Cyber risk quantification (CRQ) is the practice of estimating cyber risk in financial terms, for example the likely annual cost of a ransomware attack or a data breach, expressed as a range with probabilities. Instead of rating risks red, amber or green, CRQ puts them in the same units the business uses for other decisions, so leaders can compare security investments, insurance and accepted risk on a common basis.
At a glance
- CRQ expresses cyber risk as money, usually as a range of likely losses over a period, not a single number.
- Analyses are built around scenarios, such as ransomware on core systems or theft of customer data, and estimate how often each might happen and what it would cost.
- Factor Analysis of Information Risk (FAIR) is a widely used model; some tools use their own or blended methods.
- Outputs support budget, insurance and risk-acceptance decisions, and their quality depends heavily on the data and assumptions used.
What problem it solves
Most security risk reporting uses qualitative scales. A heat map shows dozens of risks rated “high”, but it doesn’t say which high risk costs more, whether a proposed project reduces risk enough to justify its price, or how much insurance makes sense. Boards and finance teams increasingly ask security leaders to answer in money, and a color chart can’t do that.
CRQ gives security, finance and leadership a shared language. A statement like “we estimate a 10 to 15 percent chance per year of a ransomware event costing between X and Y, and this project would cut that roughly in half” can be weighed against other uses of the same budget. It also makes assumptions visible, so people can challenge them, rather than hiding judgment inside a label.
How it works
Scenario definition. The team picks the loss events that matter most, defined concretely: what asset, what threat, what kind of impact. “Cyber risk” is too vague to quantify; “ransomware that stops order processing for several days” is not.
Frequency. For each scenario, the analysis estimates how often it is likely to happen, based on internal incident history, industry data, threat intelligence and how well current controls work. Estimates are usually ranges.
Magnitude. It then estimates the cost when it does happen: response and recovery, lost revenue, regulatory penalties, legal costs, customer notification, and longer-term effects such as lost customers. Finance and business owners provide much of this input.
Modeling. The model combines frequency and magnitude, often by running many simulations, to produce a distribution of possible annual losses. Factor Analysis of Information Risk (FAIR) is a widely used open model for structuring this; commercial platforms may use FAIR, their own models or a mix, and some pull control and exposure data from security tools automatically.
Decisions. Results are used to rank risks, compare the risk reduction from different projects, test insurance limits and record risk acceptance in a risk register. The analysis is repeated as the business, threats and controls change.
When it matters for buyers
- When the board asks for financial risk reporting. CRQ turns security updates into language directors and finance teams already use.
- When defending or reallocating a security budget. It helps show which projects reduce the most expected loss per dollar.
- At cyber insurance renewal. Loss estimates inform coverage limits and retention choices, alongside the insurer’s own view.
- When regulators, auditors or customers ask how risk is managed. A documented, repeatable method supports risk assessments and governance programs.
- When choosing between overlapping tools. It gives a basis for comparing what each would actually change.
For help building a risk program and choosing tools, see our governance, risk and compliance overview.
Questions to ask vendors
- Which model do you use (FAIR, proprietary or a mix), and is the method documented so we can explain results to our board?
- What industry loss and frequency data feed your estimates, how current are they, and how well do they fit our size and sector?
- Which inputs come from our own tools automatically, and which require interviews or manual entry?
- How do you show uncertainty, and can we see the assumptions behind each result?
- Can the platform compare the risk reduction of specific projects or controls?
- How much analyst time does a typical scenario take, and is advisory help included or extra?
- How do results map to our existing risk register and GRC tools?
How it differs from a qualitative risk assessment
A qualitative risk assessment rates likelihood and impact on scales such as low, medium and high, then plots them on a heat map. It is fast and useful for a first pass, but ratings are hard to compare and can’t be added up or weighed against cost. CRQ estimates the same two factors in numbers, usually with ranges, so risks can be ranked, summed and compared with the cost of reducing them. Many organizations use both: a qualitative screen across many risks, and CRQ for the handful of scenarios that drive major spending or insurance decisions. CRQ also sits inside a broader governance, risk and compliance (GRC) program rather than replacing it.
