The best cyber risk quantification (CRQ) tool depends on who you are. Insurers and global enterprises need actuarial depth; EU mid-market companies and suppliers need a fast, defensible euro figure mapped to NIS2. Kovrr, Squalify and Nisura sit at three different points on that spectrum. This is an honest, fact-based comparison of what each does well — and who each is really for.

Three approaches at a glance

  • Kovrr: enterprise CRQ platform built on cyber-insurance claims data + deep internal integrations
  • Squalify: Munich Re-backed, top-down actuarial CRQ from reinsurance loss data — zero technical input
  • Nisura: EU-native, telemetry-based CRQ from your live external attack surface, with transparent euro pricing

How to read this comparison

As we cover in what is cyber risk quantification, CRQ tools differ mainly in what data drives the model: historic insurance/reinsurance losses (top-down, actuarial) versus your live technical exposure (telemetry-based). That single choice shapes everything downstream — onboarding effort, who it's for, and what the number actually tells you.

KovrrSqualifyNisura
Primary dataCyber-insurance claims + threat intel + internal dataMunich Re reinsurance loss databaseLive external attack surface + EPSS/KEV exploit data
ApproachBottom-up + top-down, Monte CarloTop-down, Monte CarloTelemetry-based, Monte Carlo loss-exceedance
Input requiredIntegrations + internal data (heavier)Minimal — business profile onlyA domain to scan + business details (self-serve)
Best forLarge enterprises, insurers, portfoliosBoards of large enterprises; insurance viewEU mid-market & NIS2 suppliers; CISOs/CFOs
PricingCustom / enterprise (not public)Custom / enterprise (not public)Published: Mid-Market €4,900/yr, Enterprise from €36,000/yr

Kovrr

Kovrr is a mature, enterprise CRQ platform. Its models run Monte Carlo simulations across thousands of loss scenarios, drawing on proprietary cyber-insurance claims data, threat intelligence, vulnerability databases and a company's own internal data (assets, control maturity). It differentiates systemic, targeted and failure events, and surfaces average annual loss, 1:100 tail risk and event likelihood.

Its real depth is on the enterprise/insurance side: a decision simulator for modelling the ROI of a security investment before you make it, portfolio analysis across many entities, insurance program optimisation (mapping modelled loss to limits, deductibles and tower structures), and continuous control monitoring. It maps to NIST CSF, CIS and ISO, and supports NIS2, DORA and US SEC disclosure.

Best for: large enterprises, cyber insurers and anyone who needs deep, integration-driven modelling and portfolio/insurance views — and can run an enterprise procurement to get it.

Squalify

Squalify is a Munich Re-backed, top-down CRQ platform. The methodology was developed by the world's largest cyber reinsurer to price risk across thousands of companies, and it runs on Munich Re's cyber loss database — data from roughly 100,000 organisations across 130 industries and 80 countries. It combines Monte Carlo simulation with historic loss data, modelling frequency and severity across seven loss components, structured as cause → consequence → cost.

Its signature strength is speed with almost no input: no asset inventories, no threat modelling, no integrations — a business-impact view aimed squarely at the boardroom, backed by reinsurer-grade actuarial data.

Best for: boards and executives who want a fast, actuarially-grounded top-down number without a technical project — especially larger organisations comfortable with a claims-history view of risk.

Nisura

Nisura takes the third path: telemetry-based CRQ built for Europe. Instead of historic claims, it starts from your live external attack surface — a passive scan that maps your exposed vendors, appliances and services, cross-referenced with active exploit data (FIRST.org EPSS and CISA KEV) and current ransomware activity. It then runs the same FAIR / Monte Carlo machinery to produce an Expected Annual Loss and loss-exceedance curve in euros.

What makes it distinct:

Being honest about the trade-off: Nisura is not an actuarial claims platform and does not model insurance towers or cross-portfolio systemic risk — that is the enterprise/insurer domain Kovrr and Squalify serve. If you need those, they are the right call.

Best for: EU mid-market companies, NIS2-scoped entities and suppliers that must prove their posture — teams that want a fast, transparent, regulation-aware euro figure driven by their real, current exposure.

How to choose

Sources

Competitor details are drawn from each vendor's public materials as of August 2026 and may change — verify current capabilities with the vendor. This comparison is provided in good faith for buyer orientation.