Booze Allen Hamilton just released a great tool that the security community should take a hard look at. The tool is called “CyberTab” and can be found here: https://cybertab.boozallen.com. CyberTab approaches the bottom line based on the breach scenario. It does a really good job of presenting various different aspects of a breach and attributing cost to them. For example, the cost of the C level executive(s) that will likely be involved and applying an hourly cost to them. Other expenses such as Public Relations, Insurance, Legal, Compliance related expenses are accounted for as well. With regards to this, the tool lacks overall is guidance on what those expenses could really be. The tool does give the user a LOW and HIGH range for costs. This is great, but it would be nice to have reference points. For example the Target Breach cost X in this category. A second thing I find lacking is for systems where the cost is greater than monetary. If there is loss of power, or environmental impact, or even loss of life, it would valuable to be able to attribute a cost to it somehow – whether it be monetary, social, PR, or emotional. Finally, the report is nice; however, it is non-interactive so that if an organization were to utilize the tool in a formal risk assessment exercise, the exercise would be limited to a single scenario with fixed variable that can not be moved once the report is generated. Overall, I applaud BAH for their contribution, and can’t wait to see how the tool matures.