Glossary
GLOSSARY Risk management

Cyber Risk Quantification (CRQ)

Last updated 27 Jul 2026

Cyber risk quantification expresses security risk in financial terms rather than on a qualitative scale. Instead of a red cell on a heat map, the output is a distribution of possible losses over a period.

Why organizations move to it

Heat maps do not support decisions about money. A risk rated high and a risk rated medium give no basis for choosing where to spend, and no way to compare a security investment against any other use of the same capital.

A loss distribution does. It also lets security be discussed in the language the rest of the organization already uses for risk, which is usually the real motivation.

What it involves

Decomposing a risk into the frequency of loss events and the magnitude when they occur.

Estimating each as a range with a stated confidence rather than a point value, since the honest answer is uncertain.

Running the ranges through a simulation, usually Monte Carlo, to produce a distribution.

Reading the output as a loss exceedance curve: the probability of losing at least a given amount in a year.

The FAIR model is the most widely used framework for this and provides the decomposition and vocabulary.

Where it is oversold

The output is only as good as the estimates going in, and the estimates are usually expert judgement. A simulation applied to guesses produces a precise-looking distribution over guesses. The precision is real and the accuracy is unknown.

Presenting a curve to a board implies a rigour the inputs may not support. The responsible version states the inputs and their basis alongside the output.

What it needs underneath

CRQ models consume facts. Asset counts and criticality. Control coverage across the actual population. Historical incident frequency. Remediation timeliness.

If those inputs are themselves estimates, or are computed differently each period, the model output cannot be compared across periods and cannot be defended when challenged.

This is the sequence that matters. A probabilistic model belongs on top of a deterministic factual base, taking measured facts as input. Built the other way round, with estimates feeding estimates, nothing underneath can be checked.