Skip to main content

Stop reporting risk
in red, amber, green.

Strategic · Independent · Resilient

A heat map tells your board that something is "high". It does not tell them how much money is at stake, or whether the control you are about to fund is worth its cost. Cyber risk quantification replaces colour with currency — expressing exposure in euros and probabilities your CFO can actually work with.

All Services

Cyber Risk Quantification

Cyber risk quantification and FAIR analysis for board-level decisions

Most security programmes still communicate risk qualitatively. That works until someone asks the obvious question: how much would this actually cost us, and is the mitigation worth it? Quantification answers that. We use FAIR — Factor Analysis of Information Risk, the only international standard for quantifying information risk in financial terms — to decompose a risk into loss event frequency and loss magnitude, calibrate each factor with your own data and structured expert estimation, and run the result through Monte Carlo simulation. The output is a loss exceedance curve: the probability of exceeding any given loss over a year. That is the format investment committees, insurers, and regulators under DORA already understand. We are not selling a tool. Every engagement is fixed in scope and leaves behind a model your team can rerun without us.

01

FAIR Risk Assessment

A quantified analysis of a defined risk scenario — ransomware, third-party breach, insider data loss, cloud outage — decomposed using the FAIR taxonomy into threat event frequency, vulnerability, and primary and secondary loss magnitude. Each factor is calibrated with your incident history, industry loss data, and structured expert estimation rather than guesswork. Deliverables: quantified scenario model, loss exceedance curve, and a written rationale for every input so the numbers survive challenge.

02

Risk Quantification Programme

For organisations moving beyond one-off analyses. We establish the scenario library, calibration standards, and reporting cadence that let your team quantify risk repeatably. Includes calibrated-estimation training for the people who will supply the inputs — the single biggest determinant of whether the output is credible — plus model governance so results stay defensible over time.

03

Control Cost-Benefit Analysis

Quantification is most useful when it changes a decision. We model the expected loss reduction from a proposed control or investment against its total cost, producing a return-on-control-investment figure. This converts "we should buy this" into a comparison a finance function can evaluate against every other capital request.

04

Board Risk Reporting

Translating quantified output into something a board can act on in ten minutes. We build the reporting format — risk appetite thresholds expressed in currency, top scenarios by expected annual loss, and trend against prior periods — and, where useful, present it alongside your CISO. Boards do not need the model. They need the decision it supports.

05

Risk Appetite Definition

Most risk appetite statements are unusable because they are qualitative — "we have a low appetite for cyber risk" cannot be tested. We help boards express appetite as quantified thresholds: the annual loss they are willing to accept, and the point at which exposure requires escalation. Once appetite is a number, every subsequent risk decision has an objective reference.

06

DORA Quantitative Risk Support

DORA expects EU financial entities to assess ICT risk and, for significant incidents, estimate costs and losses. Qualitative registers do not satisfy that well. We align your quantification approach with DORA Article 8 risk assessment expectations and the incident reporting thresholds, so the same model serves both internal decisions and regulatory evidence.

Standards and methods we work with

FAIRFAIR-CAMMonte Carlo simulationISO 27005NIST SP 800-30DORA Article 8Calibrated estimation

What is your largest risk actually worth?

Most organisations cannot answer that in currency. A single quantified scenario is usually enough to show whether the approach earns its place in your programme — start there rather than committing to a full rollout.