CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Risk coverage/Cyber risk quantification

What we solve

Cyber risk quantification

Cyber exposure expressed in dollars, using Open FAIR — so a control investment can be argued against the loss it removes, and a risk acceptance can be signed by someone who understood what they were accepting.

METHOD
Open FAIR taxonomy, end to end
OUTPUT
Loss exceedance curve in USD, with assumptions on the record
BUILT FOR
The CRO, the CFO, the CISO and the board

FALCONRY360 IN PRACTICE

See the operating layer behind the service.

The platform gives the client a current view of the work, not only an end-of-month report. Scope, owners, evidence and actions remain visible between service reviews.

Illustrative Falconry360 risk quantification workspace showing exposure, scenarios and treatment priorities.Illustrative platform view
The quantification method is held in the platform with assumptions, evidence, scenarios and decisions—not left in a one-off model.

The problem with the heat map

A heat map cannot be compared with a budget request. A loss distribution can.

Almost every cyber risk register in this region is scored on a five-point scale. Those scores cannot be added, cannot be compared across categories, and cannot be set against a number in a budget. So the register is presented, the board nods, and the investment decision is made on instinct or on whoever argued hardest.

The failure is structural, not cosmetic. Ordinal scores are labels, not quantities. Two amber risks do not make a red one. A risk that moved from 3 to 4 has not doubled. And when a CRO is asked to aggregate cyber with credit, market and operational risk — all of which are already measured in currency — cyber is the one that cannot join the conversation.

How Open FAIR decomposes it

Risk is broken down until what remains is something a person who knows the estate can actually estimate. Nobody can sensibly answer "what is our ransomware risk". Most people can answer "how many credential-phishing attempts reach a privileged user in a year".

Riskannual loss exposure, USDLoss event frequencyevents per yearLoss magnitudeUSD per eventThreat event frequencyattempts per yearVulnerabilityproportion that succeedPrimary lossresponse, replacement, lost revenueSecondary lossfines, notification, customer attritionESTIMATED AS CALIBRATED RANGES, NOT SINGLE POINTSEach bottom factor is given a minimum, most likely and maximum by people who know the estate. Monte Carlo does the rest.
The Open FAIR taxonomy as implemented in the Anticipate pillar.

How a scenario is built

Six steps, run as working sessions with your people rather than as a modelling exercise done to you.

Scope the scenario

A specific asset, a specific threat, a specific effect. "Ransomware on the core banking platform causing seven days of degraded service", not "cyber risk".

Calibrate the estimators

The people giving estimates are trained to give ranges they are 90% confident in. Calibration training measurably reduces overconfidence, and it is the step most implementations skip.

Estimate the factors

Minimum, most likely and maximum for each bottom factor, with the evidence behind each recorded — incident history, control test results, sector loss data, supplier disclosures.

Run the simulation

Monte Carlo across the distributions, typically tens of thousands of iterations, producing a full range of annual loss outcomes rather than a single number.

Review and challenge

Results returned to the estimators. Where the output looks wrong, the assumption behind it is visible and can be argued with — which is the point.

Maintain it

Scenarios are re-run when controls change, incidents occur or the estate moves. A quantification done once is a slide; done continuously it is a management tool.

What comes out

A loss exceedance curve: the probability of losing more than a given amount in a year.

PROBABILITY OF EXCEEDANCE100%75%50%25%0%95th percentilethe number the board should be told0$2m$8m$25m$60mANNUAL LOSS, USD
Indicative output. Every figure traces to the scenario, the parameters and the person who calibrated them.

How a board reads it

Left to right is money. Bottom to top is probability. The curve answers the two questions a board actually asks: how bad could it get, and how likely is that.

How it changes the decision

A proposed control moves the curve. The value of the investment is the area between the two curves — expressed in dollars, over a stated period, with the assumptions open to challenge. That is an argument a CFO can engage with.

What it is used for

Quantification is not an end in itself. These are the decisions it exists to support.

