Cyber Risk Quantification (CRQ)
Cyber Risk Quantification (CRQ) is the practice of measuring cyber risk in financial terms, translating security events, controls, and exposure into probabilistic dollar-based loss distributions that boards, CFOs, and risk teams can act on.
What CRQ Actually Produces
A mature CRQ program produces enterprise-level cyber exposure in dollar terms, broken down by scenario, business unit, and control posture. Standard outputs include Average Annual Loss (AAL), the Loss Exceedance Curve, specific return period figures like the 1:100 annual loss, and scenario-level contributions to the total.
These are the same categories of output the rest of enterprise risk management uses. That is the point of CRQ: to put cyber on the same terms as every other enterprise risk, so it can be compared, prioritized, and governed consistently.
Why CRQ Has Displaced Qualitative Reporting
Traditional cyber reporting used qualitative ratings, heat maps, and maturity scores. These formats do not answer the questions boards and CFOs actually ask: what is the size of exposure, how does it compare to other risks, is investment reducing risk enough to justify the cost, and where should the next dollar go.
CRQ answers those questions directly. See what is cyber risk quantification (CRQ) and how to translate cyber risk into financial terms the CFO understands.
The Underlying Methodology
Modern CRQ typically uses Monte Carlo simulation to produce loss distributions across many synthetic years, calibrated against real-world loss data. Frequency and severity distributions for specific scenarios drive the simulation, and control posture reshapes those distributions based on measured effectiveness.
How Kovrr Approaches CRQ
Kovrr pioneered the current generation of CRQ, using probabilistic modeling calibrated against one of the largest curated cyber loss datasets in the industry. The CRQ Platform covers top-down scenarios, scenario intelligence, decision simulator, and managed CRQ program capabilities.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.






