Cyber Risk Quantification (CRQ) is the practice of expressing cyber risk as money — a probability of loss multiplied by the size of that loss — instead of a red/amber/green heatmap. It turns "we have 47 critical vulnerabilities" into "we face an expected €1.8M in annual loss," so boards, CFOs and CISOs can weigh cyber risk against budgets, insurance and regulatory fines on the same terms as every other business risk.

Cyber Risk Quantification in one box

  • Definition: cyber risk expressed in financial terms (money), not qualitative scores
  • Core formula: Annualised Loss Expectancy (ALE) = Annualised Rate of Occurrence (ARO) × Single Loss Expectancy (SLE)
  • Common method: FAIR (Factor Analysis of Information Risk) + Monte Carlo simulation
  • Output: Expected Annual Loss, a loss-exceedance curve (tail risk), and — in the EU — statutory liability under NIS2, GDPR and DORA

What is Cyber Risk Quantification?

Traditional risk registers rank threats as "high", "medium" or "low". That is fine for a technical audit, but it collapses at the boardroom door: a board cannot compare a page of amber cells against a €500k security budget, a €10M NIS2 fine ceiling, or a cyber-insurance premium. Cyber Risk Quantification fixes the unit of measure — it puts cyber risk in euros.

The discipline borrows from actuarial science and operational-risk modelling. The most widely used open standard is FAIR (Factor Analysis of Information Risk), which decomposes risk into how often a loss event happens (frequency) and how much it costs when it does (magnitude). Multiply the two and you get an expected annual loss.

The core formula: ALE = ARO × SLE

Every CRQ engine, however sophisticated, rests on one identity:

Because a single point estimate hides the tail, mature CRQ tools run a Monte Carlo simulation — thousands of simulated years — to produce a loss-exceedance curve: "most years you lose nothing; in a bad 1-in-100 year you lose €X." That tail is often what actually matters for capital and insurance decisions. For why this beats a heatmap, see why boards are dropping traffic-light heatmaps for Expected Annual Loss.

Three ways to quantify cyber risk

CRQ tools differ mainly in what data drives the model. There are three broad schools:

What drives itTrade-off
Top-down (actuarial)Historic insurance / reinsurance loss data across many companiesFast, no technical input — but backward-looking and blind to your actual live exposure
Bottom-up (asset/scenario)Internal asset inventories, control-maturity data, custom scenariosGranular — but heavy to implement (integrations, data collection)
Telemetry-basedYour live external attack surface, cross-referenced with active exploit data (EPSS, KEV)Forward-looking and threat-current — reflects what attackers can actually reach today

None is "wrong" — they answer different questions. Actuarial models are strong for insurers pricing a portfolio; telemetry-based models are strong for an operator who needs to know their exposure right now. For a side-by-side of the leading platforms, see our comparison of Kovrr, Squalify and Nisura.

Why Cyber Risk Quantification now?

CRQ and EU regulatory liability

In Europe, a loss figure is only half the story — the other half is statutory liability. A complete CRQ picture attaches the governing regime to your number: NIS2 (up to €10M or 2% of turnover for essential entities), GDPR (up to €20M or 4%), and DORA for financial entities. Nisura's engine size-gates each regime to your sector and size, so the euro figure is board-ready and defensible — not a generic US-style dollar estimate. See NIS2 vs DORA for how the regimes interact.

How to get started

You don't need a six-month consulting engagement to see a first number.

Sources & references

General information, not legal or financial advice. Model outputs are estimates for decision support; confirm regulatory applicability with qualified counsel.