Cyber Risk Quantification (CRQ) is the practice of expressing cyber risk as money — a probability of loss multiplied by the size of that loss — instead of a red/amber/green heatmap. It turns "we have 47 critical vulnerabilities" into "we face an expected €1.8M in annual loss," so boards, CFOs and CISOs can weigh cyber risk against budgets, insurance and regulatory fines on the same terms as every other business risk.
Cyber Risk Quantification in one box
- Definition: cyber risk expressed in financial terms (money), not qualitative scores
- Core formula: Annualised Loss Expectancy (ALE) = Annualised Rate of Occurrence (ARO) × Single Loss Expectancy (SLE)
- Common method: FAIR (Factor Analysis of Information Risk) + Monte Carlo simulation
- Output: Expected Annual Loss, a loss-exceedance curve (tail risk), and — in the EU — statutory liability under NIS2, GDPR and DORA
What is Cyber Risk Quantification?
Traditional risk registers rank threats as "high", "medium" or "low". That is fine for a technical audit, but it collapses at the boardroom door: a board cannot compare a page of amber cells against a €500k security budget, a €10M NIS2 fine ceiling, or a cyber-insurance premium. Cyber Risk Quantification fixes the unit of measure — it puts cyber risk in euros.
The discipline borrows from actuarial science and operational-risk modelling. The most widely used open standard is FAIR (Factor Analysis of Information Risk), which decomposes risk into how often a loss event happens (frequency) and how much it costs when it does (magnitude). Multiply the two and you get an expected annual loss.
The core formula: ALE = ARO × SLE
Every CRQ engine, however sophisticated, rests on one identity:
- ARO (Annualised Rate of Occurrence) — the probability that at least one damaging cyber event happens in a year. Good models derive this from real-world exploitation signals, not gut feel.
- SLE (Single Loss Expectancy) — the total cost of one such event: downtime and idle labour, business interruption, forensics and legal, ransom, and regulatory penalties.
- ALE (Annualised Loss Expectancy) — ARO × SLE. The headline "Expected Annual Loss" figure a board can act on.
Because a single point estimate hides the tail, mature CRQ tools run a Monte Carlo simulation — thousands of simulated years — to produce a loss-exceedance curve: "most years you lose nothing; in a bad 1-in-100 year you lose €X." That tail is often what actually matters for capital and insurance decisions. For why this beats a heatmap, see why boards are dropping traffic-light heatmaps for Expected Annual Loss.
Three ways to quantify cyber risk
CRQ tools differ mainly in what data drives the model. There are three broad schools:
| What drives it | Trade-off | |
|---|---|---|
| Top-down (actuarial) | Historic insurance / reinsurance loss data across many companies | Fast, no technical input — but backward-looking and blind to your actual live exposure |
| Bottom-up (asset/scenario) | Internal asset inventories, control-maturity data, custom scenarios | Granular — but heavy to implement (integrations, data collection) |
| Telemetry-based | Your live external attack surface, cross-referenced with active exploit data (EPSS, KEV) | Forward-looking and threat-current — reflects what attackers can actually reach today |
None is "wrong" — they answer different questions. Actuarial models are strong for insurers pricing a portfolio; telemetry-based models are strong for an operator who needs to know their exposure right now. For a side-by-side of the leading platforms, see our comparison of Kovrr, Squalify and Nisura.
Why Cyber Risk Quantification now?
- Boards demand a number. "Are we secure?" has become "how much are we exposed to, and does our spend reduce it?" — a question only money can answer.
- EU regulation made it personal. Under NIS2, management bodies can be held personally liable for cyber-risk governance (see NIS2 board liability). A defensible, quantified risk figure is the evidence that governance happened.
- Insurance is repricing. Claims-based views cap and understate true exposure — see the illusion of insured risk. CRQ lets you right-size cover instead of guessing.
CRQ and EU regulatory liability
In Europe, a loss figure is only half the story — the other half is statutory liability. A complete CRQ picture attaches the governing regime to your number: NIS2 (up to €10M or 2% of turnover for essential entities), GDPR (up to €20M or 4%), and DORA for financial entities. Nisura's engine size-gates each regime to your sector and size, so the euro figure is board-ready and defensible — not a generic US-style dollar estimate. See NIS2 vs DORA for how the regimes interact.
How to get started
You don't need a six-month consulting engagement to see a first number.
- Check which EU regime governs you (essential, important, or GDPR-only).
- Run the free cyber risk calculator to turn your external exposure into an Expected Annual Loss in euros.
- Explore how the Nisura framework models it continuously and maps it to NIS2 Article 21 evidence.
Sources & references
- The Open Group — FAIR (Factor Analysis of Information Risk), the open standard for quantitative risk analysis.
- FIRST.org EPSS (Exploit Prediction Scoring System) and CISA KEV (Known Exploited Vulnerabilities) — the exploitation signals behind telemetry-based ARO.
- Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2022/2554 (DORA) — statutory liability ceilings.
General information, not legal or financial advice. Model outputs are estimates for decision support; confirm regulatory applicability with qualified counsel.