Idraa · cyber risk, quantified
01 / 07

Quantitative cyber-risk analysis

Cyber risk,
quantified.

Idraa turns expert judgment into loss distributions — so security leaders can budget, prioritize, and defend decisions in dollars, not colors.

Open FAIR / FAIR-CAM Monte-Carlo engine Board-ready reporting
Loss exceedance — annual currentwith controls
Annualized loss expectancy (ALE)
1-in-20-year loss
Modeled reduction

Illustrative scenario. Control-driven reduction is modeled with explicit uncertainty — a range, not a precise figure.

The problem

“High” is not a number.

Risk registers rank threats red, amber, green. The colors feel precise — but they don’t add up, don’t compare, and can’t answer the one question a board asks: how much could this cost us, and is it worth fixing?

The usual way — a 5×5 matrix
Likelihood →Impact ↑

Subjective. Non-additive. Un-budgetable. Two people rarely mean the same thing by “High.”

vs
The Idraa way — a loss distribution
$ loss / year →probability ↑

In dollars. Comparable across scenarios. You can put a budget — and an ROI — behind it.

You can’t put a budget behind a color.

The method — Open FAIR

Decompose the risk.
Quantify the parts.

RISKannualized loss, $ LEFLoss Event Freq.how often it happens LMLoss Magnitudehow bad when it does TEFthreat attempts / yr VULNshare that succeed PRIMARYdirect response cost SECONDARYfines, churn, fallout × × +
RANGE

You estimate each factor as a range, not a point — a 5th/95th percentile you’re comfortable defending. Uncertainty is modeled, not hidden.

COMPOSE

The FAIR math composes frequency and magnitude into a single distribution of annual loss. Nothing is invented in the app layer.

TRACE

Every metric Idraa shows maps back to a named FAIR node — so any number in a report is traceable to its source.

The engine — Monte Carlo

One curve tells the whole story.

Loss exceedance curve currentproposed
READ

Each point answers: what’s the chance annual loss exceeds this dollar amount? Read down for the tail, across for the odds.

A

Annualized loss expectancy (ALE) — the number you carry into the budget.

B

1-in-20-year loss — the bad-year figure that sizes your reserves and cyber-insurance limits.

Δ

The shaded gap is the modeled reduction from a proposed control — estimated with explicit uncertainty, and the basis for comparing control ROI.

The workflow

From a worry to a decision, in four moves.

A guided path a security team can actually run — no statistics degree required.

STEP 01

Scope

Define what could go wrong — threat, asset, method, effect. Start from the curated library or author your own.

STEP 02

Elicit

Capture expert ranges through a guided wizard — calibrated, inherent (pre-control), and pooled across multiple estimators.

STEP 03

Simulate

Run Monte-Carlo trials — up to 100K for standard scenarios, up to 1M for catastrophic tails — to build the full loss distribution.

STEP 04

Decide

Read the curve against your appetite, and rank control investments by the dollars of risk each one removes.

The platform

Rigor under the hood, clarity on the surface.

100+
Curated scenarios
1M
Max trials / run
200+
ATT&CK techniques mapped
01

Control-aware modeling

Model how controls reduce frequency and magnitude — each control's contribution shown as a range, with its uncertainty made explicit (FAIR-CAM).

02

Library + ATT&CK

Begin from calibrated, sector-tiered scenarios cross-walked to MITRE ATT&CK techniques.

03

Multi-expert pooling

Combine disagreeing estimates without averaging away the disagreement — a true opinion pool, not a blurred mean.

04

Native simulation

A purpose-built Monte-Carlo engine that keeps the full distribution — VaR, expected shortfall, exceedance. Trial caps scale with deployment (100K standard, 1M catastrophic).

05

Verification workbook

Re-derive the engine's per-scenario sampling and ALE in an Excel workbook that mirrors the math — auditable line by line. Tail metrics (VaR, expected shortfall) stay engine-computed, not reproduced in the sheet.

06

Board-ready reporting

A posture dashboard with a risk-vs-appetite verdict, control budget, and PDF / Excel exports.

See your risk
in dollars.

Idraa turns FAIR analysis into decisions your board can act on — one scenario at a time.

idraa.app · quantitative cyber-risk analysis