Cyber risk quantification · Built on Open FAIR

Cyber risk, quantified in money.

Built on the Open FAIR standard and extended for markets where loss data is thin. In your currency, under your jurisdiction.

Runs entirely in your browser · no installation · no data leaves your machine.

Multi-currency GDPR · CCPA · LGPD · LATAM English · Español · Português
$4.4MGlobal average cost of a data breach in 2025IBM Cost of a Data Breach 2025
4% / €20MMaximum GDPR fine - the higher of the two appliesGDPR Art. 83
15%Organizations measuring the financial impact of cyber risk to a significant extentPwC 2025 Global Digital Trust Insights
8Regulatory jurisdictions modeled - US, EU, UK, BR, MX, CO, AR, CLSelectable per analysis

The problem

In data-scarce markets, risk decisions still run on a 5x5 matrix.

Loss histories and actuarial benchmarks are scarce in these markets - and without them, quantification often stops before it starts. Hargrave Risk is built for the case where the decision still needs a number: capital at risk, insurance limits, control ROI.

The method

Faithful to the ontology, calibrated to your context.

Where incident history is thin, these three additions carry the calibration.

Structured expert estimation

Where no historical series exists, guided three-point estimates (minimum, most likely, maximum) feed PERT-Beta distributions, with sector references and automatic input validation.

Anchored to your revenue, in your currency

Magnitudes are derived from your real profile - revenue, sector, size - and modeled in your currency, with optional live FX.

Global benchmarks, declared uncertainty

Sector defaults start from global benchmarks (IBM, Verizon DBIR) and are adjusted to your context. Results are reported as p10 / p50 / p90 and CVaR 90%.

How it works

From raw profile to a board-ready number.

Five steps, each with documented references, sector benchmarks and automatic input validation.

  1. 01

    Organization profile

    revenue · sector · size · currency · jurisdiction

  2. 02

    Scenario library

    global core + regional variants (PIX, SPEI)

  3. 03

    Magnitude calculator

    7 auditable loss components

  4. 04

    Monte Carlo simulation

    PERT-Beta · up to 50,000 iterations

  5. 05

    Report & decision

    appetite · control ROI · one-page export

The product

Three integrated modules. One coherent number.

FAIR engine

Monte Carlo + PERT-Beta implementing the Open FAIR ontology.

Pre-calibrated global scenarios
Configurable risk appetite
CVaR 90% stress testing
Sensitivity tornado & portfolio view

Magnitude calculator

Derive PLM and SLM from the real company profile.

Jurisdiction-aware privacy fine
Financial-regulator penalty model
Reputation / churn from LTV

Controls & ROI

Quantify what each control buys you.

Residual risk with an 80% cap
ROI per control and per package
Board-ready treatment plan

Comparison

Compared with what teams use today.

DimensionQualitative heatmapEnterprise FAIR toolsHargrave Risk
OutputColors and rankingsProbabilistic loss, USDProbabilistic loss, 9 currencies
Data requiredNoneHistorical loss seriesExpert ranges + sector benchmarks
Regulatory finesNot modeledGDPR / US only8 jurisdictions, US + EU + UK + LATAM
LanguagesNot applicableEnglishEnglish · Español · Português
PriceNo tool cost$50K-200K / yearAccessible to consultants & mid-market
AccessSpreadsheetEnterprise sales onlyRuns in the browser, no install

Comparison reflects the typical positioning of enterprise cyber risk quantification platforms. Hargrave Risk is an independent product that implements the Open FAIR ontology; it is not affiliated with or endorsed by The Open Group or any vendor.

Why now

Regulation is raising the bar on risk evidence.

Structured, defensible risk management is now a legal requirement across these markets. Estimates that state their assumptions and their uncertainty give boards and supervisors something they can examine.

EU AI Act

Risk management obligations arriving for AI systems and for the organizations deploying them - inside and outside the EU.

LGPD in active enforcement

ANPD is applying revenue-based sanctions. Privacy fines in Brazil are no longer theoretical.

Central bank resolutions

Financial regulators across emerging markets now require structured cyber risk management - documented and auditable.

Who builds it

Built by a practitioner who runs this analysis.

Hargrave Risk is built by Pedro Carnaúba, a practitioner trained in FAIR-TPRM, operating cyber risk in an emerging market. The gap it closes is the one he works in every day: bringing Open FAIR rigor to organizations that need it in their own currency and jurisdiction.