Skip to content

Latest commit

ย 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

Awesome Cyber Risk Quantification Banner

Awesome Cyber Risk Quantification (CRQ) ๐Ÿ›ก๏ธ๐Ÿ“Š

Awesome Discord Stars Forks License PRs Welcome GitHub followers


๐Ÿ“– Executive Summary & Ecosystem Overview

Cyber Risk Quantification (CRQ) is the discipline of measuring information security risks in objective, financial terms rather than ordinal "High/Medium/Low" heat maps. By leveraging standardized quantitative frameworks such as Open FAIRโ„ข (Factor Analysis of Information Risk), Monte Carlo simulations, Loss Exceedance Curves (LEC), and continuous threat intelligence, CRQ enables CISOs, risk officers, and enterprise boards to:

  • ๐Ÿ’ต Calculate Annualized Loss Expectancy (ALE) and Cyber Value at Risk (VaR) in dollars.
  • ๐ŸŽฏ Prioritize security investments based on measurable risk reduction and Return on Security Investment (ROSI).
  • ๐Ÿ“ˆ Translate technical telemetry (vulnerabilities, misconfigurations, EPSS scores) into board-ready financial exposure.
  • ๐Ÿ” Validate cyber insurance policy limits and evaluate third-party vendor supply-chain exposure.

This repository is a comprehensive, curated index of top commercial SaaS platforms, open-source engines, and risk-as-code frameworks designed for modern cyber risk quantification.


๐Ÿ“‘ Table of Contents


๐Ÿข SaaS & Commercial CRQ Platforms

Below is a curated comparison of leading commercial Cyber Risk Quantification, Continuous Threat Exposure Management (CTEM), and Third-Party Risk Management (TPRM) platforms, sorted in descending order by company valuation/size.

