Cyber Risk Quantification (CRQ) is the discipline of measuring information security risks in objective, financial terms rather than ordinal "High/Medium/Low" heat maps. By leveraging standardized quantitative frameworks such as Open FAIRโข (Factor Analysis of Information Risk), Monte Carlo simulations, Loss Exceedance Curves (LEC), and continuous threat intelligence, CRQ enables CISOs, risk officers, and enterprise boards to:
- ๐ต Calculate Annualized Loss Expectancy (ALE) and Cyber Value at Risk (VaR) in dollars.
- ๐ฏ Prioritize security investments based on measurable risk reduction and Return on Security Investment (ROSI).
- ๐ Translate technical telemetry (vulnerabilities, misconfigurations, EPSS scores) into board-ready financial exposure.
- ๐ Validate cyber insurance policy limits and evaluate third-party vendor supply-chain exposure.
This repository is a comprehensive, curated index of top commercial SaaS platforms, open-source engines, and risk-as-code frameworks designed for modern cyber risk quantification.
- ๐ข SaaS & Commercial CRQ Platforms
- ๐ Open-Source GitHub Projects
- ๐งฉ Architectural Blueprints for Custom CRQ
- ๐ค How to Contribute
- โญ Star History
โ ๏ธ Disclaimer
Below is a curated comparison of leading commercial Cyber Risk Quantification, Continuous Threat Exposure Management (CTEM), and Third-Party Risk Management (TPRM) platforms, sorted in descending order by company valuation/size.
| Platform / Tool | Company Size & Valuation | Description & CRQ Focus | Pricing (Starting Tiers) | Free Tier Limits / Free Trial Policy |
|---|---|---|---|---|
| Qualys TruRisk | ๐ฆ Public (NASDAQ: QLYS) โข Valuation: ~$5.45B Market Cap โข Revenue: ~$685M+ (TTM) |
๐ฏ Vulnerability Management, Detection, and Response (VMDR) engine computing asset-level and organization-level TruRisk scores by combining vulnerability severity, exploitability (EPSS), asset criticality, and threat intelligence. | Starts at $199 โ $250/IP/year for VMDR TruRisk; Web Application Scanning (WAS) starts at $1,995/yr (for 25 apps); starter enterprise deployment bundles begin at ~$2,500 โ $3,000/yr. | ๐ Free forever Community Edition (limited to 16 internal IPs, 3 external IPs, 1 web application, and 1 virtual scanner appliance) + 30-day free trial of full VMDR TruRisk platform. |
| SecurityScorecard | ๐ฆ Private (Series E) โข Valuation: ~$1.0B โข Revenue: ~$135M+ ARR โข Funding: ~$293M |
๐ Cybersecurity ratings and continuous monitoring platform providing outside-in risk scores (AโF), automated issue detection, and financial cyber risk quantification modules. | Starts at ~$12,000 โ $20,000/yr for entry monitoring tier (monitoring 50โ150 third-party domains); enterprise vendor management portfolios scale to $45,000+/yr. | ๐ Free forever tier (includes 1 self-monitored domain scorecard, basic questionnaire exchange, and core dashboard access) + 14-day free trial of the Business Plan with full automated alerting. |
| CyCognito | ๐ Private (Series C) โข Valuation: ~$800M โข Revenue: ~$41M+ ARR โข Funding: ~$153M |
๐ External Attack Surface Management (EASM) and continuous exposure testing platform that maps shadow IT, identifies attack paths, and quantifies business risk exposure. | Starts at ~$25,000/yr (entry-level ASM package for up to 250 external assets/domains); scales with asset volume (tiers up to 5,000โ100,000+ assets) and testing frequency. | โฑ๏ธ 14-day guided proof of concept (POC) including full external asset discovery scan and exposure report (no perpetual free tier). |
| Safe Security | ๐ Private (Series C) โข Valuation: ~$400Mโ$500M โข Funding: ~$170M |
๐ค Autonomous cyber risk management & quantification platform (SAFE One) combining FAIR-derived methodology, Monte Carlo simulations, and real-time telemetry across internal assets, cloud, and third parties. | Starts at ~$30,000 โ $50,000/yr for core CRQ packages; scales into six-figure enterprise contracts based on asset count, data connectors, and modules (CTEM, TPRM, AI-SPM). | ๐ Free access to standalone interactive tools (Interactive Cost Calculator & Cyberinsurance Assessment); 14-to-30 day guided enterprise Proof of Value (POV) upon sales qualification. |
| Brinqa | ๐ผ Private (Growth Equity) โข Valuation: ~$350Mโ$450M โข Funding: ~$110M (Insight Partners) |
