Top-Down Risk Quantification
Top-down risk quantification is an approach that models enterprise cyber exposure by starting from industry-level and portfolio-level loss scenarios, then attributing exposure across the enterprise, complementing bottom-up asset-level analysis.
How Top-Down Works
Top-down models begin with the enterprise view. Loss scenarios are defined at the portfolio level: what a ransomware event against an organization of this size, industry, and profile typically produces; what a systemic third-party incident affecting this sector would cost; what regulatory action for a data breach in this jurisdiction would look like.
The starting point is empirical: real-world loss data from comparable events at comparable organizations. Attribution across business units and asset types happens through modeling of exposure distribution.
Top-Down vs. Bottom-Up
Bottom-up quantification starts from asset-level detail and aggregates upward. Top-down starts from portfolio-level scenarios and distributes downward. Both approaches produce enterprise exposure figures, but they answer different questions.
Top-down is stronger for board conversations, benchmarking against industry peers, and initial portfolio-level analysis. Bottom-up is stronger for specific control investment decisions and business-unit-level attribution.
When to Use Top-Down
Top-down is well suited to enterprise-level reporting, insurance limit decisions, and situations where asset-level data is not yet available at sufficient quality for bottom-up modeling. It is also common as the starting point for a CRQ program, with bottom-up detail added over time.
How Kovrr Approaches Top-Down Risk Quantification
Kovrr's Top-Down Scenarios capability provides enterprise-level modeled exposure from scenario libraries calibrated against real-world loss data, giving programs a defensible starting point without requiring deep asset-level integration.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