Control investment cases
Spend argued against exposure removed rather than against a maturity score. Competing proposals compared on return, so the larger reduction wins rather than the better presentation.
Risk acceptance
A residual position stated in dollars, with the probability attached, so the person signing knows the size of what they are accepting. This is the single biggest improvement in governance quality most clients see.
Appetite and tolerance
Board appetite set as a monetary statement and decomposed into tolerances by service, asset class and risk type — measurable rather than aspirational.
Board and committee reporting
Cyber reported in the same currency as every other risk on the agenda, which is what allows it to be prioritised against them instead of beside them.
Portfolio prioritisation
Where the estate carries dozens of exposures, the ranking is by quantified loss rather than by severity score, which reliably reorders the list.
Cyber insurance
Limits and retentions tested against the modelled loss distribution, so cover is bought against exposure rather than against last year's premium.
Third-party and concentration decisions
Supplier and cloud concentration expressed as exposure, which turns an abstract dependency argument into a number.
Regulatory and supervisory engagement
Supervisors across the region increasingly expect risk to be evidenced rather than asserted. A documented method with visible assumptions is a stronger position than a colour.
Transaction and portfolio oversight
For sovereign funds and holding companies, a comparable exposure basis across portfolio companies that each run their own security function.

What you need to start

Less than most people assume. The blocker is usually ownership, not data.

  • An asset picture. Not a perfect CMDB — the crown jewels, the services they support, and who owns them. The platform builds this as you go.
  • Incident history. Whatever exists, however incomplete. Three years of tickets is more useful than nobody thinks.
  • Control test results. Existing audit findings, assessment outputs and testing reports, which inform the vulnerability factor.
  • Four to six people who know the estate. Calibrated estimators from security, technology, operations and the business. Not a consultant with a spreadsheet.
  • A decision that needs making. Start with a scenario tied to a real question — an investment case, an acceptance, an insurance renewal. Modelling without a decision attached gets abandoned.

The scenario library

Maintained in the Global Libraries by sector, each arriving with its decomposition structure, parameter guidance and calibration notes — so you are tailoring rather than starting blank.

  • Ransomware on a core platform
  • Data exfiltration and notification
  • Third-party processor failure
  • Cloud region loss
  • Insider data theft
  • Business email compromise
  • Payment fraud at scale
  • OT disruption with safety consequence
  • Regulatory examination failure
  • Credential compromise of a privileged account
  • Supply chain software compromise
  • Prolonged availability loss of a customer service

How the libraries are maintained  ·  Sector packs add their own scenarios

What quantification does not do

The risk is false precision. We would rather name it than discover it together.

  • It does not produce a true number. It produces a defensible range built on stated assumptions. Anyone presenting a single figure to two decimal places has misunderstood the method.
  • It does not remove judgement. It relocates judgement to the individual factors, where it can be examined, rather than leaving it buried in a score.
  • It is not a substitute for control work. Quantification tells you where to spend. It does not implement anything.
  • It does not suit every risk. Some exposures are better handled qualitatively, and we will say so rather than model something to justify the method.
  • Garbage in still applies. Uncalibrated estimators produce confident nonsense. That is why calibration is a step, not a footnote.
FalconryX

FalconryX proposes scenario parameters from your incident history, asset criticality and comparable sector loss data, and flags where an estimate sits outside the range its evidence supports. The estimators decide. How it is governed.

How an engagement runs

Weeks 1–2
Scope the first two or three scenarios against decisions you actually need to make. Identify and calibrate the estimators. Pull what asset, incident and control data exists.
Weeks 3–6
Estimation workshops, simulation, review and challenge. First loss exceedance curves, with the assumptions documented against each factor.
Weeks 7–10
Translate into the decision: an investment case, an acceptance recommendation, an appetite statement or an insurance position. Board-ready narrative produced from the platform record.
Ongoing
Scenarios configured in the Anticipate pillar and maintained — re-run on control change, incident or estate change, either by your team or by us under managed services.

The Anticipate pillar in full  ·  What this changes for the CRO  ·  Running it as a managed service

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.