Skip to main content

Cyber Risk Quantification (CRQ)

Note: This add-on is a separate product and may not be included in your current plan. If your organization hasn't yet purchased access, contact your account manager to enable it.


Overview

What's a vendor disruption of service actually going to cost you? CRQ answers that question in dollars - not a risk score, not a color-coded rating, but a number you can hand straight to your CFO or board.

Built on Open FAIR™ - the Open Group's industry-standard methodology for quantitative cyber risk - CRQ applies the same rigor used by risk quantification specialists and insurers, purpose-built for your third-party relationships. Instead of asking “how risky is this vendor?”, it answers “how much could this vendor cost us?”, turning the data Panorays already collects (questionnaires, Cyber Posture Rating, cyber news, dark web mentions, business snapshot, IRQ) into a clear financial estimate - the expected annual loss if the relationship goes wrong.


How It Works

Following the Open FAIR model, CRQ estimates Annualized Loss Expectancy (ALE) - the expected financial loss per year - for each of four loss scenarios, then combines them into a single supplier-level figure.

  1. Data collection: Panorays gathers the supplier's existing signals - Cyber Posture Rating, questionnaire responses, certifications (such as SOC 2 or ISO 27001), inherent risk and relationship data, company size, industry, and cyber-news and dark-web history.

  2. Three Open FAIR questions: For each scenario, the model estimates:

  • How often an attack is likely to be attempted

  • How likely that attempt is to succeed, given the supplier's defenses

  • How costly it would be if it did

  1. Monte Carlo simulation: Rather than multiplying three single guesses, the model runs thousands of iterations across realistic ranges - producing an expected value plus a credible low-to-high range.

  2. Results: A headline dollar figure per supplier, broken down by scenario, with a drill-down explaining each input. Results roll up to a portfolio-level dashboard and can be exported to PDF.


The Four Loss Scenarios

Data Leak

The cost of a breach exposing data the supplier holds on your behalf - driven by data sensitivity, volume, and regulatory exposure.

Fraud

The cost of cyber-enabled financial fraud through the vendor relationship, such as invoice or wire fraud.

Availability

The cost of the supplier going down and disrupting your operations, expressed per day of downtime.

Supply Chain Attack

The cost if the supplier is compromised and used as a stepping stone into your own environment.


How to Use and Manage CRQ

1. Checking Supplier Eligibility

CRQ can only run on suppliers that have enough signal to model. A supplier is eligible when it has:

  • A Cyber Posture Rating, and

  • An Evaluation Type of Assessment or Monitoring

Suppliers without a Cyber Posture Rating cannot be quantified.


2. Running CRQ

CRQ runs on demand - it is not calculated automatically for every supplier.

  1. Open the supplier's CRQ tab.

  2. Select Run to start the quantification. The calculation runs asynchronously; you can navigate away and return once it completes.

  3. To quantify many suppliers at once, run CRQ in bulk from your supplier list. Ineligible suppliers in the selection are skipped and reported back to you.

  4. When the run finishes, the supplier's headline ALE, scenario breakdown, and Open FAIR drill-down are available on the tab.

Note: Because results are generated on demand, they reflect the supplier's data at the moment the run happened. If a supplier's posture changes or you update your CRQ configuration, rerun CRQ to see the new figure.


3. Reading the Results

  • Headline ALE: The expected annual loss across all modeled scenarios, shown as a mean value.

  • Range: A P5-P95 range - the band the loss would realistically fall within - with the marker placed at the mean. This is deliberately a range, not a single precise number.

  • Scenario cards: One card per loss scenario, each showing its own contribution to the total and a qualitative loss-magnitude level where applicable.

  • Open FAIR breakdown: A drill-down tree tracing the figure through each Open FAIR stage - attack frequency, vulnerability, loss event frequency, loss magnitude, and ALE - so every number can be traced back to a visible input.


4. Viewing Portfolio-Level Exposure

Quantified suppliers roll up into a portfolio-level dashboard showing your total ALE and your suppliers ranked by financial exposure. Under Live Dashboard, the view can be filtered by portfolio, tag, and business impact - so you can look at exposure for a specific business unit or vendor tier.


5. Exporting Results

CRQ results can be exported to PDF from the supplier's CRQ tab - useful for board packs, risk committee reviews, and sharing with business owners outside the platform.


6. Configuring CRQ (Admin Settings)

Editing permissions: CRQ configuration is available exclusively to Admin users.

Configuration is account-wide and ships with sensible defaults - no setup is required to get started. Admins can adjust:

  • Loss magnitude scales per scenario: The dollar values used to translate a qualitative loss level into a financial amount, so estimates reflect your organization's size and sector.

  • Supply Chain Attack constant: The value used in the supply-chain scenario.

  • Simulation count: The number of Monte Carlo iterations per run. Higher counts produce more stable results and take longer.

Did this answer your question?