Cyber Risk Quantification for Critical Infrastructure: Moving Beyond ROI to Risk-Informed Decisions
About This Session
As critical infrastructure systems become more connected and digitally enabled, industrial control system (ICS) environments are facing a growing gap between operational investment decisions and cyber risk exposure. While organizations rigorously evaluate return on investment (ROI) for modernization, automation and digital transformation initiatives, cybersecurity is often assessed using qualitative metrics that fail to capture true business impact. This disconnect leaves critical infrastructure operators exposed to risks that are not fully understood, prioritized, or funded.
This session introduces a practical approach to cyber risk quantification (CRQ) tailored for ICS environments, one that translates cybersecurity from a technical discipline into a financial decision-making tool. Grounded in established methodologies, this approach quantifies cyber risk in terms of probability and financial consequence, enabling organizations to estimate annualized loss exposure and evaluate mitigation strategies in dollars rather than subjective ratings.
We will explore how this model supports a shift from traditional ROI to Return on Mitigation (RoM), allowing operators to measure how effectively cybersecurity investments reduce financial risk. In critical infrastructure, where low-probability events can result in high-impact consequences such as operational downtime, safety incidents, regulatory penalties and long-term service disruption, this distinction is essential. Quantifying these outcomes provides a common language for aligning cybersecurity with engineering, operations and executive leadership.
This session equips critical infrastructure leaders and professionals with a framework to make informed, risk-based decisions, ensuring that cybersecurity investments are aligned with operational priorities, financial performance and the long-term resilience of essential services.
Attendees will learn how to identify high-risk transformation moments, compare competing investments and prioritize actions that deliver the greatest reduction in risk exposure. The session will also highlight how integrating CRQ into planning processes improves funding justification, strengthens cross-functional alignment and supports more resilient system design.
This session introduces a practical approach to cyber risk quantification (CRQ) tailored for ICS environments, one that translates cybersecurity from a technical discipline into a financial decision-making tool. Grounded in established methodologies, this approach quantifies cyber risk in terms of probability and financial consequence, enabling organizations to estimate annualized loss exposure and evaluate mitigation strategies in dollars rather than subjective ratings.
We will explore how this model supports a shift from traditional ROI to Return on Mitigation (RoM), allowing operators to measure how effectively cybersecurity investments reduce financial risk. In critical infrastructure, where low-probability events can result in high-impact consequences such as operational downtime, safety incidents, regulatory penalties and long-term service disruption, this distinction is essential. Quantifying these outcomes provides a common language for aligning cybersecurity with engineering, operations and executive leadership.
This session equips critical infrastructure leaders and professionals with a framework to make informed, risk-based decisions, ensuring that cybersecurity investments are aligned with operational priorities, financial performance and the long-term resilience of essential services.
Attendees will learn how to identify high-risk transformation moments, compare competing investments and prioritize actions that deliver the greatest reduction in risk exposure. The session will also highlight how integrating CRQ into planning processes improves funding justification, strengthens cross-functional alignment and supports more resilient system design.
Speaker
Hector Perez
Head of Strategy, Global Industrial Cybersecurity - Black & Veatch
Hector is the Head of Strategy for Black & Veatch’s Industrial Cybersecurity practice.
With more than 20 years of experience at the intersection of operational technology (OT) cybersecurity, engineering and digital transformation, he drives strategic innovation to enhance cyber resilience across complex industrial environments. Hector specializes in secure-by-design methodologies that align operational goals with evolving threat landscapes. Throughout his career, he has earned multiple industry awards and patents, and his contributions to high-performance system design and cybersecurity integration have helped shape best practices across critical infrastructure organizations. Hector holds a degree in Chemical Engineering and an MBA from Rice University.
With more than 20 years of experience at the intersection of operational technology (OT) cybersecurity, engineering and digital transformation, he drives strategic innovation to enhance cyber resilience across complex industrial environments. Hector specializes in secure-by-design methodologies that align operational goals with evolving threat landscapes. Throughout his career, he has earned multiple industry awards and patents, and his contributions to high-performance system design and cybersecurity integration have helped shape best practices across critical infrastructure organizations. Hector holds a degree in Chemical Engineering and an MBA from Rice University.