Platform / Tool Company Size & Valuation Description & CRQ Focus Pricing (Starting Tiers) Free Tier Limits / Free Trial Policy
Qualys TruRisk ๐Ÿฆ Public (NASDAQ: QLYS)
โ€ข Valuation: ~$5.45B Market Cap
โ€ข Revenue: ~$685M+ (TTM)
๐ŸŽฏ Vulnerability Management, Detection, and Response (VMDR) engine computing asset-level and organization-level TruRisk scores by combining vulnerability severity, exploitability (EPSS), asset criticality, and threat intelligence. Starts at $199 โ€“ $250/IP/year for VMDR TruRisk; Web Application Scanning (WAS) starts at $1,995/yr (for 25 apps); starter enterprise deployment bundles begin at ~$2,500 โ€“ $3,000/yr. ๐Ÿ†“ Free forever Community Edition (limited to 16 internal IPs, 3 external IPs, 1 web application, and 1 virtual scanner appliance) + 30-day free trial of full VMDR TruRisk platform.
SecurityScorecard ๐Ÿฆ„ Private (Series E)
โ€ข Valuation: ~$1.0B
โ€ข Revenue: ~$135M+ ARR
โ€ข Funding: ~$293M
๐Ÿ” Cybersecurity ratings and continuous monitoring platform providing outside-in risk scores (Aโ€“F), automated issue detection, and financial cyber risk quantification modules. Starts at ~$12,000 โ€“ $20,000/yr for entry monitoring tier (monitoring 50โ€“150 third-party domains); enterprise vendor management portfolios scale to $45,000+/yr. ๐Ÿ†“ Free forever tier (includes 1 self-monitored domain scorecard, basic questionnaire exchange, and core dashboard access) + 14-day free trial of the Business Plan with full automated alerting.
CyCognito ๐Ÿš€ Private (Series C)
โ€ข Valuation: ~$800M
โ€ข Revenue: ~$41M+ ARR
โ€ข Funding: ~$153M
๐ŸŒ External Attack Surface Management (EASM) and continuous exposure testing platform that maps shadow IT, identifies attack paths, and quantifies business risk exposure. Starts at ~$25,000/yr (entry-level ASM package for up to 250 external assets/domains); scales with asset volume (tiers up to 5,000โ€“100,000+ assets) and testing frequency. โฑ๏ธ 14-day guided proof of concept (POC) including full external asset discovery scan and exposure report (no perpetual free tier).
Safe Security ๐Ÿš€ Private (Series C)
โ€ข Valuation: ~$400Mโ€“$500M
โ€ข Funding: ~$170M
๐Ÿค– Autonomous cyber risk management & quantification platform (SAFE One) combining FAIR-derived methodology, Monte Carlo simulations, and real-time telemetry across internal assets, cloud, and third parties. Starts at ~$30,000 โ€“ $50,000/yr for core CRQ packages; scales into six-figure enterprise contracts based on asset count, data connectors, and modules (CTEM, TPRM, AI-SPM). ๐Ÿ†“ Free access to standalone interactive tools (Interactive Cost Calculator & Cyberinsurance Assessment); 14-to-30 day guided enterprise Proof of Value (POV) upon sales qualification.
Brinqa ๐Ÿ’ผ Private (Growth Equity)
โ€ข Valuation: ~$350Mโ€“$450M
โ€ข Funding: ~$110M (Insight Partners)
๐Ÿ”— Cyber Risk Management and Vulnerability Risk Prioritization platform aggregating telemetry from 100+ security tools to model cyber relationships and compute unified risk scores. Starts at ~$50,000 โ€“ $100,000/yr (enterprise pricing based on volume of ingested assets/vulnerabilities and connector counts). โฑ๏ธ 14-to-30-day scoped proof-of-concept pilot in a dedicated sandbox environment with sample integration connectors (no perpetual free tier).
RedSeal ๐Ÿ›๏ธ Private (STG Acquired)
โ€ข Valuation: ~$150Mโ€“$200M
โ€ข Revenue: ~$51M+ ARR
โ€ข Funding: ~$140M+
๐Ÿ—บ๏ธ Cyber risk analytics and network modeling platform that constructs digital twins of hybrid networks to identify attack paths, test segmentation, and calculate digital resilience scores. Starts at ~$10,000 โ€“ $20,000/yr (licensed on a per-network-node/device model at ~$100โ€“$250 per device/firewall with minimum annual commitment). โฑ๏ธ 30-day guided evaluation / proof-of-concept license for network topology modeling and vulnerability path verification.
Black Kite ๐Ÿ›ก๏ธ Private (Series B)
โ€ข Valuation: ~$150Mโ€“$200M
โ€ข Revenue: ~$25M+ ARR
โ€ข Funding: ~$36M
๐Ÿฆ… Third-party cyber risk intelligence and CRQ platform providing financial impact calculation (FAIR-based), Ransomware Susceptibility Index (RSIโ„ข), and compliance correlation. Starts at ~$15,000 โ€“ $29,160/yr (median entry tier monitoring 25โ€“50 vendor domains); scaling up to $90,000+/yr for large enterprise supply chains. ๐Ÿ†“ 1 complimentary external Cyber Risk Assessment report for your company or 1 vendor domain + 14-day scoped evaluation trial upon request.
Balbix ๐Ÿ“ˆ Acquired (Safe Security)
โ€ข Valuation: ~$120Mโ€“$150M
โ€ข Funding: ~$60M+ (prior to acquisition)
๐Ÿง  Security posture and cyber exposure quantification platform using AI to continuously discover assets, predict breach risk, and prioritize remediation by financial impact. Starts at ~$20,000 โ€“ $35,000/yr for entry-level deployments; scales based on total asset inventory / IP count and integration volume. โฑ๏ธ 30-day proof-of-value (POV) trial including initial external and internal asset discovery scan with risk scoring (no perpetual free tier).
Axio โšก Private (Series B)
โ€ข Valuation: ~$80Mโ€“$120M
โ€ข Revenue: ~$14M+ ARR
โ€ข Funding: ~$30M (ISTARI)
๐Ÿ“Š Cyber risk management and quantification platform (Axio360) emphasizing scenario-based financial stress testing, C2M2/NIST CSF maturity assessments, and board-ready reporting. Starts at ~$12,000 โ€“ $24,000/yr for core benchmark & assessment tier; scaling to $50,000+/yr for full CRQ stress-testing suite. ๐Ÿ†“ Free forever tier for single-framework assessments (NIST CSF Quick Launch, C2M2 Quick Launch, and Ransomware Preparedness tools for 1 organization) + 14-day full platform trial.
RiskLens ๐Ÿ“˜ Acquired (Safe Security)
โ€ข Valuation: ~$50Mโ€“$80M
โ€ข Funding: ~$20M+ (prior to acquisition)
๐Ÿ“ Pure-play quantitative cyber risk management software aligned with the Open FAIRโ„ข standard; provides probabilistic loss modeling (ALE, VaR) and board-level risk analytics. Starts at ~$15,000 โ€“ $25,000/yr for RiskLens Pro / Starter tier; enterprise tiers range from $50,000 to $100,000+/yr depending on FAIR analysis volume. ๐Ÿ†“ Free forever access to the FAIR-U web application (educational tool for 1 FAIR risk scenario Monte Carlo simulation at a time via FAIR Institute) + 14-day guided enterprise trial.
Kovrr ๐ŸŽฒ Private (Series A)
โ€ข Valuation: ~$30Mโ€“$50M
โ€ข Revenue: ~$4.1M ARR
โ€ข Funding: ~$10M+
๐Ÿงฎ Financial Cyber Risk Quantification (Quantum CRQ) platform translating cyber posture into financial risk metrics (Average Annual Loss, Value at Risk, loss exceedance curves) and AI risk governance. Starts at ~$25,000 โ€“ $50,000/yr for core Quantum CRQ enterprise subscription; scales based on company revenue tier and modeling depth. ๐Ÿ†“ Free tier for AI Risk Register (first 5 AI risk scenarios free forever) + 14-day guided CRQ financial loss modeling trial.
FortifyData ๐Ÿ” Private (Series A)
โ€ข Valuation: ~$20Mโ€“$30M
โ€ข Revenue: ~$2.7M ARR
โ€ข Funding: ~$7M
๐Ÿ›ก๏ธ Continuous cyber risk management and attack surface quantification platform assessing internal and external vulnerabilities to compute real-time risk ratings and compliance posture. Starts at ~$10,000 โ€“ $21,375/yr (median entry tier for core external and internal asset monitoring). ๐Ÿ†“ Free plan (quarterly external attack surface vulnerability assessment and security rating for 1 domain) + 14-day full feature trial.

