# Zen and the art of not quantifying risk

DevFeed: [Zen and the art of not quantifying risk](<https://devfeed.tech/articles/zen-and-the-art-of-not-quantifying-risk-37136.md>)

Original publisher: [Read original article](<https://shostack.org/blog/zen-and-the-art-of-not-quantifying-risk/>)

Author: Adam

Published: 2021-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Development](<https://devfeed.tech/topics/development.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [development](<https://devfeed.tech/tags/development.md>), [dialog](<https://devfeed.tech/tags/dialog.md>), [meetings](<https://devfeed.tech/tags/meetings.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article argues that threat modeling should not focus on producing precise risk numbers. Instead, security teams should work with development and operations on prioritization, using simpler relative sizing when appropriate. This approach can reduce conflict and help address easily fixed lower-priority issues alongside larger changes.

## Source excerpt

Many people want their threat modeling work to produce risk numbers, and in this post you'll learn why that's a mistake.