Webinar

Industry Leaders

About Our Experts

Jake Olcott

Vice President, Government Affairs at BitSight

Jake has extensive experience in cybersecurity and risk management, advising Fortune 1000 executives and shaping policy at the federal level. He has taught cybersecurity as an adjunct professor, combining practical, legal, and strategic expertise to help organizations understand, mitigate, and manage cyber risks while navigating complex regulatory environments.

Paul McKay

Principal Analyst, Cybersecurity Strategy & Risk Expert

Paul McKay is a Principal Analyst at Forrester, guiding organizations in building and executing effective cybersecurity strategies. His research covers cyber risk quantification, risk ratings, CISO leadership, and European security service providers. Frequently quoted in major publications, Paul holds Oxford and St Andrews degrees and is a Fellow of the British Computer Society.

Dr. Jack Freund

VP & Head of Cyber Risk Methodology, CRQ Thought Leader

Dr. Jack Freund is VP and Head of Cyber Risk Methodology at BitSight, overseeing quantitative and qualitative frameworks for measuring cyber risk. With 23 years of experience across Fortune 100 organizations, he co-authored the seminal FAIR-based book Measuring and Managing Information Risk. He holds a Ph.D. and numerous leading cybersecurity certifications.

Cyber Risk Quantification: Turning the Dream into Reality

Jul 14 / IT GRC Forum

Cyber Risk Quantification (CRQ) is rapidly becoming a critical capability for CISOs who must explain cyber risk in financial terms, prioritize investments, and strengthen executive decision-making. Although CRQ provides clear benefits, many security leaders still struggle with where to begin, how to operationalize it, or how to adopt it without major cost or complexity.


In this webinar, BitSight’s Jake Olcott and Dr. Jack Freund, along with a featured expert from Forrester, will break down the challenges of implementing CRQ and provide practical steps to make it achievable for organizations of any size. Attendees will learn how to launch a CRQ initiative, communicate cyber risk in financial language executives understand, and integrate CRQ into existing cybersecurity frameworks. The session will also cover how to align CRQ with industry standards and identify program gaps that need improvement.

Join us to gain actionable guidance, avoid common pitfalls, and take the first steps toward building a fully operational cyber risk quantification program.