// Quantified Cyber Risk Management

Cyber risk stated in dollars, not colours.

Heat maps do not settle budget arguments. We build FAIR-informed loss scenarios, quantify the financial exposure behind each one, and translate the result into investment options your executives and directors can actually choose between.

Reviewed by a Dephiant advisor on

A recent engagement is written up in full, including the six modelled scenarios and the outcomes, in the quantified cyber risk case study.

// Methodology

Four steps from unclear exposure to a funded decision.

01 · Frame

We agree the decisions the programme must support, the risk appetite leadership will stand behind, and the data already available. Scope is written down before any modelling begins.

  • Security risk management standard
  • Written risk appetite statement
  • Decision register and scope note

02 · Model

We build threat models across product, cloud, identity, API, AI, and software supply chain scope, then convert them into loss-event scenarios with frequency and magnitude ranges.

  • Threat models for in-scope systems
  • Loss-event scenarios with exposure ranges
  • Sensitivity analysis on every key assumption

03 · Quantify

Each scenario carries a stated confidence level and the assumptions behind it. Business-impact analysis ranks exposure so investment can be prioritised against the largest financial risk rather than the loudest one.

  • Ranked enterprise risk view with named owners
  • Business-impact analysis
  • Investment options with expected loss reduction

04 · Report and operate

We stand up the indicators and reporting cadence, hand over self-service templates so business owners can run their own assessments, and re-measure each quarter.

  • Key risk, control, and performance indicators
  • Board and executive reporting pack
  • Self-service assessment templates and risk acceptance criteria

// Board reporting

What your board receives.

Directors are accountable for cyber risk oversight, so the reporting has to survive questions from auditors, insurers, regulators, and enterprise customers. Every number we present carries its assumptions and its confidence level.

See our board cyber metrics guide

Risk stated in money

Each material scenario carries an annualised loss range with stated confidence, so directors can compare cyber risk against other enterprise risks on the same terms.

Fundable options, not warnings

Every recommendation is paired with its cost and the expected reduction in exposure, which lets the board choose a level of residual risk deliberately.

One set of numbers

The same indicators appear in the board pack, the risk committee, the audit response, and the insurer submission, which removes the contradictions that erode trust.

Evidence that holds up

Assumptions, data sources, and confidence levels are documented, so the analysis survives challenge from auditors, regulators, insurers, and enterprise customers.

// Deliverables

What you keep when we finish.

  • Security risk management standard, risk appetite statement, and assessment playbooks
  • FAIR-informed quantified risk assessments with financial exposure ranges and sensitivity analysis
  • Key risk indicators, key control indicators, and programme performance indicators
  • Threat models for product, cloud, identity, API, AI, and software supply chain scope
  • Self-service risk assessment templates and risk acceptance criteria for business owners
  • Executive and board reporting that states risk in business and financial terms
  • Targeted risk campaigns across cloud estates, SaaS portfolios, privileged access, or third parties

// Who this is for

Where it fits best.

  • Enterprises building or maturing a security risk management function
  • Product-led organizations, including open source, SaaS, and cloud providers, that need secure-by-design risk governance
  • Regulated businesses answering board, auditor, insurer, and customer questions about risk posture
  • Public sector and higher education programmes prioritizing limited budget against real exposure

// Investment

A first quantification engagement is scoped as an Enterprise Advisory phase, which typically runs from $25,000 per phase. Quarterly re-measurement and indicator upkeep can be carried inside a Sentinel annual agreement or added to a Vigilance retainer. Every scope is fixed fee and written before work begins.

Review pricing tiers

// Questions

Common questions.

Do we have to adopt FAIR to use this?

No. We use FAIR-informed methods because they hold up under challenge, but the output is mapped to whatever framework you already report against, including NIST CSF, ISO 27001, and your own risk register.

What if our data is incomplete?

Quantification works with ranges and stated assumptions. We document the confidence behind every input and show where better data would change the answer, rather than presenting a single false number.

Does this replace our qualitative risk register?

It sits alongside it. Qualitative input is still useful for surfacing issues, and we keep it for quality and engineering improvements while quantification drives funding decisions.

Who is this delivered by?

A senior risk practitioner works directly with your security leadership and the business owners involved, not a handed-down delivery team.

Put a number on your largest exposure.

Tell us your sector, size, region, and compliance obligations, and we will return a scoping note covering the scenarios worth quantifying first.