Cyber Risk Quantification

Cyber Risk Quantification, patented.
Numbers you can defend.

Everything that runs underneath Citalid's number, from live threat intelligence to the financial model, opened layer by layer for anyone who wants to see how it's built.

They trust us

Allianz
Capgemini
Groupe Rocher
Lagardère
Relyens
Unéo
Allianz
Capgemini
Groupe Rocher
Lagardère
Relyens
Unéo
Allianz
Capgemini
Groupe Rocher
Lagardère
Relyens
Unéo

What cyber risk quantification actually measures

Loss Event Frequency X Loss Magnitude = Annual exposure

Each side of the equation is broken down, then simulated thousands of times. The result isn't one number, it's a range: a typical annual loss, and a worst-case loss you're unlikely to exceed.
That's what lets you answer the two questions your board actually asks:
What does a normal year cost, and what does a bad one cost?

Prioritize

Which scenario costs the most, and by how much.

Align

One indicator that security, finance and the board all read the same way.

Steer

A risk appetite executives can set and monitor.

The Citalid Product Suite

A comprehensive platform tailored to your organization's scale and risk management needs.

Citalid Core

First-Party Level

Full-depth view, including your internal data and controls aggregated to your perimeter (business units, subsidiaries)

Risk Quantification

Budget planning

Cyber insurance

Board and regulator reporting

Explore Citalid Core

Citalid TPRM

Third-party Level

Supplier exposure priced from threat intelligence rather than self declaration, with cascading impact across your operations.

Vendor prioritization

Contract risk clauses

Continuous monitoring

Supply chain resilience

Explore Citalid TPRM

Citalid Portfolio

Group Level

The same engine applied to insured entities, borrowers and portfolios, including accumulation on shared points of failure.

Underwriting and pricing

Accumulation risk

Lending decisions

M&A due diligence

Explore Citalid Portfolio

Get started

What it costs you, at every level you carry the risk

Five layers. This is what actually builds the number.

Business context and external exposure

Before any scenario exists, the engine needs your perimeter and your business.

The starting point is what's public and what you tell us, never a guess

Your assets, revenue drivers and existing controls, read through the framework you already run on

Attack surface and exposed services, mapped from the outside in

Live Cyber Threat Intelligence

This is where the frequency side of the equation comes from.

Continuous tracking of more than 1,000 active intrusion sets and their tactics

Targeting patterns and attacker operational capacity, combined into a frequency specific to your organization

Monitored continuously by CTI analysts, so the model moves when the threat does

Patented attack and defense simulation

Where your controls stop being a maturity score and start being tested.

Tens of thousands of simulated confrontations between attacker techniques and your defenses

A patented model of how an intrusion would propagate through your systems

A frequency and severity range for every scenario, built from your own configuration

Bayesian financial modeling, built on FAIR

Where the simulation becomes a euro or dollar figure.

Transparency by construction, from the CTI source down to the loss parameter

Operational, reputational and legal losses modeled and priced separately

Calibrated further with your own historical data

The number, and the distribution behind it

What you actually walk away with.

A full loss distribution, not a single point estimate

Every probability backed by Monte Carlo simulation and reproducible on demand

Every layer above open to challenge by a regulator, an auditor or an insurer

A Major Private Equity Firm Strengthens Its Cyber Resilience with Citalid

A major international private equity firm used Citalid to move from reactive security to controlled, demonstrable cyber resilience, valued directly by investors.

500+ employees, financial services, Citalid Core

Read the customer story

~1%

estimated potential loss as % of annual revenue

2×/year

comprehensive cyber strategy review

Moving from an abstract red-green heat map to a concrete, justifiable view of the cyber threats at stake.

Citalid client, confidential industry

A CTI-based solution that dynamically quantifies financial exposure, combining AI with risk expertise.

Frédéric Bouveresse - Cyber Risk Specialist, transportation industry

CRQ strengthens our Zero Trust portfolio: mitigating risk, predicting impact, prioritising investment.

Christophe Maira - CISO, Mutex

The questions we get before the demo

CRQ translates cyber risk into a financial figure, an expected loss in dollars or euros, instead of a technical score or color rating. It lets security, finance and governance teams compare cyber risk to other risks they already manage in monetary terms.

Citalid's models are built on the FAIR standard, extended with live Cyber Threat Intelligence and Bayesian financial modeling. Every scenario runs through patented attack and defense simulations before a loss distribution is calculated.

Citalid tracks more than 1,000 active intrusion sets and their tactics. This live intelligence feeds directly into the frequency estimates for each risk scenario, so figures reflect who is actually targeting a given sector this week, not a static historical table.

FAIR (Factor Analysis of Information Risk) is the leading standard for quantifying information risk in financial terms. Citalid builds on FAIR rather than replacing it. Jack Jones, who created FAIR, sits on Citalid's Advisory Board.

The model is FAIR aligned and documented assumption by assumption, which is what allows it to be reviewed by an internal audit, a regulator or an insurer. Citalid is also a Founding Member of the Enterprise Risk Quantification Institute (ERQI), a cross industry community that scrutinizes CRQ practice.

No. Citalid quantifies the financial impact of the risks that audits and technical assessments identify. It works alongside frameworks like CIS, NIST, ISO 27001 and DORA rather than replacing the assessments built around them.

Get started

What your cyber risk costs you, at every level you carry the risk

Talk to an expert