ specialist entails.

We often measure cyber risks with color-coded tables, but they can lead us astray. The talk showed why it’s worth setting the compass by mathematics and moving to quantification in euros and time. The “Slovenská strela” also appeared as a metaphor, reminding us that bold innovations can come from where we don’t expect them.

From hygiene to numbers: where to start

If you instinctively sense that your cybersecurity has room for improvement, start with basic hygiene. Begin by implementing inexpensive, proven controls—such as the CIS Critical Security Controls (IG1)—if they cost less than a thorough risk analysis. Alongside that, make simple, qualitative considerations about threats and impacts in your environment. The goal, however, is to gradually move to expected annual loss expressed in euros, that is, to numbers that enable better decisions.

Read more

Sign in to ITAPA Health & Care 2026

Michal Hanus

Quant In Cyber Security
A cyber risk tamer and visionary who turns guesswork into exact financial losses. With a background in quantum and computational chemistry, he brings the rigor and accuracy of mathematics to cybersecurity. After 20 years in international IT consulting, service management, and architecture, he is disrupting traditional qualitative models and high…

Recommendation speakers

Johanna-Kadri Kuusk

e-Estonia Briefing Centre

Vanda Tuxhorn

Head of the Department of Pediatrics and Neonatology, Landau in der Pfalz, Germany

Christian Kumar

Capital Kinetics

Lukáš Benzl

Czech Association of Artificial Intelligence
Páčil sa ti článok? Zdieľaj ho a povedz o ňom aj ostatným