Citalid Secures U.S. Patent for Automated Cyberattack Simulation Powering Its CRQ Platform

News

US Patent

Paris, France – March 17, 2026 — Citalid, the leading cyber risk quantification (CRQ) tech provider in Europe, today announced the grant of U.S. Patent No. 12,542,803 B2 for a proprietary automated cyberattack simulation method that enhances the precision, measurability, and reliability of cyber risk assessment.

This U.S. patent follows the grant of the same core invention in France in 2023, reinforcing the international recognition of Citalid’s technological innovation and its mathematical approach to cyber risk modeling.

This innovation is not a standalone product, but a core technological advancement embedded within Citalid’s Cyber Risk Quantification engine. By enabling large-scale probabilistic simulation of cyberattacks across complex information systems, the patented method strengthens the accuracy, consistency, and reproducibility of cyber risk modeling — delivering defensible financial risk metrics at scale for enterprises, insurers, and financial institutions.

See how Citalid supports large, complex organizations with enterprise-grade cyber risk quantification

EXPLORE CITALID ENTERPRISE

From Security Testing to Quantified Cyber Risk

Traditional cybersecurity assessments such as penetration testing or red teaming provide point-in-time, human-driven evaluations. While valuable, they are inherently limited in scale and repeatability.

Citalid’s patented method introduces an automated approach that:

  • Simulates thousands of attack paths across complex, interconnected systems
  • Models attacker capabilities against defensive controls to calculate the probability of successful compromise
  • Produces structured, quantitative risk indicators that are repeatable, comparable, and directly linkable to financial impact

By running large-scale probabilistic simulations, the platform transforms technical exposure into measurable, repeatable, and comparable risk indicators over time.

The result: cyber risk that can be quantified with greater statistical rigor and linked directly to financial impact modeling.

Serving Enterprises, Third-Party Risk Management, and Financial Stakeholders

The patented technology strengthens risk assessment capabilities across multiple use cases:

1. Enterprise Self-Assessment

Organizations can more accurately measure their own exposure, evaluate the financial return on security investments, and prioritize remediation based on modeled probability of compromise.

2. Third-Party Risk Management (TPRM)

Most enterprises still assess third-party cyber risk, a growing regulatory and operational priority in both the U.S. and U.K., through spreadsheets and questionnaires. Citalid’s newly launched TPRM offering changes that, applying the same patented simulation methodology at scale to suppliers and critical vendors, and replacing declarative assessments with probabilistic, evidence-based exposure scoring at scale.

3. Insurance Underwriting and Credit Risk Assessment

For insurers and banks, the patented simulation approach enhances the ability to assess cyber exposure of portfolios of clients and prospects. By providing probabilistic, scenario-based indicators, the platform supports more consistent underwriting decisions and risk-informed credit granting.

In a market increasingly focused on resilience, regulatory scrutiny, and financial accountability, this innovation helps bridge the gap between cybersecurity operations and financial risk management.

Strengthening the Foundations of Cyber Risk Quantification

“A risk you can’t measure, you can’t manage… and you certainly can’t explain to a board or a regulator,” said Maxime Cartan, co-founder and CEO of Citalid. “This patent is at the core of how we make cyber risk measurable. Consistently, at scale, in financial terms.”

As cyber threats grow in sophistication and interconnectedness, stakeholders across industries require transparent, quantitative methodologies to support strategic decisions. The U.S. patent grant marks an important milestone in advancing cyber risk from a qualitative discipline to a measurable financial risk category.

More content

Related content