๐ Cyber Risk Management and Vulnerability Risk Prioritization platform aggregating telemetry from 100+ security tools to model cyber relationships and compute unified risk scores. | Starts at ~$50,000 โ $100,000/yr (enterprise pricing based on volume of ingested assets/vulnerabilities and connector counts). | โฑ๏ธ 14-to-30-day scoped proof-of-concept pilot in a dedicated sandbox environment with sample integration connectors (no perpetual free tier). |
| RedSeal | ๐๏ธ Private (STG Acquired) โข Valuation: ~$150Mโ$200M โข Revenue: ~$51M+ ARR โข Funding: ~$140M+ |
๐บ๏ธ Cyber risk analytics and network modeling platform that constructs digital twins of hybrid networks to identify attack paths, test segmentation, and calculate digital resilience scores. | Starts at ~$10,000 โ $20,000/yr (licensed on a per-network-node/device model at ~$100โ$250 per device/firewall with minimum annual commitment). | โฑ๏ธ 30-day guided evaluation / proof-of-concept license for network topology modeling and vulnerability path verification. |
| Black Kite | ๐ก๏ธ Private (Series B) โข Valuation: ~$150Mโ$200M โข Revenue: ~$25M+ ARR โข Funding: ~$36M |
๐ฆ Third-party cyber risk intelligence and CRQ platform providing financial impact calculation (FAIR-based), Ransomware Susceptibility Index (RSIโข), and compliance correlation. | Starts at ~$15,000 โ $29,160/yr (median entry tier monitoring 25โ50 vendor domains); scaling up to $90,000+/yr for large enterprise supply chains. | ๐ 1 complimentary external Cyber Risk Assessment report for your company or 1 vendor domain + 14-day scoped evaluation trial upon request. |
| Balbix | ๐ Acquired (Safe Security) โข Valuation: ~$120Mโ$150M โข Funding: ~$60M+ (prior to acquisition) |
๐ง Security posture and cyber exposure quantification platform using AI to continuously discover assets, predict breach risk, and prioritize remediation by financial impact. | Starts at ~$20,000 โ $35,000/yr for entry-level deployments; scales based on total asset inventory / IP count and integration volume. | โฑ๏ธ 30-day proof-of-value (POV) trial including initial external and internal asset discovery scan with risk scoring (no perpetual free tier). |
| Axio | โก Private (Series B) โข Valuation: ~$80Mโ$120M โข Revenue: ~$14M+ ARR โข Funding: ~$30M (ISTARI) |
๐ Cyber risk management and quantification platform (Axio360) emphasizing scenario-based financial stress testing, C2M2/NIST CSF maturity assessments, and board-ready reporting. | Starts at ~$12,000 โ $24,000/yr for core benchmark & assessment tier; scaling to $50,000+/yr for full CRQ stress-testing suite. | ๐ Free forever tier for single-framework assessments (NIST CSF Quick Launch, C2M2 Quick Launch, and Ransomware Preparedness tools for 1 organization) + 14-day full platform trial. |
| RiskLens | ๐ Acquired (Safe Security) โข Valuation: ~$50Mโ$80M โข Funding: ~$20M+ (prior to acquisition) |
๐ Pure-play quantitative cyber risk management software aligned with the Open FAIRโข standard; provides probabilistic loss modeling (ALE, VaR) and board-level risk analytics. | Starts at ~$15,000 โ $25,000/yr for RiskLens Pro / Starter tier; enterprise tiers range from $50,000 to $100,000+/yr depending on FAIR analysis volume. | ๐ Free forever access to the FAIR-U web application (educational tool for 1 FAIR risk scenario Monte Carlo simulation at a time via FAIR Institute) + 14-day guided enterprise trial. |
| Kovrr | ๐ฒ Private (Series A) โข Valuation: ~$30Mโ$50M โข Revenue: ~$4.1M ARR โข Funding: ~$10M+ |
๐งฎ Financial Cyber Risk Quantification (Quantum CRQ) platform translating cyber posture into financial risk metrics (Average Annual Loss, Value at Risk, loss exceedance curves) and AI risk governance. | Starts at ~$25,000 โ $50,000/yr for core Quantum CRQ enterprise subscription; scales based on company revenue tier and modeling depth. | ๐ Free tier for AI Risk Register (first 5 AI risk scenarios free forever) + 14-day guided CRQ financial loss modeling trial. |
| FortifyData | ๐ Private (Series A) โข Valuation: ~$20Mโ$30M โข Revenue: ~$2.7M ARR โข Funding: ~$7M |
๐ก๏ธ Continuous cyber risk management and attack surface quantification platform assessing internal and external vulnerabilities to compute real-time risk ratings and compliance posture. | Starts at ~$10,000 โ $21,375/yr (median entry tier for core external and internal asset monitoring). | ๐ Free plan (quarterly external attack surface vulnerability assessment and security rating for 1 domain) + 14-day full feature trial. |
Below is a curated list of top open-source tools, Monte Carlo engines, GRC platforms with native FAIR quantification, and risk modeling frameworks, sorted in descending order by GitHub Stars.
