Customer cases
At ACI Risk Measure, we work with organisations that seek a stronger foundation for decision-making in cybersecurity.
Our client cases provide insight into how risk quantification can be translated into concrete action – and how a shared language for cyber and IT risk can strengthen the dialogue between security, business, and leadership.
“The collaboration with ACI Risk Measure has given us a firm grip on a complex area. We can now show the board what incidents actually cost, and we can follow up on whether our mitigation measures are actually being implemented, not just decided on.”
Quantifying incidents and ongoing follow-up strengthens Vestjylland Forsikring’s approach to cyber risk
Challenge
As an insurance company, Vestjylland Forsikring faces a growing requirement to document, prioritise and follow up on cyber risks for both management and the board. The company lacked a systematic method for assessing risk, translating incidents into concrete figures and ensuring that agreed mitigation measures were actually implemented, not just decided on.
Approach
In collaboration with ACI Risk Measure, Vestjylland Forsikring has established the Managed Cyber Risk service, which combines an annual SARA risk assessment with quarterly status follow-up. The SARA assessments form the basis for concrete mitigation strategies, on which the board tracks progress on an ongoing basis.
The collaboration follows a fixed format: ACI Risk Measure interviews key people at Vestjylland Forsikring and develops concrete proposals for how individual risk areas can be addressed. In addition, the company’s security incidents are quantified using ACI Risk Measure’s taxonomy for external and internal incidents, which Vestjylland Forsikring has adopted as a shared language for incident management. This shared language reduces ambiguity in reporting across departments and makes it possible each quarter to answer precisely which incidents have actually been most costly to the organisation, based on data drawn directly from the company’s ISMS tool. In this way, the SARA risk assessments can be continuously tested against real figures, rather than remaining a theoretical exercise.
The collaboration also includes ongoing dialogue on current topics and major IT projects. The contingency exercises are a concrete example of this: they stem directly from a mitigation recommendation in an earlier SARA risk assessment, and Vestjylland Forsikring has used the recommendation to strengthen its response capability in a specific risk area, thereby reducing the risk in practice.
Result
The collaboration has given Vestjylland Forsikring a fixed, recognisable format for its risk work and a clear link between risk assessment, financial consequence and concrete action. Quantifying incidents gives the board a tangible picture of what cyber risks actually cost quarter by quarter, and makes it possible to continuously measure the SARA assessments against real figures. At the same time, the quarterly follow-up ensures that mitigation proposals from SARA are actually translated into action rather than stopping at the decision stage, which the contingency exercise directly demonstrates: a risk assessment that has become a concrete improvement and an actual reduction in risk.
“ACI Risk Measure provides valuable sparring and challenges our assessments in a constructive way. They understand our situation and ask relevant questions that help us refine our risk assessments. The quarterly reports give a good overview and serve as a useful basis for dialogue with management and the board.”
Continuous sparring on cyber risk strengthens the decision-making basis
Challenge
As a financial institution, Sydjysk Sparekasse operates in a landscape of increasing regulatory requirements and an ongoing need to document and prioritise cyber risks. Consequently, the bank wanted a more structured and data-driven approach to risk management, one that could also support the decision-making process of management and the board.
Approach
In collaboration with ACI Risk Measure, Sydjysk Sparekasse conducts quarterly workshops as part of the Managed Cyber Risk service. These workshops address their cyber risks, with ACI Risk Measure providing sparring on the identified risks and the assumptions underlying the assessments. Based on the workshops, together with available data, statistics and current threat assessments, a report is produced that gives an overall view of the risk picture.
Result
The collaboration has contributed to a more systematic approach to cyber risk work and provided a better basis for prioritising risk-reducing initiatives. The reports support dialogue with management and the board and help create clarity in a complex area. At the same time, the ongoing sparring contributes to a shared understanding of cyber risk across the organisation.
“Quantification has been on my radar for a long time, but every approach we came across ended up as a theoretical exercise, fine words and loads of PowerPoint slides, with little real value to the business. ACI Risk Measure was different. We started with a PoC on a defined area of the business to test both the concept and their approach, and we’ve come away with exactly the insight we were looking for. Not theory, but something we could actually use and act on.”
Quantification that works in practice – not just on paper
Challenge
Trivium Packaging had solid security measures in place but wanted to go further: understanding their risk exposure in financial terms.
They had looked into quantification before, but the approaches they encountered were complex, theoretical and hard to connect to the realities of their business. When they were introduced to ACI Risk Measure’s methodology, they decided to put it to the test through a Proof of Concept (PoC) on a selected area of the business.
