Skip to main content

Control Effectiveness Model

Also known as:
  • CEM

Companion model that maps control strength and coverage to measurable reductions in loss event frequency, translating control investment decisions into annual loss expectancy changes.

Written by Askara Solutions editorial team · Updated

The Control Effectiveness Model answers the question exposure quantification does not directly answer: if you invest in a specific control, by how much does the risk actually go down?

Exposure quantification gives you a loss expectancy range for a scenario. This model adds the controls layer, mapping each control's strength and coverage to adjustments in the loss event frequency factor, so the model can express the risk delta between the current state and a proposed control investment.

The mechanics break a control down into effectiveness and coverage. Effectiveness captures how well the control performs its function when it is invoked. Coverage captures how consistently it applies across the relevant attack surface. Both feed the probability that a threat event produces a loss event. When a control improves, loss event frequency falls; when coverage is partial, the reduction is proportionally smaller. That makes it possible to model the difference between, say, deploying multi-factor authentication for all users and deploying it for privileged accounts only.

For an organisation that has already built a quantified risk register, this is the mechanism that makes the register useful for procurement and investment decisions rather than only for reporting. It answers the question a CFO or a board risk committee will eventually ask: we have a hundred thousand euros to spend on security this year. Which control investment reduces our exposure the most?

The Risk Investigation Agent uses it as the analytic layer connecting control proposals to quantified outcomes, on top of the Askara Exposure Model.