Hargrave is built on the Open FAIR standard and extends it where emerging markets need it - probabilistic loss in local currency, structured expert calibration where historical data is scarce, and fine models tuned to the jurisdiction you operate in. No enterprise price tag, no six-week consulting project.
Across emerging markets, billions in GDP are protected by qualitative 5x5 matrices - because textbook FAIR is hard to apply where loss data is scarce. That heatmap is the baseline that actually runs these decisions, and it cannot size capital, insurance or control ROI.
A red cell does not tell the board how much capital is at risk, what insurance limit to buy, or which control pays for itself. Money does.
Textbook FAIR calibration expects incident series and actuarial benchmarks. Where history is missing, teams give up on quantification entirely and fall back to the matrix.
Enterprise FAIR platforms cost tens of thousands of dollars a year, output US dollars against US case law, and ignore the currencies and regulators of everyone else.
A structured five-step flow. Every step has documented references, sector benchmarks and automatic input validation - so the estimate is defensible, not a gut feel.
Revenue, sector, size, customers, currency and regulatory jurisdiction - entered once, feeding every downstream calculation.
Global core scenarios (ransomware, wire fraud, data breach, supply chain, DDoS) plus regional variants activated by jurisdiction - PIX fraud for Brazil, SPEI for Mexico.
Decomposes loss into auditable components - downtime, response, recovery, privacy fine, reputation, legal - each with a formula and an adjustable assumption.
PERT-Beta distributions and up to 50,000 iterations per scenario produce p10 / p50 / p90 and CVaR 90% - uncertainty represented honestly.
Set risk appetite, evaluate control ROI, and export a one-page executive report - in the language and currency of your audience.
Hargrave does not fork or correct FAIR - it implements the Open FAIR ontology faithfully and adds the calibration layer that data-scarce markets need to use it at all.
Where no historical series exists, guided three-point estimates (minimum, most likely, maximum) feed PERT-Beta distributions - with sector references and automatic input validation. Defensible inputs, not guesses.
Magnitudes are derived from your real profile - revenue, sector, size - and modeled in your currency, with optional live FX. Not dollar figures imported from another economy.
Sector defaults start from global benchmarks (IBM, Verizon DBIR) and are adjusted to your context. Results are reported as p10 / p50 / p90 and CVaR 90% - never a single number pretending to be certain.
Monte Carlo + PERT-Beta implementing the Open FAIR ontology.
Derive PLM and SLM from the real company profile.
Quantify what each control buys you.
| Dimension | Qualitative heatmap | Enterprise FAIR tools | Hargrave |
|---|---|---|---|
| Output | Colors and rankings | Probabilistic loss, USD | Probabilistic loss, 9 currencies |
| Data required | None - and it shows | Historical loss series | Expert ranges + sector benchmarks |
| Regulatory fines | Not modeled | GDPR / US only | 8 jurisdictions, US + EU + UK + LATAM |
| Languages | Not applicable | English | English · Español · Português |
| Price | Free, costly in decisions | $50K-200K / year | Accessible to consultants & mid-market |
| Access | Any spreadsheet | Enterprise sales only | Runs in the browser, no install |
Comparison reflects the typical positioning of enterprise cyber risk quantification platforms. Hargrave is an independent product that implements the Open FAIR ontology; it is not affiliated with or endorsed by The Open Group or any vendor.
Structured, defensible risk management is now a legal requirement in markets that do not have the loss data the gold standard assumes. The demand for a rigorous middle ground is not future - it is current.
Risk management obligations arriving for AI systems and for the organizations deploying them - inside and outside the EU.
ANPD is applying revenue-based sanctions. Privacy fines in Brazil are no longer theoretical.
Financial regulators across emerging markets now require structured cyber risk management - with numbers, not colors.
Hargrave is built by Pedro Carnaúba, a FAIR-TPRM certified practitioner operating cyber risk in an emerging market - not theorizing about it from outside. The gap Hargrave closes is the one he works in every day: bringing Open FAIR rigor to organizations the framework was not calibrated to reach.