A Statistician Addresses Risk in Information Security

Someone sent an email to Andrew Gelman regarding the discussion around quantitative and qualitative risk management (nope, wasn’t me). He has some important things to say about quantifying risk, garbage-in, garbage-out, etc…