Skip to content

Speaking


Tony Martin-Vegue on stage at the 2025 FAIR Conference, under a slide that says traditional risk programs are obsessed with changing colors

I wrote From Heatmaps to Histograms and built the cyber risk quantification program at Netflix. Since 2014 I’ve given more than 60 talks, workshops and panels. Most are about measuring cyber risk in dollars: how to start a program, where the data comes from, what AI changes, and how to explain a range of possible losses to the people who have to act on it.

I’ve spoken at RSA Conference in five different years, at DEF CON, FAIRcon and SiRAcon, at several BSides and ISACA conferences, and at FAIR Institute chapters around the country. Several of my recent sessions work through a live analysis, and the workshops are hands-on.

I speak at conferences and at corporate and private events, including leadership offsites and team meetings. I’m happy to sign books at your event, and Springer offers bulk pricing if you’d like copies for your attendees.

What I talk about

Nearly everything I talk about comes back to one idea: cyber risk is measurable, and the belief that it isn’t is something our industry inherited and never tested. These are the topics I’m asked about most.

  • From Heatmaps to Histograms, my signature keynote on why risk matrices fail and what to use instead
  • Finding, vetting, and blending the data a risk analysis needs, even when you think you have none
  • Running a first quantitative risk analysis with a spreadsheet and no statistics degree
  • Talking about cyber risk with boards and executives in dollars
  • Deciding how much security is enough, and what the budget is buying
  • Measuring AI risk in dollars and probabilities
  • Using generative AI in risk analysis, and where it still needs a human check
  • Calibration, and how to get good estimates out of experts
  • How bad statistics spread through the security industry, and how to grade a report
  • Security metrics and KRIs that inform decisions
  • The economics of ransomware
  • Building a risk quantification program that lasts past its first year
  • The six levers that change cyber risk, of which controls are only one

Any of these can run as a keynote, a workshop, a fireside chat or a debate. Tell me what your audience is wrestling with and I’ll tell you what I’d bring. If your team wants to practice the methods together, I also run private workshops, and the book site describes the formats.

Watch a talk

Rethinking Cyber Risk Responses, Risk Awareness Week, 2021

Program chairs usually want to see a talk before booking one. These recordings are free to watch.

Recent talks

Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR

A 90-minute workshop in the Noob Village at DEF CON 34, Las Vegas, August 2026

Did We Solve the Data Problem? Judgment, Beliefs, and Risk in the AI Age

Keynote at SiRAcon ’26, Boston, April 2026

The Future of Cyber Risk Intelligence

Part of the FAIR Institute seminar at RSAC 2026, San Francisco, March 2026

The Six Levers That Actually Move Risk (Hint: It’s Not Just Controls)

Case study at FAIRCON25, New York, November 2025

Speaking the Language of Business: Cyber Risk Reimagined

Panel with Richard Seiersen and Doug Hubbard at Qualys ROCon Americas 2025, Houston, October 2025

Quantifying in the Age of Hallucination: How I Learned to Stop Worrying and Trust the AI (Sometimes)

Talk at SiRAcon ’25, Boston, September 2025

Conference talks since 2014

2026

  • A panel on qualitative and quantitative risk analysis (ERQI Global Risk Summit, online)
  • Beyond the Heat Map: An Introduction to FAIR for Security Teams (ISACA Sacramento Flagship Conference)
  • Two workshop sessions (The Quantify Workshop, Salt Lake City)
  • Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR (workshop, DEF CON 34 Noob Village, Las Vegas)
  • Did We Solve the Data Problem? Judgment, Beliefs, and Risk in the AI Age (keynote, SiRAcon ’26, Boston)
  • The Future of Cyber Risk Intelligence (FAIR Institute seminar, RSAC 2026, San Francisco)

2025

  • The Six Levers That Actually Move Risk (Hint: It’s Not Just Controls) (FAIRCON25, New York)
  • Case Study: Operationalizing Decision Support in the Age of AI (with Zach Cossairt, FAIRCON25, New York)
  • Change Management: The Mental Shifts That Make Quantification Stick (workshop, Risk Awareness Week, online)
  • Speaking the Language of Business: Cyber Risk Reimagined (panel, Qualys ROCon Americas, Houston)
  • From Gut Feel to Good Data: How AI will Transform Risk Management (Qualys ROCon Americas, Houston)
  • From Gut Feel to Good Data: How AI Can (and Can’t) Transform Risk Management (SF ISACA Fall Conference, San Francisco)
  • Quantifying in the Age of Hallucination: How I Learned to Stop Worrying and Trust the AI (Sometimes) (SiRAcon ’25, Boston)
  • A walk through a FAIR analysis (FAIR Institute seminar, RSAC 2025, San Francisco)

2024

  • Getting Started with FAIR (with Rob Moore and AJ Anand, FAIRCON24)

