March 30, 2026 · Cyber Risk Quantification · Monte Carlo Engine

CRQ Monte Carlo engine — FAIR math wired into every dollar figure

RFC-017 lands the Cyber Risk Quantification engine: FAIR-shaped LEF × LM decomposition, 10,000-run Monte Carlo per scenario, Loss Exceedance Curves as primary output, BLS + Gartner blended labor rates for remediation cost. Every dollar figure downstream is now live simulation, not a lookup table.

What changed

The Cyber Risk Quantification (CRQ) engine (RFC-017) shipped this month as the math layer underneath every dollar figure the platform will produce from this point forward. The cost-methodology work in the platform stops being a lookup table and starts being a live simulation of the customer’s actual exposure.

Decomposition
Every scenario splits into a Loss Event Frequency distribution and a Loss Magnitude distribution per the FAIR model, configurable per scenario and per customer.
Simulation
Ten-thousand-run Monte Carlo per scenario over a one-year horizon, producing a distribution of possible losses rather than a single expected number.
Output
A Loss Exceedance Curve that answers “what’s the probability we lose more than $X this year?” at the dollar figures the customer cares about — the point on the curve at $50k, at $500k, at $5M.
Cost panels
Every panel that used to show a hardcoded low/medium/high cost estimate now pulls the real percentile from the engine. Change the business context, threat model, or control coverage and the number moves with it.
Labor rate
Per-finding remediation cost is derived from an hours-per-finding estimate multiplied by a documented BLS + Gartner blended labor rate, which the customer can override to match their actual labor cost.

Why it matters

Every product improvement that talks about a dollar figure — maturity-assessment cost breakdown, per-finding ALE, board-facing risk reports, quantified vendor exposure, LEC curves in the CFO panel — is now driven by the same math the FAIR Institute and NIST 800-30 Rev. 1 use, not a lookup table. The industry norm of red-yellow-green cyber risk is an unforced error. This engine is the platform’s answer.

LECs are what board risk committees actually reason against. The engine produces them at the percentiles those committees ask for, with the inputs documented and the methodology citable.

For the methodology this engine implements at SMB scale, see Cyber Risk Quantification for Mid-Market. For the show-your-work discipline the LEC output supports, see Why This Probability: Bayesian Conditional Exposure.

Availability

Live now across the platform’s cost outputs. Every panel that previously rendered a hardcoded cost range reads from the engine.

Scenario distributions and the blended labor rate are seeded from the FAIR Institute methodology and public BLS + Gartner wage data. A customer override to the labor rate carries through every downstream dollar figure: per-finding ALE, maturity-assessment cost breakdowns, and quantified vendor exposure.

Known limitations

The simulation horizon is one year. Multi-year loss curves aren’t produced by the engine in this iteration.