Cyber and IT Risk Quantification

If you can’t measure your risk, you can’t manage it.

We measure cyber and IT risk in financial terms. Security findings become a figure your investment committee or board can act on.

Priced
Cyber risk as a number you can take to the board
Pre-deal
Know the exposure before the capital is committed
Defensible
A figure that holds up to the first hard question
Ongoing
See what moved across the portfolio each quarter

Whatever decision you’re making, there’s a number behind it.

01

Target Screening

An early read on a target’s cyber exposure before diligence budget is committed.

Learn more
02

Transaction Due Diligence

A full assessment of what a cyber incident could cost, built for the investment committee decision.

Learn more
03

White Label Supply

Advisory firms offer quantified cyber risk under their own brand, without building the capability in-house.

Learn more
04

Portfolio Monitoring

Quarterly re-quantification keeps exposure figures current across a portfolio, not only at close.

Learn more

Built for the decision you’re making, not a generic audit.

Speed

Screen a full shortlist, not just the front runner

No target cooperation needed to start, so several candidates can be reviewed in parallel instead of the one or two names a traditional review has time for.

Clarity

Bring a number the room will accept

Every figure lands in money terms, with a realistic case and a bad case, and is reviewed before delivery, so it holds up against the first hard question in the committee meeting.

Consistency

Keep exposure current, not a one-time snapshot

Re-quantify portfolio companies every quarter and see what moved, instead of relying on a diligence report from two years ago.

Every figure is produced on Risqua, not in a spreadsheet.

Model

Financial exposure modelling

Each scenario runs thousands of Monte Carlo iterations to a probable annual loss and an uncertainty range: a realistic case and a bad case, never a single point.

Decision

Treatment ROI

Current exposure set against residual exposure, control cost, and expected reduction, so a budget line is weighed against what it actually removes.

Report

Board-ready reporting

Governance documentation aligned to NIS2, DORA, the SEC Cyber Rule, and ISO 27005, generated from the same run.

CyberLab executive simulation preview: annual loss expectancy and tail exposure for a ransomware scenario
CyberLab, executive simulation preview
NIS2DORASEC Cyber RuleISO 27005

Recent thinking on cyber and IT risk.

Board Lens

Common Cyber Threats Facing Businesses: A Guide for CFOs

Read the guide →
Board Lens

Protecting Your Business from Cyber Attacks: A Guide for CEOs

Read the guide →
Board Lens

Conducting a Cyber Risk Assessment: A Guide for C-Level Executives and Directors

Read the guide →

See it before you commission it

Read a finished assessment before commissioning one.

Pick the decision you’re facing: screening, due diligence, white label, or portfolio monitoring, and we’ll send a finished assessment of that type.

Request a sample assessment