Found in 2 comments on Hacker News
collingreene · 2017-10-29 · Original thread
If you like that book he wrote one about applying those ideas to this exact problem! https://www.amazon.com/How-Measure-Anything-Cybersecurity-Ri...

I've never managed to make the effort to apply his ideas with much rigor but they are definitely appealing and possibly better than the alternative of "maybe nothing".

Fresh book recommendations delivered straight to your inbox every Thursday.