Cyber Risk Quantification
Cyber Risk Quantification, patented.
Numbers you can defend.
Everything that runs underneath Citalid's number, from live threat intelligence to the financial model, opened layer by layer for anyone who wants to see how it's built.

What cyber risk quantification actually measures
Each side of the equation is broken down, then simulated thousands of times. The result isn't one number, it's a range: a typical annual loss, and a worst-case loss you're unlikely to exceed.
That's what lets you answer the two questions your board actually asks:
What does a normal year cost, and what does a bad one cost?
Prioritize
Which scenario costs the most, and by how much.
Align
One indicator that security, finance and the board all read the same way.
Steer
A risk appetite executives can set and monitor.
The Citalid Product Suite
A comprehensive platform tailored to your organization's scale and risk management needs.
Citalid Core
First-Party Level
Full-depth view, including your internal data and controls aggregated to your perimeter (business units, subsidiaries)
Risk Quantification
Budget planning
Cyber insurance
Board and regulator reporting

Citalid TPRM
Third-party Level
Supplier exposure priced from threat intelligence rather than self declaration, with cascading impact across your operations.
Vendor prioritization
Contract risk clauses
Continuous monitoring
Supply chain resilience

Citalid Portfolio
Group Level
The same engine applied to insured entities, borrowers and portfolios, including accumulation on shared points of failure.
Underwriting and pricing
Accumulation risk
Lending decisions
M&A due diligence

Get started
What it costs you, at every level you carry the risk
Five layers. This is what actually builds the number.
A Major Private Equity Firm Strengthens Its Cyber Resilience with Citalid
A major international private equity firm used Citalid to move from reactive security to controlled, demonstrable cyber resilience, valued directly by investors.
500+ employees, financial services, Citalid Core
Read the customer story~1%
estimated potential loss as % of annual revenue
2×/year
comprehensive cyber strategy review
Moving from an abstract red-green heat map to a concrete, justifiable view of the cyber threats at stake.
Citalid client, confidential industry
A CTI-based solution that dynamically quantifies financial exposure, combining AI with risk expertise.
Frédéric Bouveresse - Cyber Risk Specialist, transportation industry
CRQ strengthens our Zero Trust portfolio: mitigating risk, predicting impact, prioritising investment.
Christophe Maira - CISO, Mutex
The questions we get before the demo
CRQ translates cyber risk into a financial figure, an expected loss in dollars or euros, instead of a technical score or color rating. It lets security, finance and governance teams compare cyber risk to other risks they already manage in monetary terms.
Citalid's models are built on the FAIR standard, extended with live Cyber Threat Intelligence and Bayesian financial modeling. Every scenario runs through patented attack and defense simulations before a loss distribution is calculated.
Citalid tracks more than 1,000 active intrusion sets and their tactics. This live intelligence feeds directly into the frequency estimates for each risk scenario, so figures reflect who is actually targeting a given sector this week, not a static historical table.
FAIR (Factor Analysis of Information Risk) is the leading standard for quantifying information risk in financial terms. Citalid builds on FAIR rather than replacing it. Jack Jones, who created FAIR, sits on Citalid's Advisory Board.
The model is FAIR aligned and documented assumption by assumption, which is what allows it to be reviewed by an internal audit, a regulator or an insurer. Citalid is also a Founding Member of the Enterprise Risk Quantification Institute (ERQI), a cross industry community that scrutinizes CRQ practice.
No. Citalid quantifies the financial impact of the risks that audits and technical assessments identify. It works alongside frameworks like CIS, NIST, ISO 27001 and DORA rather than replacing the assessments built around them.











