What Is CRQ (Cyber Risk Quantification)?

Also called: Cybersecurity risk quantification

Related problems: The board wants cyber risk in dollars, not red, amber and green; Can't justify the security budget against other spending; Don't know how much cyber insurance coverage we actually need; Every security project is labeled high priority

Cyber risk quantification (CRQ) is the practice of estimating cyber risk in financial terms, for example the likely annual cost of a ransomware attack or a data breach, expressed as a range with probabilities. Instead of rating risks red, amber or green, CRQ puts them in the same units the business uses for other decisions, so leaders can compare security investments, insurance and accepted risk on a common basis.

At a glance

  • CRQ expresses cyber risk as money, usually as a range of likely losses over a period, not a single number.
  • Analyses are built around scenarios, such as ransomware on core systems or theft of customer data, and estimate how often each might happen and what it would cost.
  • Factor Analysis of Information Risk (FAIR) is a widely used model; some tools use their own or blended methods.
  • Outputs support budget, insurance and risk-acceptance decisions, and their quality depends heavily on the data and assumptions used.

What problem it solves

Most security risk reporting uses qualitative scales. A heat map shows dozens of risks rated “high”, but it doesn’t say which high risk costs more, whether a proposed project reduces risk enough to justify its price, or how much insurance makes sense. Boards and finance teams increasingly ask security leaders to answer in money, and a color chart can’t do that.

CRQ gives security, finance and leadership a shared language. A statement like “we estimate a 10 to 15 percent chance per year of a ransomware event costing between X and Y, and this project would cut that roughly in half” can be weighed against other uses of the same budget. It also makes assumptions visible, so people can challenge them, rather than hiding judgment inside a label.

How it works

Scenario definition. The team picks the loss events that matter most, defined concretely: what asset, what threat, what kind of impact. “Cyber risk” is too vague to quantify; “ransomware that stops order processing for several days” is not.

Frequency. For each scenario, the analysis estimates how often it is likely to happen, based on internal incident history, industry data, threat intelligence and how well current controls work. Estimates are usually ranges.

Magnitude. It then estimates the cost when it does happen: response and recovery, lost revenue, regulatory penalties, legal costs, customer notification, and longer-term effects such as lost customers. Finance and business owners provide much of this input.

Modeling. The model combines frequency and magnitude, often by running many simulations, to produce a distribution of possible annual losses. Factor Analysis of Information Risk (FAIR) is a widely used open model for structuring this; commercial platforms may use FAIR, their own models or a mix, and some pull control and exposure data from security tools automatically.

Decisions. Results are used to rank risks, compare the risk reduction from different projects, test insurance limits and record risk acceptance in a risk register. The analysis is repeated as the business, threats and controls change.

When it matters for buyers

  • When the board asks for financial risk reporting. CRQ turns security updates into language directors and finance teams already use.
  • When defending or reallocating a security budget. It helps show which projects reduce the most expected loss per dollar.
  • At cyber insurance renewal. Loss estimates inform coverage limits and retention choices, alongside the insurer’s own view.
  • When regulators, auditors or customers ask how risk is managed. A documented, repeatable method supports risk assessments and governance programs.
  • When choosing between overlapping tools. It gives a basis for comparing what each would actually change.

For help building a risk program and choosing tools, see our governance, risk and compliance overview.

Questions to ask vendors

  • Which model do you use (FAIR, proprietary or a mix), and is the method documented so we can explain results to our board?
  • What industry loss and frequency data feed your estimates, how current are they, and how well do they fit our size and sector?
  • Which inputs come from our own tools automatically, and which require interviews or manual entry?
  • How do you show uncertainty, and can we see the assumptions behind each result?
  • Can the platform compare the risk reduction of specific projects or controls?
  • How much analyst time does a typical scenario take, and is advisory help included or extra?
  • How do results map to our existing risk register and GRC tools?

How it differs from a qualitative risk assessment

A qualitative risk assessment rates likelihood and impact on scales such as low, medium and high, then plots them on a heat map. It is fast and useful for a first pass, but ratings are hard to compare and can’t be added up or weighed against cost. CRQ estimates the same two factors in numbers, usually with ranges, so risks can be ranked, summed and compared with the cost of reducing them. Many organizations use both: a qualitative screen across many risks, and CRQ for the handful of scenarios that drive major spending or insurance decisions. CRQ also sits inside a broader governance, risk and compliance (GRC) program rather than replacing it.

Frequently Asked Questions

What is FAIR in cyber risk quantification?
Factor Analysis of Information Risk (FAIR) is a widely used model for CRQ. It breaks risk into how often a loss event is likely to happen and how much it is likely to cost, and it is maintained as an open standard. It is not the only approach; some tools use their own models or combine FAIR with other methods.
Is CRQ accurate?
It produces estimates, usually as ranges with probabilities, not precise forecasts. The results are only as good as the data and assumptions behind them. Its value is in making assumptions explicit and comparing options consistently, so treat outputs as a decision aid, not a guarantee of future losses.
Do we need a CRQ platform to get started?
Not necessarily. Teams can start with a few top risk scenarios, a spreadsheet and a documented model, often with help from an advisor. Platforms help when you want to analyze many scenarios, pull in control and threat data automatically and repeat the work regularly.
How does CRQ help with cyber insurance?
It gives you an estimate of what a serious incident might cost, which can inform how much coverage and what retention to consider. Insurers use their own underwriting models, so your figures support the conversation rather than set the premium.
Who should own CRQ?
Usually the security or risk function runs the analysis, with input from finance, legal and business owners who understand what an outage or data loss would actually cost. Results are typically reported to executives and the board.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.