Cyber risk quantification · Built on Open FAIR
Built on the Open FAIR standard and extended for markets where loss data is thin. In your currency, under your jurisdiction.
Runs entirely in your browser · no installation · no data leaves your machine.
The problem
Loss histories and actuarial benchmarks are scarce in these markets - and without them, quantification often stops before it starts. Hargrave Risk is built for the case where the decision still needs a number: capital at risk, insurance limits, control ROI.
The method
Where incident history is thin, these three additions carry the calibration.
Where no historical series exists, guided three-point estimates (minimum, most likely, maximum) feed PERT-Beta distributions, with sector references and automatic input validation.
Magnitudes are derived from your real profile - revenue, sector, size - and modeled in your currency, with optional live FX.
Sector defaults start from global benchmarks (IBM, Verizon DBIR) and are adjusted to your context. Results are reported as p10 / p50 / p90 and CVaR 90%.
How it works
Five steps, each with documented references, sector benchmarks and automatic input validation.
revenue · sector · size · currency · jurisdiction
global core + regional variants (PIX, SPEI)
7 auditable loss components
PERT-Beta · up to 50,000 iterations
appetite · control ROI · one-page export
The product
Monte Carlo + PERT-Beta implementing the Open FAIR ontology.
Derive PLM and SLM from the real company profile.
Quantify what each control buys you.
Comparison
| Dimension | Qualitative heatmap | Enterprise FAIR tools | Hargrave Risk |
|---|---|---|---|
| Output | Colors and rankings | Probabilistic loss, USD | Probabilistic loss, 9 currencies |
| Data required | None | Historical loss series | Expert ranges + sector benchmarks |
| Regulatory fines | Not modeled | GDPR / US only | 8 jurisdictions, US + EU + UK + LATAM |
| Languages | Not applicable | English | English · Español · Português |
| Price | No tool cost | $50K-200K / year | Accessible to consultants & mid-market |
| Access | Spreadsheet | Enterprise sales only | Runs in the browser, no install |
Comparison reflects the typical positioning of enterprise cyber risk quantification platforms. Hargrave Risk is an independent product that implements the Open FAIR ontology; it is not affiliated with or endorsed by The Open Group or any vendor.
Why now
Structured, defensible risk management is now a legal requirement across these markets. Estimates that state their assumptions and their uncertainty give boards and supervisors something they can examine.
Risk management obligations arriving for AI systems and for the organizations deploying them - inside and outside the EU.
ANPD is applying revenue-based sanctions. Privacy fines in Brazil are no longer theoretical.
Financial regulators across emerging markets now require structured cyber risk management - documented and auditable.
Who builds it