Realized 2nd edition was out and switched to that one for book club.
informative medium-paced

Difficult book to review as it was not for me. I think I would have preferred how to measure anything.  But even in saying that I still got a lot out of the book in both how to mathematically approach problem, especially the calibration chapter but also how to conceptualise likelihood, risk and issues as a whole
informative slow-paced

First, this was just a good read on how to get started on quantifying and managing information security risk. If your organization needs some improvement in this area, start here.

Secondly, apparently I'm late to the game because this book is now on a dozen desks in my office and nobody told me it was all the rage!