A round of updates to the Nisura cyber risk quantification engine — all aimed at one thing: making the euro figure more decision-useful for the board. You can now model the ROI of a security investment before you make it, price resilience (not just prevention), read sharper board-level metrics, and prioritise vulnerabilities the way CISA does. Here's what changed and why it matters.
1. Model the ROI before you spend — the decision simulator
The hardest question a CISO gets from a CFO isn't "are we secure?" — it's "if we spend on this, how much risk does it actually remove?" Nisura now answers it directly. The new What-if panel lets you toggle any security control and instantly see how your Expected Annual Loss would change — the difference measured in euros, against your current controls.
Enter the annual cost of a change and it becomes an expected-value ROI: X euros of loss avoided per euro spent. We never invent control costs — ROI only appears once you supply the number — so the output stays honest and defensible.
2. Price resilience, not just prevention
Most risk models only reward controls that lower the odds of a breach. But backups, a tested incident-response plan and a DR/business- continuity plan don't change whether you're hit — they change how much it costs when you are. Nisura now models these as a separate resilience & recovery tier that reduces the recoverable loss (downtime, business interruption, forensics) rather than the likelihood — cited to the IBM Cost of a Data Breach report, NIST SP 800-34 and the Sophos State of Ransomware.
The result: your remediation options now split cleanly into reduce the odds and reduce the damage — the two levers a board actually pulls.
3. Sharper board metrics
We relabelled the loss-exceedance output to the numbers executives and insurers use directly:
- Average annual loss — your expected loss per year.
- Annual event likelihood — the chance of at least one incident this year.
- 1-in-100 tail — the worst-case year that actually drives capital and insurance decisions.
Same rigorous Monte-Carlo engine underneath (see why we price a distribution, not a single number) — just named the way the boardroom reads it.
4. Prioritise the way CISA does — SSVC + CVSS 4.0
A CVSS severity score tells you how bad a vulnerability could be in theory; it doesn't tell you whether to drop everything and fix it. CISA's SSVC (Stakeholder-Specific Vulnerability Categorization) does — it's a decision, not a score: Act, Attend or Track, based on whether a flaw is actively exploited, mass- automatable, and total in impact.
Following NVD's June 2026 rollout of CISA-ADP SSVC data, Nisura now ingests those decision points and surfaces them on your findings, elevating an actively-exploited, automatable vulnerability to critical in the remediation backlog. We also added CVSS 4.0 to the score chain so newer CVEs are read correctly. This reinforces how the engine already thinks — prioritising by real-world exploitation (EPSS, CISA KEV), not theoretical severity. We surface CISA's published decision points faithfully and label our own indicative tier as exactly that — we don't put words in CISA's mouth.
See it on your own exposure
All of this runs on your live external attack surface, priced in euros and mapped to NIS2, GDPR and DORA. Run the free cyber risk calculator, or see how Nisura compares to the other CRQ platforms in our Kovrr vs Squalify vs Nisura breakdown.