๐Ÿ”“ Open-Source GitHub Projects

Below is a curated list of top open-source tools, Monte Carlo engines, GRC platforms with native FAIR quantification, and risk modeling frameworks, sorted in descending order by GitHub Stars.

  • CISO Assistant Stars
    ๐ŸŒ Comprehensive open-source GRC and risk management platform featuring native support for Open FAIR risk assessments, automated Loss Exceedance Curve (LEC) generation, and Monte Carlo risk simulations.

  • cve-search Stars
    ๐Ÿ” Local vulnerability and exposure search engine and database importer (CVE, CWE, CPE, CAPEC) enabling fast risk scoring, vulnerability correlation, and threat exposure calculations.

  • riskquant Stars
    ๐Ÿ Netflix's open-source Python library for quantitative risk assessment; computes annualized loss expectancy (ALE) and Loss Exceedance Curves by fitting loss frequency and magnitude to lognormal probability distributions.

  • awesome-risk-quantification Stars
    ๐Ÿ“š Curated index and learning roadmap of resources, academic papers, books, and software implementations for quantitative information security risk analysis and FAIR modeling.

  • evaluator Stars
    ๐Ÿ“Š Open-source R toolkit for quantitative risk assessment based on the OpenFAIR ontology and risk analysis standard. Supports data-driven, repeatable FAIR-style simulation, parameter estimation, and graphical reporting.