Approach
Working closely with Trivium Packaging’s specialists, the most relevant risk scenarios were identified. A series of workshops were used to gather and validate data points and assumptions, after which the scenarios were modelled quantitatively.
Result
The PoC put financial estimates to the selected risk areas. Senior management gained clear insight into what the identified risks represent in terms of potential financial loss, where uncertainty is greatest and which risks are driving the overall exposure. This gave the organisation a much clearer picture of where future efforts and security investment would have the greatest impact.
The PoC also showed that quantification does not depend on having perfect data. By working systematically with assumptions, uncertainty became a natural part of the analysis rather than an obstacle. Trivium Packaging now has a solid foundation for taking quantification forward as a core part of its risk management.
“The collaboration with ACI Risk Measure has provided us with a risk management approach that genuinely supports management decision-making. The continuous updates deliver a current, data-driven risk picture that can be used directly in day-to-day management and in dialogue with the board.”
CONTINUOUS CYBER RISK MANAGEMENT CREATES DECISION-MAKING CLARITY AND REGULATORY ROBUSTNESS
Challenge
Lægernes Pension and Bank is characterised by being both a pension fund and a bank, which places specific requirements on governance, compliance, and it risk management. This combination means that the organisation is subject to a broad and complex regulatory landscape, including DORA.
Prior to the collaboration, Lægernes Pension and Bank had a clear objective to raise their compliance and maturity level in relation to DORA while at the same time strengthening management oversight of it risks. Achieving greater control and transparency was essential – particularly in relation to IT third parties – and ensuring that risk management was operational, data-driven, and decision-relevant. The work was initiated one and a half to two years before DORA entered into force and required a coordinated effort across management, IT, risk management, and compliance.
Approach
In collaboration with ACI Risk Measure, Lægernes Pension and Bank transitioned from an annual risk and security assessment (SARA) to quarterly updates. As a result, the risk picture has become a continuous and dynamic management tool, where new incidents, changes in the threat landscape, and operational experience are quickly reflected in the assessments.
ACI Risk Measure’s Managed Cyber Risk forms a central element of this approach. The quarterly updates are based on actual data points, Lægernes Pension and Bank’s own incident logging, and follow-up on initiated risk-mitigating measures. At the same time, the solution supports clear management processes within it, a structured handling of it third-party risks, and a multi-year risk assessment setup that ensures consistency and continuity in the risk picture – in full alignment with Lægernes Pension and Bank’s DORA programme.
Result
During the period, Lægernes Pension and Bank underwent an independent maturity assessment conducted by an audit firm, which evaluated a range of it processes, including IT risk management. In the audit firm’s reporting, Lægernes Pension and Bank’s it risk management was assessed as being at a medium-to-high level, providing a solid starting point for Lægernes Pension & Bank to work towards achieving a generally high level of maturity.
The most significant result, however, is that Lægernes Pension and Bank has now established risk management as a genuine management tool. Executive management and the board receive ongoing reporting that can be used directly as decision support and have a clear overview of risks, trends, and the effect of initiated measures. Risk management is now operational, data-driven, and DORA-aligned throughout the year.
“Cybersecurity has been a strategic focus area for us for many years. The collaboration with ACI Risk Measure has provided us with a clear picture of our cyber risks in business terms. I am very impressed by the way ACI Risk Measure applies actuarial methods to calculate probabilities and associated costs. It translates risk into a language that is familiar and understandable to the board.”
QUANTIFYING CYBER RISK STRENGTHENS STRATEGIC DECISION-MAKING
Challenge
VELUX wanted a stronger foundation for discussing and prioritising cyber risks at executive level. The traditional red, yellow, and green heat maps (4×4 matrix) did not provide a true picture of what the risks actually meant for the business. The goal was therefore to establish a better way of communicating risk – one that could enhance understanding of the risks and their business impact, while supporting strategic choices and investment priorities that reduce risk where it creates the most value.
Approach
In collaboration with ACI Risk Measure, VELUX’s cyber risks were analysed and quantified through a series of workshops and data-driven assessments. The process combined the security team’s existing knowledge with business insights from leadership, enabling risks to be translated into concrete financial estimates. This made it possible to illustrate how different types of incidents could affect VELUX – both directly and indirectly – in financial terms, supported by statistical data.
Result
By quantifying the risks, cybersecurity could be communicated in a far clearer and more measurable way. The report summarising the results has been used as both a communication and prioritisation tool for management and the board, making it easier for the security team and leadership to speak from a common point of reference. It provided a clear picture of where efforts create the most value, increased transparency around budget needs, and strengthened the dialogue on priorities.