Definitions

Cyber risk quantification, explained.

Cyber risk quantification (CRQ) is the practice of expressing an organization's cyber risk in financial terms — typically as annualized loss exposure in dollars — instead of heat maps or high/medium/low labels. It exists so security decisions can be weighed like every other business decision: against cost, in the board's own unit.

How it works, mechanically

Most credible CRQ implementations follow FAIR (Factor Analysis of Information Risk): estimate how often a loss event is likely to occur, estimate the magnitude if it does, and run the two distributions through a Monte Carlo simulation. The output is not one number but a range — a typical year (p50), a bad year (p90) — expressed in dollars, which is the only unit a board, an insurer, and a budget all speak.

The honest problem with CRQ dashboards

A dollar figure is only as good as what feeds it, and most CRQ platforms feed on questionnaires and industry averages — then present the output with more confidence than the inputs deserve. Two failure modes matter. First, provenance blur: the dashboard shows “$2.3M annualized exposure” without saying which parts were measured and which were assumed. Second, the vanishing act: the number is alive only while you pay — cancel, and the evidence behind every figure you ever reported to your board goes dark.

What a re-checkable alternative looks like

CyberTwin's approach: every figure carries its provenance in-line — PROVEN when it was parsed from a configuration you uploaded (1,917+ deterministic checks across 37 vendors), MODELED when it was inferred from your declared answers. The FAIR simulation runs on that labeled foundation, scores 24 frameworks, and emits dated, Ed25519-signed proofs — files you keep, which an auditor or insurer can re-verify in their browser at /verify without trusting us. No agents, no scans; an unpriced asset reads “not valued yet”, never $0.

How to evaluate any CRQ product

Four questions cut through every demo. Can it show, per figure, what was measured versus assumed? Can a third party re-check a number without vendor access? What happens to your evidence when you cancel? And does it ever print a dollar it cannot source? Ask them of us too — the demo is open, and the sample proof is downloadable before you pay anything.