2022

  • Case Study: Five Objections to FAIR and How to Overcome Them (with Prashanthi Koutha, FAIRCON22)
  • Why is FAIR worth it for organizations? A Fireside Chat with FAIR Institute Members (FAIR Institute seminar, RSA Conference 2022, San Francisco)
  • How do I get started? Easing your company into a quantitative cyber risk program (I-4 2022)

2021

  • Fireside Chat: How to Get a FAIR Program Off the Ground (FAIRCON21)
  • Rethinking Cyber Risk Responses (workshop, Risk Awareness Week, online)
  • Operational Risk: lessons in resilience and quantification (panel, CIISec LIVE, online)
  • Baby Steps: Easing Your Company into a Quantitative Cyber Risk Program (SIRAcon ’21, online)
  • Building and Running a Quantitative Risk Management Program: Lessons from the Field (panel, ISSA Central Ohio InfoSec Summit, online)

2020

  • Case Study: How FAIR Analyses Support Decision-Making at Netflix (FAIRCON 2020, online)
  • Expert Estimation for Risk Analysis: A Debate (panel I moderated, SIRAcon 2020, online)

2019

  • Incentivizing Better Risk Decisions: Lessons from Rogue Actuaries (SIRAcon 2019, Cincinnati)
  • Expert Estimation and Calibration (pre-conference workshop, SIRAcon 2019, Cincinnati)
  • Getting Started with a Quantitative Cyber-Risk Program (Peer2Peer discussion, RSA Conference 2019, San Francisco)

2018

  • How to Lie with Statistics, Information Security Edition (CircleCityCon 5.0, Indianapolis)
  • Quantitative Information Security Risk Management (Birds of a Feather discussion, RSA Conference 2018, San Francisco)
  • Issues of Quantifying Risk around Identity and Access Management (IAM) (panel, RSA Conference 2018, San Francisco)
  • Becoming a security bookie: Improving your estimations with calibration (Peerlyst Live, San Francisco)
  • Cybersecurity Aspects of Blockchain and Cryptocurrency (PRMIA round table, San Francisco)
  • Crowdsourced Probability Estimates: A Field Guide (SIRAcon 2018, Seattle)

2017

  • Should I Pay or Should I Go? Game Theory and Ransomware (BSides San Francisco)

2016

  • Ransomware & Game Theory: To Pay, or Not to Pay? (NBTcon 3, San Francisco)
  • Measuring DDoS Risk with FAIR (the first FAIRcon, Charlotte)
  • Can Cyber Extortion Happen to You? Practical Tools for Assessing the Threat (BSides Seattle)

2015

  • How to Lie with Statistics, Information Security Edition (BSides San Francisco)

2014

  • How to Improve Your Risk Assessments with Attacker-Centric Threat Modeling (SF ISACA Fall Conference, San Francisco)

Podcasts

  • Risk Is Our Business with Michael Rasmussen, 2026, an hour on the book
  • CISO Confidential with Saket Modi, 2026, on the human side of breach response
  • GRC Engineer with Ayoub Fandi, 2025, on quantification as a mindset shift for GRC
  • Risk Is Our Business with Michael Rasmussen, 2025, heatmaps, histograms, and star charts
  • GRC & Me with Chris Clarke, 2023, on moving from colored charts to quantification

Speaker kit

Organizers usually ask for a bio and a photo, so both are here to copy or download. The speaker kit puts both bios, my topics and a headshot on one page.

Short bio

Tony Martin-Vegue has worked in security and risk for more than 25 years. He built the cyber risk quantification program at Netflix, wrote From Heatmaps to Histograms (Apress, 2026) and started CRQ Bootcamp, which teaches risk quantification in live classes. Through his firm, 95 Risk Advisory, he helps companies build programs of their own.

Long bio

Tony Martin-Vegue has worked in security and risk for more than 25 years. He spent six years at Netflix, where he built and led the company’s cyber risk quantification program, and in 2025 he founded 95 Risk Advisory to help other companies build their own. Recent clients include some of the biggest companies in AI and finance.

He wrote From Heatmaps to Histograms: A Practical Guide to Cyber Risk Quantification (Apress, 2026), a book for anyone who wants to start measuring cyber risk in dollars. He also started CRQ Bootcamp, where he and Apolonio Garcia teach the book’s methods in live classes. He chairs the FAIR Institute’s San Francisco chapter, and the Institute gave him its FAIR Ambassador Award in 2020. He’s an Executive Fellow at the Cyentia Institute and a contributor to the 2026 Verizon Data Breach Investigations Report.

He has spoken at RSA Conference, DEF CON, FAIRcon and SiRAcon, and at several BSides and ISACA conferences. He lives in the San Francisco Bay Area.

Downloads

To book a talk, send me a note through the contact page with the event, the date, the audience and the format you have in mind.