-
CISO Assistant
๐ Comprehensive open-source GRC and risk management platform featuring native support for Open FAIR risk assessments, automated Loss Exceedance Curve (LEC) generation, and Monte Carlo risk simulations. -
cve-search
๐ Local vulnerability and exposure search engine and database importer (CVE, CWE, CPE, CAPEC) enabling fast risk scoring, vulnerability correlation, and threat exposure calculations. -
riskquant
๐ Netflix's open-source Python library for quantitative risk assessment; computes annualized loss expectancy (ALE) and Loss Exceedance Curves by fitting loss frequency and magnitude to lognormal probability distributions. -
awesome-risk-quantification
๐ Curated index and learning roadmap of resources, academic papers, books, and software implementations for quantitative information security risk analysis and FAIR modeling. -
evaluator
๐ Open-source R toolkit for quantitative risk assessment based on the OpenFAIR ontology and risk analysis standard. Supports data-driven, repeatable FAIR-style simulation, parameter estimation, and graphical reporting. -
pyfair
๐ฒ Python package implementing the Factor Analysis of Information Risk (FAIR) model for programmatic Monte Carlo risk simulations, distribution fitting, and risk scenario comparisons. -
CRML (Cyber Risk Modeling Language)
๐ Open-source declarative language and engine for writing "Risk as Code" (RaC). Provides YAML/JSON schemas to describe cyber risk models, telemetry mappings, and simulation pipelines in an engine-agnostic format. -
Security Decision Labs
๐งช Collection of statistical decision science and FAIR CRQ toolkits, including agent-based control simulations (FAIR-CAM), Threat Event Frequency (TEF) estimators, and Value of Information (VoI) calculators. -
OpenFAIR
๐ Lightweight R implementation for simulating Open FAIR cyber risk scenarios and calculating probabilistic annualized loss distributions. -
Fair TPRM
๐ Free, self-hosted open-source Third-Party Risk Management (TPRM) & GRC platform that incorporates native FAIR risk quantification (ALE calculations), vendor compliance scoring, and continuous risk monitoring.
Organizations building custom internal Cyber Risk Quantification pipelines typically assemble a multi-layer stack:
- Telemetry & Ingestion Layer: Ingest vulnerability scan data (Qualys, Nessus, OpenVAS), asset inventories, EPSS exploitability scores, CISA KEV feeds, and external attack surface exposures into a centralized lake or graph.
-
Standardized Ontology Layer: Map technical assets and vulnerabilities into the Open FAIRโข Risk Taxonomy (Threat Event Frequency
$\times$ Vulnerability$\times$ Loss Magnitude). -
Simulation Engine Layer: Execute 10,000โ100,000 iterations using Python/R Monte Carlo engines (
riskquant,pyfair, orevaluator) to generate probabilistic loss distributions. - Executive Reporting Layer: Output Loss Exceedance Curves (LEC), 90th-percentile Cyber VaR, and Annualized Loss Expectancy (ALE) to BI dashboards (Tableau, Grafana, Power BI) and board slide decks.
We welcome contributions from cybersecurity practitioners, risk analysts, data scientists, and developers!
- ๐ด Fork the repository on GitHub.
- ๐ฟ Create a feature branch:
git checkout -b add-new-crq-tool - ๐ Add your entry in README.md following the format:
- For SaaS: Include Name, Link, Valuation/Revenue size, Description, Starting Price, and specific Free Tier/Trial limits. Insert in the correct sorted order.
- For Open-Source: Include Repo Name, GitHub Link, Stargazers Star Badge (
style=social&color=white), and Description. Insert in the correct star-sorted order.
- ๐ Submit a Pull Request with a concise description of the contribution.
โญ Star this repository if you find it helpful for your quantitative cyber risk journey!
- This is a community-curated index for informational and educational purposes โ it does not constitute financial, legal, or cyber insurance advice.
- Cyber Risk Quantification models depend heavily on the quality, calibration, and assumptions of input data (Threat Event Frequency, Control Strength, Primary/Secondary Loss bounds).
- Open-source Monte Carlo and FAIR tools provide complete transparency and model auditability, but require sound risk modeling calibration and statistical validation before using results in regulatory filings or board reporting.
Made with ๐ก๏ธ for CISOs, risk officers, security engineers, and cyber insurance underwriters striving for transparent, defensible, and mathematical cyber risk quantification.