Quantitative cyber-risk analysis
Idraa turns expert judgment into loss distributions — so security leaders can budget, prioritize, and defend decisions in dollars, not colors.
Illustrative scenario. Control-driven reduction is modeled with explicit uncertainty — a range, not a precise figure.
The problem
Risk registers rank threats red, amber, green. The colors feel precise — but they don’t add up, don’t compare, and can’t answer the one question a board asks: how much could this cost us, and is it worth fixing?
Subjective. Non-additive. Un-budgetable. Two people rarely mean the same thing by “High.”
In dollars. Comparable across scenarios. You can put a budget — and an ROI — behind it.
You can’t put a budget behind a color.
The method — Open FAIR
You estimate each factor as a range, not a point — a 5th/95th percentile you’re comfortable defending. Uncertainty is modeled, not hidden.
The FAIR math composes frequency and magnitude into a single distribution of annual loss. Nothing is invented in the app layer.
Every metric Idraa shows maps back to a named FAIR node — so any number in a report is traceable to its source.
The engine — Monte Carlo
Each point answers: what’s the chance annual loss exceeds this dollar amount? Read down for the tail, across for the odds.
Annualized loss expectancy (ALE) — the number you carry into the budget.
1-in-20-year loss — the bad-year figure that sizes your reserves and cyber-insurance limits.
The shaded gap is the modeled reduction from a proposed control — estimated with explicit uncertainty, and the basis for comparing control ROI.
The workflow
A guided path a security team can actually run — no statistics degree required.
Define what could go wrong — threat, asset, method, effect. Start from the curated library, author your own, or import your existing risk register.
Capture expert ranges through a guided wizard — calibrated, inherent (pre-control), and pooled across multiple estimators.
Run Monte-Carlo trials — up to 100K for standard scenarios, up to 1M for catastrophic tails — to build the full loss distribution.
Read the curve against your appetite, and rank control investments by the dollars of risk each one removes.
Already keep a qualitative risk register? Import it. Idraa drafts a FAIR scenario from each entry — priors for your analysts to review and quantify, never auto-finalized.
The platform
Model how controls reduce frequency and magnitude — each control's contribution shown as a range, with its uncertainty made explicit (FAIR-CAM).
Begin from calibrated, sector-tiered scenarios cross-walked to MITRE ATT&CK techniques.
Combine disagreeing estimates without averaging away the disagreement — a true opinion pool, not a blurred mean.
A purpose-built Monte-Carlo engine that keeps the full distribution — VaR, expected shortfall, exceedance. Trial caps scale with deployment (100K standard, 1M catastrophic).
Re-derive the engine's per-scenario sampling and ALE in an Excel workbook that mirrors the math — auditable line by line. Tail metrics (VaR, expected shortfall) stay engine-computed, not reproduced in the sheet.
A posture dashboard with a risk-vs-appetite verdict, control budget, and PDF / Excel exports.
Idraa turns FAIR analysis into decisions your board can act on — one scenario at a time.