Multi-currency GDPR · CCPA · LGPD · LATAM English · Español · Português
Cyber risk quantification · Built on Open FAIR

Turn cyber risk into money your board actually understands.

Hargrave is built on the Open FAIR standard and extends it where emerging markets need it - probabilistic loss in local currency, structured expert calibration where historical data is scarce, and fine models tuned to the jurisdiction you operate in. No enterprise price tag, no six-week consulting project.

Runs entirely in your browser · no installation · no data leaves your machine.
$4.4MGlobal average cost of a data breach in 2025IBM Cost of a Data Breach 2025
4% / €20MMaximum GDPR fine - revenue-based, whichever is higherGDPR Art. 83
~1 in 7Organizations that can measure the financial impact of cyber riskPwC Digital Trust Insights
8Regulatory jurisdictions modeled - US, EU, UK, BR, MX, CO, AR, CLSelectable per analysis
The problem

The real alternative isn't perfect FAIR. It's a colored heatmap.

Across emerging markets, billions in GDP are protected by qualitative 5x5 matrices - because textbook FAIR is hard to apply where loss data is scarce. That heatmap is the baseline that actually runs these decisions, and it cannot size capital, insurance or control ROI.

Risk managed by color

A red cell does not tell the board how much capital is at risk, what insurance limit to buy, or which control pays for itself. Money does.

The standard assumes data you may not have

Textbook FAIR calibration expects incident series and actuarial benchmarks. Where history is missing, teams give up on quantification entirely and fall back to the matrix.

×

Tools built for someone else

Enterprise FAIR platforms cost tens of thousands of dollars a year, output US dollars against US case law, and ignore the currencies and regulators of everyone else.

How it works

From raw profile to a board-ready number.

A structured five-step flow. Every step has documented references, sector benchmarks and automatic input validation - so the estimate is defensible, not a gut feel.

1

Organization profile

Revenue, sector, size, customers, currency and regulatory jurisdiction - entered once, feeding every downstream calculation.

2

Scenario library

Global core scenarios (ransomware, wire fraud, data breach, supply chain, DDoS) plus regional variants activated by jurisdiction - PIX fraud for Brazil, SPEI for Mexico.

3

Magnitude calculator

Decomposes loss into auditable components - downtime, response, recovery, privacy fine, reputation, legal - each with a formula and an adjustable assumption.

4

Monte Carlo simulation

PERT-Beta distributions and up to 50,000 iterations per scenario produce p10 / p50 / p90 and CVaR 90% - uncertainty represented honestly.

5

Report & decision

Set risk appetite, evaluate control ROI, and export a one-page executive report - in the language and currency of your audience.

The method

Built on Open FAIR. Extended where the standard is silent.

Hargrave does not fork or correct FAIR - it implements the Open FAIR ontology faithfully and adds the calibration layer that data-scarce markets need to use it at all.

Δ

Structured expert estimation

Where no historical series exists, guided three-point estimates (minimum, most likely, maximum) feed PERT-Beta distributions - with sector references and automatic input validation. Defensible inputs, not guesses.

%

Anchored to your revenue, in your currency

Magnitudes are derived from your real profile - revenue, sector, size - and modeled in your currency, with optional live FX. Not dollar figures imported from another economy.

±

Global benchmarks, declared uncertainty

Sector defaults start from global benchmarks (IBM, Verizon DBIR) and are adjusted to your context. Results are reported as p10 / p50 / p90 and CVaR 90% - never a single number pretending to be certain.

The product

Three integrated modules. One coherent number.

FAIR engine

Monte Carlo + PERT-Beta implementing the Open FAIR ontology.

Pre-calibrated global scenarios
Configurable risk appetite
CVaR 90% stress testing
Sensitivity tornado & portfolio view
Σ

Magnitude calculator

Derive PLM and SLM from the real company profile.

Jurisdiction-aware privacy fine
Financial-regulator penalty model
Reputation / churn from LTV

Controls & ROI

Quantify what each control buys you.

Residual risk with an 80% cap
ROI per control and per package
Board-ready treatment plan
The real comparison

Against the heatmap, not against perfect FAIR.

DimensionQualitative heatmapEnterprise FAIR toolsHargrave
OutputColors and rankingsProbabilistic loss, USDProbabilistic loss, 9 currencies
Data requiredNone - and it showsHistorical loss seriesExpert ranges + sector benchmarks
Regulatory finesNot modeledGDPR / US only8 jurisdictions, US + EU + UK + LATAM
LanguagesNot applicableEnglishEnglish · Español · Português
PriceFree, costly in decisions$50K-200K / yearAccessible to consultants & mid-market
AccessAny spreadsheetEnterprise sales onlyRuns in the browser, no install

Comparison reflects the typical positioning of enterprise cyber risk quantification platforms. Hargrave is an independent product that implements the Open FAIR ontology; it is not affiliated with or endorsed by The Open Group or any vendor.

Open the platform
Why now

Regulators are demanding numbers from markets that lack the data.

Structured, defensible risk management is now a legal requirement in markets that do not have the loss data the gold standard assumes. The demand for a rigorous middle ground is not future - it is current.

AI

EU AI Act

Risk management obligations arriving for AI systems and for the organizations deploying them - inside and outside the EU.

§

LGPD in active enforcement

ANPD is applying revenue-based sanctions. Privacy fines in Brazil are no longer theoretical.

¤

Central bank resolutions

Financial regulators across emerging markets now require structured cyber risk management - with numbers, not colors.

Who builds it

Built by the user the standard tools don't serve.

Hargrave is built by Pedro Carnaúba, a FAIR-TPRM certified practitioner operating cyber risk in an emerging market - not theorizing about it from outside. The gap Hargrave closes is the one he works in every day: bringing Open FAIR rigor to organizations the framework was not calibrated to reach.