  • pyfair Stars
    ๐ŸŽฒ Python package implementing the Factor Analysis of Information Risk (FAIR) model for programmatic Monte Carlo risk simulations, distribution fitting, and risk scenario comparisons.

  • CRML (Cyber Risk Modeling Language) Stars
    ๐Ÿ“ Open-source declarative language and engine for writing "Risk as Code" (RaC). Provides YAML/JSON schemas to describe cyber risk models, telemetry mappings, and simulation pipelines in an engine-agnostic format.

  • Security Decision Labs Stars
    ๐Ÿงช Collection of statistical decision science and FAIR CRQ toolkits, including agent-based control simulations (FAIR-CAM), Threat Event Frequency (TEF) estimators, and Value of Information (VoI) calculators.

  • OpenFAIR Stars
    ๐Ÿ“ˆ Lightweight R implementation for simulating Open FAIR cyber risk scenarios and calculating probabilistic annualized loss distributions.

  • Fair TPRM
    ๐Ÿ“‹ Free, self-hosted open-source Third-Party Risk Management (TPRM) & GRC platform that incorporates native FAIR risk quantification (ALE calculations), vendor compliance scoring, and continuous risk monitoring.


๐Ÿงฉ Architectural Blueprints for Custom CRQ

Organizations building custom internal Cyber Risk Quantification pipelines typically assemble a multi-layer stack:

  1. Telemetry & Ingestion Layer: Ingest vulnerability scan data (Qualys, Nessus, OpenVAS), asset inventories, EPSS exploitability scores, CISA KEV feeds, and external attack surface exposures into a centralized lake or graph.
  2. Standardized Ontology Layer: Map technical assets and vulnerabilities into the Open FAIRโ„ข Risk Taxonomy (Threat Event Frequency $\times$ Vulnerability $\times$ Loss Magnitude).
  3. Simulation Engine Layer: Execute 10,000โ€“100,000 iterations using Python/R Monte Carlo engines (riskquant, pyfair, or evaluator) to generate probabilistic loss distributions.
  4. Executive Reporting Layer: Output Loss Exceedance Curves (LEC), 90th-percentile Cyber VaR, and Annualized Loss Expectancy (ALE) to BI dashboards (Tableau, Grafana, Power BI) and board slide decks.

๐Ÿค How to Contribute

We welcome contributions from cybersecurity practitioners, risk analysts, data scientists, and developers!

  1. ๐Ÿด Fork the repository on GitHub.
  2. ๐ŸŒฟ Create a feature branch: git checkout -b add-new-crq-tool
  3. ๐Ÿ“ Add your entry in README.md following the format:
    • For SaaS: Include Name, Link, Valuation/Revenue size, Description, Starting Price, and specific Free Tier/Trial limits. Insert in the correct sorted order.
    • For Open-Source: Include Repo Name, GitHub Link, Stargazers Star Badge (style=social&color=white), and Description. Insert in the correct star-sorted order.
  4. ๐Ÿš€ Submit a Pull Request with a concise description of the contribution.

โญ Star this repository if you find it helpful for your quantitative cyber risk journey!


โญ Star History

Star History Chart


โš ๏ธ Disclaimer

  • This is a community-curated index for informational and educational purposes โ€” it does not constitute financial, legal, or cyber insurance advice.
  • Cyber Risk Quantification models depend heavily on the quality, calibration, and assumptions of input data (Threat Event Frequency, Control Strength, Primary/Secondary Loss bounds).
  • Open-source Monte Carlo and FAIR tools provide complete transparency and model auditability, but require sound risk modeling calibration and statistical validation before using results in regulatory filings or board reporting.

Made with ๐Ÿ›ก๏ธ for CISOs, risk officers, security engineers, and cyber insurance underwriters striving for transparent, defensible, and mathematical cyber risk quantification.

About

Top Cyber Risk Quantification ๐ŸŒŸ Star if you like it! ๐ŸŒŸ

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Contributors