Services

Services

Cyber findings become financial exposure your investment committee can act on.

Screen a shortlist, quantify a transaction under exclusivity, extend your own advisory brand, or monitor a portfolio every quarter. Each service line turns security findings into a number you can weigh against deal value, not a colour on a scorecard.

What you getA number, not a ratingExposure you can weigh against deal value
When it helpsBefore you signRuns on a shortlist or during exclusivity
What it costs youA fraction of a reviewPriced to look at every name, not just one
How it readsA range, not a guessA realistic case and a bad case, side by side
Service lines

Whichever decision you’re facing, there’s a service line built for it.

You get the same thing either way: exposure in money terms, with a realistic case and a bad case. What changes is the decision it feeds, how deep the scope goes, and whose name is on the report.

Screening

Screen a shortlist before diligence budget is committed.

Assess several acquisition candidates for the cost of one traditional review, at the stage where the field is still being narrowed rather than a decision confirmed.


  • StagePre-IOI and IOI
  • OutputRanked exposure, critical dependencies, evidence gaps
Due diligence

Quantify exposure on a transaction already under exclusivity.

The full assessment covers what the business depends on, where it is exposed through its assets and suppliers, and how well it is defended, with each scenario shown as a realistic case and a bad case, and the cost of fixing it in terms an investment committee can read.


  • StagePost-LOI, confirmatory phase
  • OutputFull assessment plus a management question set
White label

Put quantified cyber risk behind an advisory firm’s own brand.

Boutique cyber, GRC, and transaction advisory firms gain quantitative capability under their own name, without building a research pipeline in house.


  • ModelPer report or monthly licence
  • ExclusivityOne partner per vertical
  • OutputUnbranded or partner-branded assessment
Portfolio

Track exposure across a portfolio every quarter.

Where diligence answers a question once, monitoring answers it repeatedly, showing whether exposure is moving across the holding period.


  • CadenceQuarterly per company
  • InputPublic evidence, or company-supplied data once held
  • OutputComparable exposure, movement, and outlier view
The platform

Every service line runs on the same platform.

Whichever engagement you commission, the exposure figure, the treatment comparison, and the board documentation are produced in Risqua: the same model, the same checks, every time.

Model

Financial exposure modelling

Each scenario runs thousands of Monte Carlo iterations to a probable annual loss and an uncertainty range: a realistic case and a bad case, not a single number.

Decision

Treatment ROI

Current exposure against residual exposure, control cost, and expected reduction, so each spend is weighed against what it removes.

Report

Board-ready reporting

Governance documentation aligned to NIS2, DORA, the SEC Cyber Rule, and ISO 27005, generated from the same run. Assessment inputs are not retained after the session.

CyberLab executive simulation preview: annual loss expectancy and tail exposure for a ransomware scenario
A CyberLab result, in the terms a board pack uses.
Why buyers choose this

Priced and paced to run on a whole shortlist.

Whole shortlist

Look at every name, not just the front-runner.

Nothing has to be requested from the target to begin, so candidates can be assessed in parallel instead of one or two at a time.

Deal-ready

Exposure your investment committee can weigh.

You get the figure, plus what it would cost to fix set against what fixing it saves, so the committee can decide with the deal model open.

Defensible

The numbers hold up when the room pushes back.

Each figure links back to a business process and a scenario, so you can answer where a number came from in the meeting, not afterwards.

Honest about gaps

You know what is confirmed and what is inferred.

Each finding is labelled for what stands behind it, and the unknowns come back to you as questions to put to management rather than a quiet guess.

Who this is for

Built for teams deciding before the evidence is complete.

Private equity

Screen a pipeline, focus confirmatory diligence, then track exposure across the holding period.

Corporate development

Surface material cyber issues before integration planning and capital commitment.

Advisory firms

Offer quantified cyber risk under their own brand without building the capability in house.

Operating partners

Compare portfolio companies on one consistent basis and see what moved this quarter.

Questions buyers ask first

Answers to the questions buyers ask first.

How can exposure be assessed without access to the target?

The assessment works from regulatory filings, published vulnerability and exploitation intelligence, breach and enforcement records, supplier assurance disclosures, and corporate reporting. That evidence supports a defensible picture of business process criticality, dependency structure, and likely exposure, but it cannot confirm internal configuration. Findings are labelled accordingly, and the unknowns become the management question set.

What is cyber risk quantification, and how does it differ from a maturity score?

A maturity score states that a control sits at level two of five but not what that costs. Quantification models specific loss events and expresses each as a range in money terms (a realistic case and a severe case per scenario) that can be weighed against deal value.

How is an engagement scoped?

Scope is set by the decision at hand rather than a fixed template. A screening engagement covers one or several named targets, a due diligence engagement covers a single transaction in depth, and white label or portfolio work is scoped per report or per company. Each request starts with a short conversation to confirm what the deliverable needs to answer.

What does a service line cost?

Screening is priced per target and sits well below a traditional review, which is what makes a full shortlist viable. Transaction assessments are banded by deal size, white label supply is priced per report with volume tiers, and portfolio monitoring is priced per company per quarter.

What stops the numbers from being wrong?

Before a report goes out it runs through a consistency check: the inventories line up, the arithmetic adds up, the risk bands match the size of the loss, and the cost of fixing something is judged against the expected loss rather than the worst case. Anything that does not clear that check is corrected, or the report is held back.

Start here

Read one finished assessment before commissioning one.

Pick the service line that matches the decision you’re facing, and we’ll send a finished assessment of that type.