// Offer pack
The quantified cyber risk offer, ready to take to your finance and audit teams.
This page holds everything needed to scope, fund, and justify a FAIR-informed cyber risk assessment. Download the proposal template, the budget narrative, and the compliance matrix, then send them to us with your scope and we will return a fixed fee in writing.
Reviewed by a Dephiant advisor on
// Downloads
Three documents, editable and ready for your own headings.
Quantified cyber risk assessment proposal template
Purpose, scope, method, loss scenarios, deliverables, timeline, commercial terms, assumptions, and acceptance criteria.
Quantified cyber risk budget narrative
A cost table by category with a written justification for every line, plus the commercial principles we hold to.
Every figure in these documents is a bracketed placeholder. We do not publish modelled exposure numbers or fees that have not been agreed with a client in writing.
// What gets modelled
The standard starting set of loss scenarios.
Ransomware encrypts core production systems
A threat actor gains access through an exposed service or a compromised credential, moves laterally, and encrypts the systems the business depends on to trade.
Loss forms considered: Business interruption and lost revenue, Incident response and forensics cost, Recovery and rebuild labour, Regulatory and legal cost where personal data is affected.
Cloud storage or database exposes regulated data
A misconfiguration or over-permissive identity makes a data store readable outside the intended boundary, and regulated records are copied.
Loss forms considered: Breach notification and credit monitoring, Regulatory fines and supervisory engagement, Legal defence and settlement, Customer churn and brand repair.
A critical vendor or service provider is compromised
A supplier that holds data or operates part of the delivery chain suffers an incident that disrupts service or exposes records the organisation is accountable for.
Loss forms considered: Service disruption and contractual credits, Customer notification and support cost, Replacement or dual-running supplier cost.
Business email compromise diverts payment
An attacker takes over or impersonates a finance or executive mailbox and redirects a legitimate payment or payroll run.
Loss forms considered: Direct fraud loss, Investigation and recovery effort, Audit and control remediation.
Insider exfiltrates intellectual property
A departing or privileged user copies source code, models, customer lists, or pricing data to a personal account or device.
Loss forms considered: Competitive loss and margin erosion, Legal and investigative cost, Contractual notification where customer data is involved.
Identity provider or administrator account takeover
Multifactor bypass, help desk social engineering, or session theft gives an attacker administrative control of the identity platform.
Loss forms considered: Wide business interruption, Mass credential reset and reissue, Forensic scope expansion across every connected application.
// What gets tracked
Indicators, thresholds, and a refresh cycle.
Known exploited vulnerability exposure window
Median days between a vulnerability appearing on the CISA Known Exploited Vulnerabilities catalogue and remediation on internet-facing assets.
Cadence: Monthly.
Privileged accounts without phishing-resistant authentication
Count and percentage of administrative accounts in the identity platform that are not protected by a hardware or platform authenticator.
Cadence: Monthly.
Verified restore coverage for tier one systems
Percentage of tier one systems with a restore test completed and evidenced inside the agreed test interval.
Cadence: Quarterly.
Critical vendors with current assurance evidence
Percentage of critical suppliers with an in-date assurance report or completed questionnaire and a recorded owner.
Cadence: Quarterly.
Detection coverage against priority techniques
Percentage of the priority attack techniques in the threat model with an active, tested detection or preventive control.
Cadence: Quarterly.
Modelled annualised exposure trend
Change in the aggregate modelled annualised loss exposure range since the previous measurement cycle.
Cadence: Quarterly.
Control effectiveness sample pass rate
Pass rate of sampled control tests across the controls that carry the largest modelled risk reduction.
Cadence: Quarterly.
Refresh options
Quarterly refresh
Indicators are refreshed monthly where the data supports it, the model is re-measured each quarter, and a board summary is issued within ten business days of quarter end.
Semiannual refresh
Indicators are refreshed quarterly and the model is re-measured twice a year, which suits organisations with a stable estate and an annual funding cycle.
Annual refresh with event triggers
The model is re-measured once a year and out of cycle after a material change such as an acquisition, a new regulated market, a major platform migration, or a significant incident.
// Board report
The report your directors receive each cycle.
- Executive position in one page
- Top loss scenarios with exposure ranges and the assumptions behind them
- Movement since the previous cycle and what caused it
- Key risk indicators against agreed thresholds
- Funded work and the exposure reduction it is expected to deliver
- Decisions requested from the board with dates
// Commercials
How this is priced.
A first quantification engagement is scoped as an Enterprise Advisory phase, which typically starts around $25,000. Quarterly re-measurement can sit inside a Sentinel annual agreement or a Vigilance retainer. Every scope is fixed fee and written before work begins, and there is no contingent or percentage based pricing.
Send us your scope and we will return a fixed fee.
Tell us the decisions the model must support and the platforms in scope. We will confirm the loss scenarios, the indicator set, and the refresh cycle in writing before any work starts.