CRQ Monte Carlo engine — FAIR math wired into every dollar figure
RFC-017 lands the Cyber Risk Quantification engine: FAIR-shaped LEF × LM decomposition, 10,000-run Monte Carlo per scenario, Loss Exceedance Curves as primary output, BLS + Gartner blended labor rates for remediation cost. Every dollar figure downstream is now live simulation, not a lookup table.
The Cyber Risk Quantification (CRQ) engine (RFC-017) shipped this month as the platform’s Monte Carlo simulation substrate — the math layer underneath every dollar figure the platform will produce from this point forward. FAIR-shaped decomposition, calibrated distributions, ten-thousand-run Monte Carlo simulation, Loss Exceedance Curve output. The cost-methodology work in the platform stops being a lookup table and starts being a live simulation of the customer’s actual exposure.
What’s in the engine
- FAIR-style Loss Event Frequency × Loss Magnitude decomposition. Every scenario the engine evaluates decomposes into a probability distribution over how often the event happens per year and a probability distribution over the financial magnitude when it does. Both are configurable per scenario and per customer.
- Ten-thousand-run Monte Carlo per scenario. Rather than a single expected-loss number, the engine produces a distribution of possible losses over a one-year horizon — which is what a probable-loss curve actually is and what a board risk committee actually asks for.
- Loss Exceedance Curve (LEC) as the primary output. The LEC answers “what’s the probability we lose more than $X this year?” at every dollar figure the customer cares about — the point on the curve at $50k, at $500k, at $5M. LECs are what board risk committees actually reason against.
- Live percentiles wired into cost methodology. Every panel that used to show a hardcoded “low/medium/high” cost estimate now pulls the real percentile from the engine. Change the underlying business context, threat model, or control coverage; the number changes with it.
- BLS + Gartner blended labor rate for remediation cost. Per-finding remediation cost is derived from an hours-per-finding estimate multiplied by a documented and citation-backed blended labor rate, not from a hardcoded category. The customer can override the rate to match their actual labor cost.
Why this matters
Every product improvement that talks about a dollar figure — maturity-assessment cost breakdown, per-finding ALE, board-facing risk reports, quantified vendor exposure, LEC curves in the CFO panel — is now driven by the same math the FAIR Institute and NIST 800-30 Rev. 1 use, not a lookup table. The industry norm of red-yellow-green cyber risk is an unforced error. This engine is the platform’s answer.
Related reading
Cyber Risk Quantification for Mid-Market — the FAIR-based methodology this engine implements at SMB scale.
Why This Probability: Bayesian Conditional Exposure — the show-your-work discipline the engine's LEC output supports.